Onit
About Onit
Position Summary
Onit, Inc. is looking for an Application Security Engineer to help secure our SaaS applications, APIs, and emerging AI capabilities.
This is a hands-on, high-impact role where you’ll work closely with engineering and product teams to design secure systems, identify vulnerabilities, and improve how we build software. You’ll play a key role in shaping our security practices as we scale.
Key Responsibilities
- Lead security reviews for application architecture and system design
- Evaluate designs for:
- Authentication & authorization models
- Data access patterns
- API exposure and trust boundaries
- Provide clear, actionable guidance to engineering teams
- Identify risks early and influence secure design decisions
- Conduct pre-production / go-live security assessments
- Determine whether a feature is safe to launch and what risks must be mitigated vs accepted
- Partner with engineering and product to prioritize fixes and define compensating controls
- Act as a security approver / advisor for production releases
- Design and assess:
- OAuth2, OIDC, SAML implementations
- RBAC / fine-grained authorization models
- Identify and remediate broken access control and privilege escalation paths
- Drive adoption of least privilege and secure access patterns
- Lead security reviews of REST, GraphQL, and event-driven APIs
- Identify risks such as:
- Broken Object Level Authorization (BOLA)
- Injection vulnerabilities
- Data leakage
- Define standards for:
- API authentication
- Input validation
- Rate limiting and abuse protection
- Assess security risks in AI-powered features and systems
- Evaluate threats such as:
- Prompt injection
- Data leakage via LLMs
- Model misuse and access control gaps
- Help define and implement AI security guardrails
- Review architectures involving MCP (Model Context Protocol) or similar AI integration patterns
- Lead vulnerability identification using Static analysis (SAST) and Dependency scanning (SCA)
- Validate findings and eliminate false positives
- Prioritize vulnerabilities based on exploitability and business impact
- Drive remediation with engineering teams
- Assess and map application attack surface
- Identify exposed services, endpoints, and integrations
- Evaluate third-party and supply chain risks
- Continuously improve visibility into application risk
- Integrate and optimize security tools in CI/CD pipelines
- Define security gates for builds and releases
- Automate security checks where possible
- Improve developer experience with secure defaults
Security Architecture & Design Reviews
Go-Live Security Reviews & Risk Decisions
Authentication, Authorization & Access Control
API Security
AI & Emerging Technology Security
Vulnerability Management & Testing
Attack Surface & Risk Assessment
Security Tooling & DevSecOps
Required Skills
- 10+ years of experience in Application Security, Security Engineering, or Software Engineering with a strong security focus
- Proven experience performing security architecture/design reviews, as well as Go-live/production readiness security assessments, with experience with cloud platforms (AWS, GCP, Azure) preferred
- Strong understanding of OWASP Top 10 and modern web vulnerabilities and secure system design and threat modeling
- Experience with SAST tools (e.g., SonarQube, Checkmarx) and SCA tools (e.g., Snyk, Dependabot)
- Ability to assess real-world risk and prioritize effectively in a SaaS environment
- Understanding of LLM risks (prompt injection, data leakage) and AI system architecture
- Exposure to securing AI features or platforms
- Familiarity with MCP or similar AI integration patterns
- Deep Expertise in the following:
- Authentication & Authorization
- OAuth2, OIDC, SAML
- RBAC / ABAC / least privilege models
- API Security
- REST / GraphQL
- Common API attack vectors (BOLA, injection, data exposure)
- Application Security
- Secure coding practices
- Input validation, output encoding, session management
Benefits & Perks That Support You:
Our Commitment to Applicants
Onit Values
Originally posted on Himalayas
To apply for this job please visit himalayas.app.
About this role & career path
Working in India
India, officially the Republic of India, is a country in South Asia. It is the seventh-largest country by area, the most populous country in the world and, since its independence in 1947, the world's most populous democracy. Bounded by the Indian Ocean on the south, the Arabian Sea on the southwest, and the Bay of Bengal on the southeast, it shares land borders with Pakistan to the west; China, Nepal and Bhutan to the north; Bangladesh and Myanmar to the east. In the Indian Ocean, India is near Sri Lanka and the Maldives. Its Andaman and Nicobar Islands share a maritime border with Myanmar, Th
More jobs at Onit
Keep exploring on Get A Job.ai
Not quite the right fit? Your next opportunity is a click away.
- Browse all jobs
- More jobs by category
- Remote jobs you can do from anywhere
- Research typical pay for this role
- Set a job alert so new matches reach you first
- Upload your resume to apply faster
Hiring instead? Post a job and reach candidates searching right now.