Senior Security Engineer

Contractual
Delhi
Posted 22 hours ago

NeGD is currently inviting applications for the position of Senior Security Engineer on a contractual basis, initially for 3 years, with further extension as required by the project.

Position Senior Security Engineer
No. of Positions 01
Last Date 07th September 2026

Responsibilities

  • Conduct hands-on security assessment of web applications, APIs, microservices, mobile/backend services, cloud deployments, containers, and supporting infrastructure, using a combination of manual testing and automated security tooling
  • Perform application and API penetration testing covering authentication and authorisation failures, injection vulnerabilities, insecure business logic, SSRF, deserialization issues, file-handling vulnerabilities, privilege escalation, session weaknesses, secrets exposure, and other OWASP-class vulnerabilities
  • Conduct security reviews of AI-enabled applications, including LLM, RAG, agentic AI, predictive ML, computer vision, identity-verification, and fraud-detection systems, identifying risks introduced by models, prompts, retrieval layers, tools, data pipelines, and integrations
  • Design and execute LLM and agentic-AI red-team exercises covering direct and indirect prompt injection, jailbreaks, system-prompt leakage, sensitive-data disclosure, insecure tool invocation, excessive agency, permission bypass, output manipulation, cross-user data leakage, and policy boundary violations
  • Assess RAG security including poisoning or manipulation of retrieved content, malicious document ingestion, retrieval-based prompt injection, source-integrity weaknesses, access-control failures in vector stores, sensitive-data retrieval, and trust-boundary failures between retrieval and generation components
  • Test traditional and machine-learning systems for relevant adversarial ML threats, including adversarial inputs, model extraction, model inversion, membership inference, data poisoning, training-data leakage, and abuse of prediction or inference APIs
  • Build reusable scripts, attack harnesses, payload libraries, test datasets, and automated security checks in Python, Bash, or equivalent languages so security testing can be reproduced and integrated into engineering workflows
  • Perform threat modelling for conventional and AI-enabled systems using frameworks such as STRIDE, attack trees, MITRE ATT&CK, MITRE ATLAS, OWASP ASVS, OWASP API Security Top 10, and OWASP guidance for LLM and generative-AI applications
  • Review architecture and code for secure implementation of authentication, authorisation, session management, API security, input validation, output handling, file processing, secrets management, logging, encryption, and data isolation
  • Review OAuth 2.0, OpenID Connect, SAML, RBAC, ABAC, service-to-service authentication, API keys, tokens, and workload identities, and identify privilege-escalation or access-control weaknesses across applications and AI services
  • Integrate and operate security testing within the software delivery lifecycle, including SAST, DAST, SCA, secrets scanning, container and image scanning, IaC scanning, dependency vulnerability management, and security gates within CI/CD pipelines
  • Conduct manual code review and configuration review where automated tooling is insufficient, particularly for high-risk services, custom authentication flows, sensitive-data processing, and AI orchestration logic
  • Assess cloud, Kubernetes, container, network, API-gateway, WAF, secrets-management, logging, and model-serving configurations for exploitable misconfigurations and insecure defaults, working closely with DevOps/SRE and MLOps engineers
  • Review the security of AI model and data supply chains — training and evaluation data, model artefacts, open-source models, third-party APIs, packages, containers, model registries, prompt templates, embeddings, plugins, tools, and external knowledge sources
  • Define and help engineers implement practical mitigations for AI attacks, including prompt and context isolation, privilege minimisation, tool allow-listing, deterministic security controls outside the model, input/output validation, secure retrieval, sandboxing, human approval for high-impact actions, and monitoring for abuse
  • Verify that security controls work in practice by attempting to bypass them rather than relying solely on design documentation or vendor claims
  • Reproduce findings reported by VAPT providers, automated scanners, researchers, or internal teams; determine exploitability and severity; and work directly with engineering teams until remediation is technically verified
  • Support security incident investigation and root-cause analysis, including examination of application logs, cloud and infrastructure telemetry, authentication events, AI interaction logs, model/tool activity, and indicators of compromise or abuse
  • Contribute secure coding patterns, threat models, red-team playbooks, testing utilities, security checklists, and reusable engineering controls that can be adopted across multiple government AI projects
  • Stay current with developments in application security, cloud security, offensive security, adversarial machine learning, LLM security, agent security, and AI supply-chain security, and translate relevant research into practical engineering controls and tests

Important Links

Download Detailed Notification Click Here
Apply Here Click Here
Official Website Click Here

About National e-Governance Division (NeGD)

The National e-Governance Division (NeGD) is an independent business division under the Digital India Corporation, Ministry of Electronics and Information Technology. NeGD has been supporting MeitY in Programme Management and implementing e-governance projects across Ministries/Departments at the Central and State levels.

NeGD has been spearheading several innovative initiatives under the aegis of the Digital India Programme. Those have been developed keeping the vision areas of Digital India at the core- providing digital infrastructure as a core utility to every citizen, governance and services on demand and in particular, digital empowerment of the citizens of our country; some of these initiatives include DigiLocker, UMANG, Poshan Tracker, OpenForge Platform, API Setu, National Academic Depository, Academic Bank of Credits, Learning Management System.