Source description
About the role
NxtWave is one of India’s fastest-growing Ed-Tech startups. NxtWave is revolutionizing the 21st-century job market by transforming youth into highly skilled tech professionals irrespective of their educational background with its CCBP 4.0 programs.
NxtWave is founded by Rahul Attuluri (Ex Amazon, IIIT Hyderabad), Sashank Reddy (IIT Bombay) and Anupam Pedarla (IIT Kharagpur). The startup is backed by Orios Ventures, Better Capital and marquee angels , including founders of some of India’s unicorns.
NxtWave is an official partner for NSDC , under the Ministry of Skill Development & Entrepreneurship, Govt. of India, and recognized by NASSCOM, Ministry of Commerce and Industry, Govt. of India, and Startup India. The startup has received accolades as ‘ The Greatest Brand in Education ’ in a research-based listing by URS Media, a leading international media house.
By offering vernacular content and interactive learning, NxtWave is breaking the entry barrier for learning tech skills. Learning in their mother tongue helps learners achieve higher comprehension, deeper attention, longer retention and greater outcomes.
NxtWave now has paid subscribers from 450+ districts across India. In just 2 years, CCBP 4.0 learners have been hired by 800+ companies including Google, Amazon, Nvidia, Goldman Sachs, Oracle, Deloitte and more.
Scale at which we operate on tech level:
50 Cr+ learning minutes spent
12 Cr+ Code Runs
2Bn.+ API Requests Handled by our servers
Know more about NxtWave: https://www.ccbp.in
Read more about us in the news - Economic Times | The Hindu | Yourstory | VCCircle
Opportunity NxtWave is actively seeking a Security Engineer (Application Security + Cloud Security) to join and play a critical role in the Engineering team. As our first dedicated security hire, you will own application security and cloud security across our products, protect our learners and their data, and help us build a strong security-first engineering culture.
Our platform powers interactive coding playgrounds, live assessments, and cloud-native learning infrastructure — all running on AWS. As we scale, the attack surface grows with it. We need someone who can think like an attacker, build like an engineer, and secure our systems proactively.
Why NxtWave? As a Security Engineer at NxtWave, you
Shape how security is built across the company from the ground up. High ownership, high impact.
Work on genuinely interesting security challenges across a real code execution environment, cloud-native infrastructure, and high-traffic learning platforms.
Work in an engineering-first culture where security lives inside the engineering team, with direct access to engineering leadership.
Enjoy the freedom to experiment and learn from mistakes (Fail Fast, Learn Faster).
Experience the rapid growth of one of the fastest-growing EdTech startups, with the opportunity to implement security solutions from the ground up.
Skills & Experience
-
3+ years of hands-on experience in Application Security, Product Security, or Security Engineering.
-
Proficiency in Python and JavaScript/Node.js — you should be able to read, review, and write code, not just run scanners.
-
Working knowledge of Django security patterns and React frontend security best practices.
-
Solid understanding of OWASP Top 10 (Web + API) with demonstrated ability to find and fix these vulnerabilities in real codebases.
-
Hands-on experience with AWS security services: IAM, VPC, Security Groups, S3 policies, CloudTrail, GuardDuty.
-
Experience with container security concepts: Docker image hardening, ECS/Fargate task role security, network isolation.
-
Should have hands-on experience in Security Tools (SAST and DAST) such as Semgrep, SonarQube, BurpSuite, ZAP, or similar, and integrating them into CI/CD pipelines.
-
Strong grasp of secret management, API authentication (OAuth 2.0, JWT), and secure session handling.
-
Should have good knowledge of secure design practices, threat modeling, and common software vulnerabilities such as CWE Top 25 and OWASP Top 10.
-
Good understanding of threat and attack landscape, latest security trends, attack vectors, and how they are leveraged by malicious actors.
-
Should have knowledge about compliance frameworks such as ISO 27001, SOC 2, etc.
-
Experience working in an AGILE environment.
-
Excellent verbal and written communication skills.
-
Good to Have Experience securing code execution or sandbox environments (container escape prevention, resource isolation).
-
Familiarity with Infrastructure as Code security (CloudFormation/Terraform) or policy-as-code tools (OPA, Checkov).
-
Experience with dependency vulnerability scanning tools (Snyk, Trivy, Dependabot).
-
Experience with WAF configuration and DDoS mitigation (AWS WAF, CloudFront security).
-
Comfortable working with latest AI tools and should be able to adopt new AI workflows to improve security processes and efficiency.
-
Certifications such as CEH, OSCP, AWS Security Specialty, or CompTIA Security+ (valued but not required).
-
Bug bounty or CTF participation.
-
Prior experience in a startup environment.
Responsibilities
-
Application Security Perform secure code reviews on the Django backend and React frontend, identifying vulnerabilities before they reach production.
-
Assess and harden application infrastructure against security threats including sandbox escape, resource abuse, and data exfiltration.
-
Find and fix OWASP Top 10 issues across web applications and APIs.
-
Integrate automated security scanning (SAST/DAST) into CI/CD pipelines to catch vulnerabilities early.
-
Conduct threat modeling for new features and architectural changes, working directly with development teams.
-
Investigate and remediate client-side security issues including secret exposure, XSS, and insecure data handling.
-
Cloud Security Own the security posture of the AWS environment: ECS, EKS, Lambda, S3, CloudFront, API Gateway, and IAM.
-
Audit and enforce least-privilege IAM policies, S3 bucket policies, security group rules, and VPC configurations.
-
Set up and manage AWS-native security tooling: GuardDuty, Security Hub, CloudTrail, Config Rules, and WAF.
-
Ensure container security for ECS Fargate workloads — image scanning, task role lockdown, and network segmentation.
-
Implement secret management best practices and eliminate hardcoded credentials across services.
-
Conduct periodic cloud security assessments using tools like Prowler, ScoutSuite, or equivalent.
-
Incident Response & Security Operations Investigate security incidents including phishing attacks, social engineering attempts, and extortion emails targeting employees.
-
Serve as the technical escalation point for IT security matters: support IT personnel with EDR, DLP, patch management, and endpoint security tooling.
-
Build and maintain incident response playbooks and drive post-incident remediation.
-
Compliance Support Act as the technical bridge for ISO 27001 compliance — provide evidence for audits, support risk assessments, and ensure security controls are operational.
-
Coordinate with the compliance team on SOA updates, internal audit evidence, and corrective action tracking.
-
Contribute to security awareness initiatives and developer security training.
More at Darwinbox