Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Infosec engineer image - Rise Careers
Job details

Infosec engineer

About the Company:

Ouro is a global, vertically-integrated financial services and technology company dedicated to the delivery of innovative financial empowerment solutions to consumers worldwide. Ouro’s financial products and services span prepaid, debit, cross-border payments, and loyalty solutions for consumers and enterprise partners.

Ouro's flagship product Netspend provides prepaid and debit account solutions that connect customers with secure, convenient access to global payment networks so they can manage their money and make everyday purchases. With a nationwide U.S. retail network, customers can purchase and reload Netspend products at 130,000 reload points and over 100,000 distributing locations.

Since Ouro's founding in 1999 by industry pioneers Roy and Bertrand Sosa, Ouro products have processed billions of dollars in transaction volume and served millions of customers worldwide. The company is headquartered in Austin, Texas with regional offices around the world. Learn more at www.ouro.com.

About the Role

We are seeking a seasoned and highly skilled Senior Application Security Engineer with a proven background in penetration testing, threat hunting, cyber threat intelligence, and digital forensics. This senior-level role will focus on securing applications throughout the software development lifecycle (SDLC) while proactively identifying adversarial threats and supporting incident response. You will drive deep technical initiatives that enhance our organization's security maturity, working cross-functionally with development, DevOps, SOC, and compliance teams.

Key Responsibilities:

Application Security & SDLC Integration:

1. Lead and manage Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) efforts using tools like Fortify, Checkmarx, Burp Suite, and Black Duck.

2. Embed security testing into CI/CD pipelines (GitLab, Jenkins) and enforce secure coding practices across engineering teams.

3. Provide technical guidance on threat modeling, secure design, and risk remediation within Agile and DevOps workflows.

4. Develop and maintain custom automation scripts (Python, Bash) for security validation, report generation, and triage workflows.

Penetration Testing & Vulnerability Research:

5. Plan, conduct, and report manual and automated penetration tests against web, 

mobile, and API services.

6. Simulate advanced adversarial behavior using red team techniques and tools 

(e.g., Burp Suite Pro, OWASP ZAP, Metasploit, Nmap).

7. Research and exploit security vulnerabilities across the application stack; validate

CVEs and 0-days in lab environments.

8. Generate detailed exploit PoCs, attack narratives, and mitigation playbooks for developers and executives.

Threat Intelligence & Hunting:

9. Integrate threat intelligence into vulnerability prioritization and detection engineering using frameworks like MITRE ATT&CK and Kill Chain.

10. Perform proactive threat hunting across logs, WAF telemetry, and behavioral data to identify TTPs indicative of compromise.

11. Write and tune YARA/Sigma detection rules for identifying threats specific to application-layer indicators and attacker infrastructure.

12. Enrich IOCs with contextual intelligence from OSINT, STIX/TAXII, and paid TI platforms (if applicable).

Digital Forensics & Incident Response:

13. Lead forensic investigations for application-layer breaches, using tools such as Volatility, Autopsy, FTK, and The Sleuth Kit.

14. Perform memory, disk, and network traffic analysis to uncover root cause and post-exploitation activity.

15. Participate in IR activities and post-incident reviews to improve detection,containment, and recovery strategies


Minimum Qualifications:

●Bachelor's or Master’s in Computer Science, Cybersecurity, or related field.

●5+ years of experience in application security, penetration testing, or advanced 

security engineering roles.

●Strong expertise in SAST, DAST, and SCA tools.

●Hands-on proficiency with manual penetration testing and vulnerability 

exploitation.

●Proficiency in Python, Bash, and automation toolchains.

●Experience with CI/CD tools: GitLab, GitHub Actions, Jenkins.

●Excellent communication and mentoring skills.

Preferred Skills & Certifications:

●Knowledge of OWASP Top 10, CWE/SANS Top 25, and secure design patterns.

●Familiarity with SIEM and EDR platforms (e.g., Splunk, SentinelOne, 

CrowdStrike).

●Practical understanding of threat intelligence frameworks and IOC enrichment.

●Strong incident response knowledge with hands-on forensic analysis experience.

●Certifications such as:

○OSCP, OSWE, GWAPT (Penetration Testing)

○CISSP, CSSLP (Security Leadership)

○GCTI, GCFA, GNFA (Threat Intel & Forensics)

Preferred Attributes:

●Proactive and analytical thinker with strong attention to detail.

●Passion for mentoring junior engineers and security champions.

●Ability to collaborate effectively across development, infrastructure, and security

operations.

●Commitment to continuous learning in threat trends, tooling, and best practices.

Average salary estimate

$120000 / YEARLY (est.)
min
max
$100000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Infosec engineer, Ouro

Ouro, a global leader in financial services and technology, is on the lookout for an innovative and experienced Infosec Engineer to join our vibrant team in Noida. As a Senior Application Security Engineer, you'll play a crucial role in fortifying our applications throughout the software development lifecycle (SDLC). This isn't just a routine job; you'll be deep diving into penetration testing, threat hunting, and enhancing our security measures while working closely with our development, DevOps, SOC, and compliance teams. We're looking for someone who not only understands the complexities of application security but also possesses a passion for mentoring others and sharing knowledge. You'll manage static and dynamic security tests, integrate security practices into CI/CD pipelines, and conduct penetration tests against our web, mobile, and API services. Your ability to synthesize threat intelligence and conduct thorough incident responses will be invaluable as we seek to proactively identify adversarial threats. We value attention to detail and a proactive approach, so your contributions will help shape our security strategy at Ouro. If you’re ready to tackle challenges and drive our organization's security maturity to new heights, we can't wait to meet you!

Frequently Asked Questions (FAQs) for Infosec engineer Role at Ouro
What are the main responsibilities of an Infosec Engineer at Ouro?

As an Infosec Engineer at Ouro, your main responsibilities include managing Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) efforts, conducting penetration tests on various services, and providing guidance on secure coding practices throughout the SDLC. You will also embed security testing into our CI/CD pipelines while collaborating with cross-functional teams.

Join Rise to see the full answer
What qualifications are required to apply for the Infosec Engineer position at Ouro?

To apply for the Infosec Engineer position at Ouro, you should have a Bachelor's or Master’s degree in Computer Science, Cybersecurity, or a related field, along with 5+ years of experience in application security or penetration testing. Strong expertise in SAST, DAST, and SCA tools, as well as proficiency in Python and Bash, are also required.

Join Rise to see the full answer
What technologies do you use for penetration testing as an Infosec Engineer at Ouro?

At Ouro, we utilize a variety of tools and technologies for penetration testing, including Burp Suite Pro, OWASP ZAP, Metasploit, and more. Your role will involve planning and executing both manual and automated tests to ensure the security of our web, mobile, and API services.

Join Rise to see the full answer
How does the Infosec Engineer collaborate with other teams at Ouro?

The Infosec Engineer at Ouro collaborates closely with development, DevOps, SOC, and compliance teams to integrate security practices within Agile workflows. You'll provide technical guidance on threat modeling and secure design, and your insights will enhance the organization’s overall security posture.

Join Rise to see the full answer
What is the importance of threat intelligence for an Infosec Engineer at Ouro?

Threat intelligence is crucial for an Infosec Engineer at Ouro as it helps prioritize vulnerabilities and enhance detection engineering. By integrating frameworks like MITRE ATT&CK into your work, you'll proactively hunt for threats and enrich incident response strategies, thereby strengthening our security measures significantly.

Join Rise to see the full answer
Common Interview Questions for Infosec engineer
Can you explain your experience with SAST and DAST tools?

Certainly! In my previous roles, I've extensively used SAST tools like Fortify and Checkmarx to identify vulnerabilities during the development phase. I also regularly engaged with DAST tools such as Burp Suite for runtime testing, which allows me to uncover real-time vulnerabilities. My experience has taught me to integrate these tools seamlessly into the CI/CD pipeline.

Join Rise to see the full answer
How do you ensure secure coding practices in an Agile environment?

To ensure secure coding practices in an Agile environment, I advocate for incorporating security into each sprint. This includes conducting regular security workshops and code reviews to guide developers in implementing secure design patterns and risk remediation throughout the development process.

Join Rise to see the full answer
Describe a challenging penetration test you've conducted.

In one challenging penetration test, I had to assess an API service with complex authentication mechanisms. I employed both manual and automated tools to simulate real-world attack scenarios, identifying critical vulnerabilities. The experience taught me the importance of creativity and critical thinking in security assessments.

Join Rise to see the full answer
What steps do you take in threat hunting?

In threat hunting, I start by analyzing logs and behavioral data to identify anomalies. I integrate threat intel frameworks like MITRE ATT&CK to guide my approach and leverage detection tools to identify potential threats. This proactive methodology allows me to uncover TTPs indicative of compromise effectively.

Join Rise to see the full answer
How familiar are you with compliance standards relevant to application security?

I am well-versed in compliance standards relevant to application security, such as OWASP Top 10 and CWE/SANS Top 25. I utilize these standards to guide security practices and ensure compliance during development and testing phases.

Join Rise to see the full answer
What role does documentation play in your security processes?

Documentation is crucial in my security processes as it provides transparency and a roadmap for security measures. I always produce detailed reports after penetration tests, including vulnerability findings, exploit PoCs, and recommended mitigation strategies, ensuring that all stakeholders are informed.

Join Rise to see the full answer
Can you discuss your experience with incident response?

Certainly! My experience with incident response involves leading forensic investigations and analyzing data from various sources. I'm familiar with tools like Autopsy and FTK, and my method includes documenting the entire process for post-incident reviews to enhance future response strategies.

Join Rise to see the full answer
How do you stay updated with the latest security trends?

To stay updated with the latest security trends, I regularly participate in webinars, attend industry conferences, and read industry publications. Engaging with the cybersecurity community through forums and social media also helps me keep abreast of emerging threats and tools.

Join Rise to see the full answer
What programming languages do you use for automation in security?

I primarily use Python for automation due to its versatility and extensive libraries, but I also work with Bash scripts for quick automation tasks. This allows me to create custom scripts for security validation, report generation, and workflows to enhance efficiency.

Join Rise to see the full answer
How do you assess and prioritize vulnerabilities?

I assess vulnerabilities based on their impact and exploitability, typically using a combination of threat intelligence and risk assessment frameworks. This prioritization drives our response efforts by focusing on high-risk vulnerabilities that could significantly impact our systems.

Join Rise to see the full answer
Similar Jobs

Join UChicago Medicine as an Inpatient Orders Analyst - Associate in a remote role and help advance healthcare through technology.

Photo of the Rise User
ASUCLA Remote US, Los Angeles County, CA; California, Los Angeles, CA
Posted 2 days ago

Join Associated Students UCLA as a NetSuite Administrator/Developer and play a key role in managing their NetSuite ERP and driving innovative solutions.

Photo of the Rise User
Posted 13 days ago

Nayya is looking for a Senior Security Risk & Compliance Analyst to lead their governance, risk, and compliance initiatives while enhancing their security posture.

Photo of the Rise User
Posted 10 days ago

The Director of AI Technology at CyberArk will spearhead the development and scaling of innovative AI capabilities within a cross-functional team.

Photo of the Rise User
Posted 12 days ago

A leading company is looking for a skilled Senior Business System Analyst to enhance their manufacturing systems and provide actionable insights through Power BI.

Photo of the Rise User
Posted 6 days ago

Join Egis as an Oracle Administrator where you'll enhance data integrity and quality in a pivotal role for our global consulting efforts.

Photo of the Rise User
METRO/MAKRO Remote Metro-Straße 1, 40235 Düsseldorf, Germany
Posted 4 days ago

Join METRO as an IT & Information Security Risk and Compliance Expert and take the lead in managing IT risks in a dynamic global environment.

Photo of the Rise User
Intersec Group Remote No location specified
Posted 13 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Family Medical Leave
Paid Holidays
Sabbatical

Join Intersec in La Défense as a Tech Support Technician, where you'll support our engineering team and enhance our IT infrastructure.

Netspend & Rêv come together to be the most innovative & accessible company in financial services, focused on helping consumers around the world manage and get more value for their money.

36 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
10 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Steubenville just viewed Digital Marketing Content Intern at Sanction Scanner
Photo of the Rise User
Someone from OH, Cleveland just viewed Data Labeling Associate - 6 Month Contract at Citylitics
Photo of the Rise User
Someone from OH, Dublin just viewed Trainee Database Engineer - IN ( Oracle ) at Rackspace
Photo of the Rise User
13 people applied to ITSM Specialist at Datacom
C
Someone from OH, Lorain just viewed RN Ambulatory - Dermatology at CCF
Photo of the Rise User
Someone from OH, New Albany just viewed Jr Data Scientist (Hybrid) at NielsenIQ
Photo of the Rise User
7 people applied to Cybersecurity Intern at Terumo
Photo of the Rise User
Someone from OH, Lewis Center just viewed Banking Sector | PL/SQL Developer (Hybrid) at Devoteam
Photo of the Rise User
Someone from OH, Loveland just viewed Director, Change Management at Visa
Photo of the Rise User
14 people applied to IT Intern - Seasonal at Carowinds
Photo of the Rise User
Someone from OH, Columbus just viewed Manager, People Partner (Remote, US) at Renew Home
Photo of the Rise User
Someone from OH, Pleasant Hill just viewed Manager, Strategic Partnerships at Lindenwood University
Photo of the Rise User
Someone from OH, Columbus just viewed Associate Director, US HCP Marketing at Sobi
Photo of the Rise User
9 people applied to Cybersecurity Architect at CAI
C
Someone from OH, Cincinnati just viewed Injection Molding Machine Operator at Clarios
Photo of the Rise User
Someone from OH, Columbus just viewed Senior XM Advisor - Customer Experience at Qualtrics
Photo of the Rise User
Someone from OH, Columbus just viewed Dynamics 365 Senior Functional Consultant at ARO
Photo of the Rise User
Someone from OH, Canton just viewed Consultant- Natural Resources at Esri
Photo of the Rise User
Someone from OH, Strongsville just viewed Digital Operations Specialist at Riverside Insights
Photo of the Rise User
Someone from OH, Delaware just viewed Casting: 'Séance At The Museum' at Backstage
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff UX Researcher at ServiceNow
Photo of the Rise User
Someone from OH, Greenville just viewed Information Security Analyst at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director Advisory & Client Services at Mitratech