Skip to content

Open nowPosted 262 days ago

Senior Offensive Security Engineer(Cloud Operations)

Bazaarvoice26 open roles

Where
Bengaluru
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Offensive Security Engineer(Cloud Operations)Bazaarvoice · Bengaluru
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Bazaarvoice's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.2%14 days
  5. 34.5%30 days
This job: posted 262 days ago

The posting

About Bazaarvoice

At Bazaarvoice, we create smart shopping experiences. Through our expansive global network, product-passionate community & enterprise technology, we connect thousands of brands and retailers with billions of consumers. Our solutions enable brands to connect with consumers and collect valuable user-generated content, at an unprecedented scale. This content achieves global reach by leveraging our extensive and ever-expanding retail, social & search syndication network. And we make it easy for brands & retailers to gain valuable business insights from real-time consumer feedback with intuitive tools and dashboards. The result is smarter shopping: loyal customers, increased sales, and improved products.

The problem we are trying to solve : Brands and retailers struggle to make real connections with consumers. It's a challenge to deliver trustworthy and inspiring content in the moments that matter most during the discovery and purchase cycle. The result? Time and money spent on content that doesn't attract new consumers, convert them, or earn their long-term loyalty.

Our brand promise : closing the gap between brands and consumers.

Founded in 2005, Bazaarvoice is headquartered in Austin, Texas with offices in North America, Europe, Asia and Australia.

It’s official: Bazaarvoice is a Great Place to Work in the US , Australia, India, Lithuania, France, Germany and the UK!

We are looking for a Senior Offensive Security Engineer who is a "Jack of all trades, Master of some." You don’t need to be a world-class Red Teamer AND a Cloud Architect; rather, you need a solid foundation in offensive security, operational experience in cloud platforms (AWS/GCP) and the maturity to manage our external penetration testing and bug bounty programs. As a leader within our proactive security strategy, you will drive the identification of complex vulnerabilities through expert management of third-party tests and by leading sophisticated, in-depth internal assessments of our cloud infrastructure. You will operate with a high degree of autonomy, tackling significant security challenges while mentoring others to influence strategy across the organization.

Shift Hours: This position will have working hours of 1:00 PM to 10:00 PM IST (Indian Standard Time) and will allow for a mixture of in-office and work from home.

What You'll Be Doing:

  • Lead Offensive Security Engagements: Own and execute complex, end-to-end internal penetration tests against Bazaarvoice's most critical applications, infrastructure, and cloud environments. You will simulate advanced, multi-stage attack scenarios to uncover systemic security weaknesses before they can be exploited.
  • Program and Tooling Enhancement: Take a lead role in defining the strategy for our offensive security capabilities. You will research, prototype, and implement new tools, techniques, and automation to mature our testing processes and keep pace with the evolving threat landscape.
  • Strategic Third-Party Penetration Test Management: Act as the primary technical lead for our third-party penetration testing program. You will not only manage the engagement lifecycle but also define the strategic direction of our testing roadmap, ensuring we partner with providers to target the highest-risk areas of our business.
  • Bug Bounty Program Leadership: Design, lead, and operate all aspects of our bug bounty program, serving as the technical interface for third-party researchers and coordinating internal responses to submitted vulnerability findings, ensuring clear communication and timely resolution.
  • Mentorship and Technical Leadership: Mentor junior team members and act as a security champion and trusted advisor to engineering teams. You will elevate the security knowledge across the organization by leading training sessions, developing secure coding guidelines, and providing expert consultation on secure architecture.
  • Threat Modeling: Proactively engage with development teams early in the SDLC to conduct threat modeling exercises, helping them build more secure products from the ground up.

Required Skills and Experience:

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience with 10+ years of related experience.
  • 7+ years of hands-on experience in offensive security, with a strong background in penetration testing, red teaming, or application security.
  • Operational Cloud Expertise: 3-5 years of hands-on experience operating in, managing, or performing manual penetration tests of cloud infrastructure (AWS preferred), with a deep understanding of cloud-native attack vectors (e.g., IAM exploitation, container escapes, and serverless security).
  • Expert-level knowledge in managing the lifecycle of penetration testing engagements and a proven track record of driving remediation efforts in a complex, multi-team environment.
  • Deep and practical understanding of common and advanced vulnerability classes (OWASP Top 10 and beyond) and the ability to architect solutions to remediate them at scale.
  • High proficiency in one or more scripting languages (e.g., Python, Go, Bash) for advanced tool development and automation of complex tasks.
  • Exceptional communication and interpersonal skills, with a demonstrated ability to influence technical and non-technical stakeholders at all levels, including senior leadership.
  • A proven history of mentorship and a passion for elevating the skills of those around you.

Desired Skills and Experience:

  • Advanced offensive security certifications such as OSCP, OSWE, OSEP, GPEN, GXPN, or equivalent.
  • Deep expertise in AWS cloud security operations and infrastructure-as-code security.
  • Experience building and maturing an offensive security program or function.
  • Demonstrated experience leading red team or purple team exercises.
  • Published security research, conference presentations, or active contributions to the open-source security community.
  • Experience in a Security Development Lifecycle (SDL) environment and a history of implementing DevSecOps principles. Why You’ll Love Working with Us? Work with cutting-edge tech in an innovative, collaborative environment. Competitive salary + good benefits (insurance, annual leave, bonuses, referral rewards, and more). We’reGreat Place to Work Certified (3 years in a row!). Hybrid work model (3 days in office – Prestige Tech Pacific, Kadubeesanahalli). Interview Process: Tech Round 1 Tech Round 2 Hiring Manager Meeting: Team, values & culture check. Final Round: Chat with HR/Senior Leadership. Disclaimer: All Official communications from Bazaarvoice recruitment originates strictly from our verified domain (@bazaarvoice.com). Bazaarvoice does not send recruitment emails from different domains. Bazaarvoice never requests payment / financial deposits as part of our selection process. All legitimate career opportunities and application details are listed on our official careers page. (https://www.bazaarvoice.com/company/careers/) Bazaarvoice is not responsible for any unauthorized emails or interactions originating outside the official web domain.

#LI-Hybrid#LI-CK1

Why join Bazaarvoice?

Customer is key

We see our own success through our customers’ outcomes.

We approach every situation with a customer first mindset.

Transparency & Integrity Builds Trust

We believe in the power of authentic feedback because it’s in our DNA.

We do the right thing when faced with hard choices. Transparency and trust accelerate our collective performance.

Passionate Pursuit of Performance

Our energy is contagious, because we hire for passion, drive & curiosity.

We love what we do, and because we’re laser focused on our mission.

Innovation over Imitation

We seek to innovate as we are not content with the status quo.

We embrace agility and experimentation as an advantage.

Stronger Together

We bring our whole selves to the mission and find value in diverse perspectives.

We champion what’s best for Bazaarvoice before individuals or teams.

As a stronger company we build a stronger community.

Discover Life at Bazaarvoice

Want to see our culture in action? Explore our channels to see the bigger picture and meet the teams behind the tech: Global perspective : Head over to our global Linkedin Life Page, Life at Bazaarvoice to see what makes us tick worldwide.

Regional Teams: Visit our APAC Life Page to see what life is like in our local offices.

Want an inside look at Bazaarvoice India? > Follow our journey and check out our team reviews on AmbitionBox

Commitment to diversity and inclusion

Bazaarvoice provides equal employment opportunities (EEO) to all team members and applicants according to their experience, talent, and qualifications for the job without regard to race, color, national origin, religion, age, disability, sex (including pregnancy, gender stereotyping, and marital status), sexual orientation, gender identity, genetic information, military/veteran status, or any other category protected by federal, state, or local law in every location in which the company has facilities. Bazaarvoice believes that diversity and an inclusive company culture are key drivers of creativity, innovation and performance. Furthermore, a diverse workforce and the maintenance of an atmosphere that welcomes versatile perspectives will enhance our ability to fulfill our vision of creating the world’s smartest network of consumers, brands, and retailers.

Please note that a standard background verification (BGV) forms part of our selection process. This will be conducted with your consent and will strictly focus on information relevant to the role.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Bazaarvoice's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Bazaarvoice's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Bazaarvoice's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.