HighLevel logo

Lead Security Engineer (Penetration Testing)

HighLevel

IndiaRemoteFull-timeNo compensation foundPosted 3w agoVerified open 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
IndiaRemote
Schedule
Full-time
Work Authorization
Not specified

Job overview

HighLevel is hiring a Lead Security Engineer (Penetration Testing). HighLevel seeks a Lead Security Engineer to guide application and AI security across its remote‑first platform. The role involves hands‑on technical leadership, mentoring engineers, and embedding security into the software development lifecycle for a global, AI‑powered sales and marketing solution.

Key focus areas include Lead application security initiatives across HighLevel’s products and engineering teams, Proliferate security standards recommended by central security team as best practices within Dev teams, and Conduct architecture reviews, secure design assessments, and threat modeling for new features and platforms.

Successful candidates bring 8+ Years Of Experience In Cybersecurity. Important skills include Application Security, AI Security, Secure Architecture Decisions, Architecture Reviews, Secure Design Assessments, and Threat Modeling. Preferred (not required): Securing Workloads On Google Cloud Platform (GCP), Infrastructure As Code Security, Terraform, and CSPM Solutions.

Skills & qualifications

RequiredNice to have

Skills

Application SecurityAI SecuritySecure Architecture DecisionsArchitecture ReviewsSecure Design AssessmentsThreat ModelingSecurity Assessments for Web ApplicationsSecurity Assessments for Mobile ApplicationsSecurity Assessments for API-Based ApplicationsSecure SDLC PracticesSecurity Vulnerability RemediationPrompt Injection MitigationData Leakage MitigationInsecure Tool Usage MitigationModel Abuse MitigationEmerging AI Attack Techniques MitigationSecurity Tooling ImprovementAutomate Security Testing Within CI/CD PipelinesSecure Coding PracticesVulnerability ManagementCollaborationCommunicationOWASP StandardsOAuth 2.0OpenID ConnectJWTSAMLSecure Design ReviewsSecure Code ReviewsPenetration TestingDevSecOpsAutomating Security in CI/CD PipelinesContainer SecurityKubernetesDockerManaging Security ToolingSASTDASTSCASecret ScanningModel Misuse MitigationInsecure Agent/Tool Integration MitigationPythonGoJavaScriptBashSecuring Workloads on Google Cloud Platform (GCP)Infrastructure as Code SecurityTerraformCSPM SolutionsIdentify Security VulnerabilitiesPrioritize Security VulnerabilitiesRemediate Security VulnerabilitiesImprove Security ToolingDeveloper EnablementRemediation WorkflowsCommunicate Complex Security RisksInfluence Product RoadmapsStay Current With Emerging ThreatsSecuring Web EnvironmentsSecuring Mobile EnvironmentsSecuring API EnvironmentsDevSecOps ProficiencyREST APIsGraphQL APIsCI/CD PipelinesGCPRed TeamingPurple Team ExercisesData Leakage PreventionModel Misuse PreventionLeadershipCoaching

Qualifications

8+ Years Cybersecurity ExperienceCEH CertificationOSCP CertificationGWAPT CertificationCISSP CertificationGCP Professional Cloud Security Engineer Certification

Full job description

About Us

HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 1 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames.

Our People

With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home.

Our Impact

As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen.

About the Role

We are looking for a Lead Security Engineer– Application Security & AI Security with 8+ years of experience to help secure HighLevel’s products, platforms, and AI-powered capabilities. This is a hands-on technical leadership role focused on building and scaling Application Security practices while driving security initiatives for AI-enabled products.You will work closely with Engineering, Product, Infrastructure, and AI teams to embed security into every stage of the software development lifecycle. You’ll provide technical leadership, mentor engineers, influence secure architecture decisions, and help define the future of security across our engineering organization.

Learn more about us on our YouTube Channel or Blog Posts

What You’ll Be Doing:

  • Lead Application Security initiatives across HighLevel’s products and engineering teams.
  • Proliferate security standards recommended by central security team as best practices within Dev teams.
  • Conduct architecture reviews, secure design assessments, and threat modeling for new features and platforms.
  • Perform security assessments for Web, Mobile, and API-based applications.
  • Define and drive secure SDLC practices across engineering teams.
  • Partner with developers to identify, prioritize, and remediate security vulnerabilities.
  • Lead security reviews for AI/LLM-powered applications, agents, and AI integrations.
  • Develop security guardrails for AI systems, including protections against prompt injection, data leakage, insecure tool usage, model abuse, and emerging AI attack techniques.
  • Improve security tooling and automate security testing within CI/CD pipelines.
  • Champion secure coding practices through developer enablement, documentation, and training.
  • Drive vulnerability management efforts and improve remediation workflows.
  • Mentor engineers and foster a strong security-first engineering culture.
  • Drive cross-functional collaboration by communicating complex security risks to technical and non-technical stakeholders, influencing product roadmaps, and ensuring alignment between security priorities and engineering objectives.
  • Stay current with emerging threats, application security trends, and advancements in AI security.

What You’ll Bring:

  • 8+ years of experience in Cybersecurity, with deep expertise in Application Security and leading engineering-focused security initiatives.
  • Comprehensive technical knowledge in securing Web, Mobile (Android/iOS), and API (REST/GraphQL) environments, including OWASP standards and authentication protocols (OAuth 2.0, OIDC, JWT, SAML).
  • Proven experience performing security assessments including threat modeling, secure design/code reviews, penetration testing, and architecture reviews.
  • Hands-on DevSecOps proficiency: automating security in CI/CD pipelines, container security (Kubernetes/Docker), and managing security tooling (SAST, DAST, SCA, Secret Scanning).
  • Specialized expertise in AI/LLM security, including mitigation of prompt injection, data leakage, model misuse, and insecure agent/tool integration.
  • Proficiency in programming/scripting (Python, Go, JavaScript, or Bash) and strong communication skills to influence technical stakeholders across product and engineering teams.

Preferred Qualifications

  • Experience securing workloads on Google Cloud Platform (GCP).
  • Experience with Infrastructure as Code security (Terraform).
  • Familiarity with CSPM/CNAPP solutions.
  • Experience leading or participating in Red Teaming, adversary simulation, or purple team exercises.
  • Experience with DevSecOps and security automation.
  • Security certifications such as CEH, OSCP, GWAPT, CISSP, GCP Professional Cloud Security Engineer, or similar.
  • Contributions to open-source security projects, bug bounty programs, or security research.

Equal Employment Opportunity Information

The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government record keeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.

#LI-Remote #LI-SS1

You've read the whole posting — now see how you match it.