Fynd is a frontier technology company. We started at the intersection of technology and retail because that is where technology was the least available. Over the years, we became one of India’s largest retail technology platforms. But retail was the entry point, not the boundary. Today, Fynd builds intelligent software that runs business operations. Not tools that help people work faster, but systems that absorb entire functions: manufacturing, marketing, logistics, commerce, quality control. We sit inside our customers’ businesses, harvest deep domain context, and build AI systems that operate autonomously. We are expanding from retail into manufacturing, generative media, physical AI, and healthcare.

Role Overview
Fynd operates an AI‑native security function. The function builds and operates its own controls — security gates within CI/CD, cloud‑posture and attack‑surface tooling, detection pipelines, and agentic systems that identify, validate, and prioritise risk across a multi‑cloud estate. The mandate extends, through automation, into product security, privacy engineering, security enablement, and resilience. The role holder will own such controls end to end, applying AI tooling as the primary force multiplier.

Candidates are not expected to hold prior expertise in every area listed below. Candidates are expected to demonstrate the capacity to close knowledge gaps rapidly and independently through the disciplined use of AI tooling: specifying the work, building it, verifying it, and owning the outcome.

What will you do at Fynd?
CI/CD Security and Software Supply Chain
  • Own the security stages of the CI/CD estate (Jenkins, Azure DevOps, GitHub Actions), including SAST, SCA, and secrets detection, such that Critical and High severity findings are prevented from reaching production without impeding release velocity.
  • Reduce false positives through custom validation, thereby maintaining engineering confidence in security gates.
  • Secure the software supply chain, including SBOM generation, dependency and base‑image provenance, and the governance of secrets and non‑human identities across pipelines.
Cloud and Kubernetes Security
  • Harden self‑managed Kubernetes clusters across multiple clouds: RBAC, admission control, network policy, node and operating‑system hardening, and managed‑image patching pipelines.
  • Build and operate cloud security posture and external attack‑surface tooling on GCP, encompassing IAM, organisational policy, and service‑account hygiene, together with automated remediation of identified misconfigurations.
Detection and Response
  • Engineer detection‑as‑code upon the existing observability stack (Prometheus, Grafana, ELK), including eBPF‑based runtime security.
  • Participate in the security on‑call rotation and contribute to incident triage, containment, and post‑incident review.
Vulnerability Management Engineering
  • Engineer the vulnerability pipeline: a single consolidated queue enriched with reachability and exploitability context, governed by severity‑based SLAs, and operating on the principle of find → validate → prioritise → hand over to engineering.
Agentic Security Engineering
  • Design and build agentic security systems: LLM tool calling and MCP, structured outputs, evaluation harnesses that verify agent output, and deterministic‑first architecture with bounded LLM judgement and human override.
  • Secure AI systems in production, including prompt‑injection resistance, tool‑permission scoping, MCP server security, and threat modelling aligned to the OWASP LLM Top 10 and emerging agentic threat taxonomies.
Product and Application Security Automation
  • Engineer automated threat modelling and secure design review: threat models generated and maintained from design documents, API specifications, and infrastructure‑as‑code, with human review reserved for high‑risk changes.
  • Define and enforce API security standards as code: specification linting, authentication and authorisation conformance checks, and continuous discovery of undocumented or unauthenticated endpoints.
  • Build continuous multi‑tenant isolation assurance: automated cross‑tenant access probes executed against production‑representative environments, with regressions treated as release‑blocking defects.
  • Integrate mobile application security testing into the build pipeline for released applications.
  • Engineer the vetting pipeline for third‑party extensions and marketplace submissions: automated static and dynamic screening, credential and secret detection, and permission review prior to listing.
Privacy Engineering Automation
  • Build automated data discovery and classification across datastores and pipelines, maintaining a continuously refreshed map of personal data and its flows.
  • Enforce privacy controls as code: detection of personal data in logs and analytics, retention and deletion enforcement, and encryption and key‑management posture checks.
  • Automate the fulfilment of data‑principal requests (access, correction, erasure) and the supporting evidence trail, aligned to the Digital Personal Data Protection Act and applicable frameworks.
Security Enablement Automation
  • Build behaviour‑driven, personalised security training: modules generated and assigned from observed events — a committed secret, a policy breach, a phishing simulation failure — targeted to the individual, their role, and the systems they touch.
  • Measure enablement by behaviour change (repeat‑incident rate, time to remediate), not by completion rates.
Resilience and Chaos Engineering
  • Automate backup assurance: scheduled restore testing with integrity verification, on the principle that an unverified restore is not a backup.
  • Engineer disaster‑recovery validation: automated failover exercises and game days measured against defined RTOs and RPOs.
  • Practise chaos engineering across Kubernetes workloads and critical dependencies: controlled fault injection to verify graceful degradation under failure.
  • Practise security chaos engineering: controlled injection of security failures — a disabled control, a dropped admission webhook, a simulated credential exposure — to verify that detection and response operate as designed.
  • Validate detections continuously through automated adversary emulation.
Compliance Automation
  • Automate the collection of continuous control evidence (ISO 27001, CIS Benchmarks) in support of ongoing audit readiness.

Some Sepecific Requirements

  • Proficiency in Python, together with Go or advanced shell scripting, and a record of shipping production‑quality tooling rather than scripts.
  • Hands‑on GCP security experience: IAM, networking, and organisational policy, including a working command of authorisation paths.
  • Kubernetes internals and container security on self‑managed clusters.
  • Linux administration and security hardening.
  • Terraform and policy‑as‑code.
  • Depth in code, build, and release management: Git, together with Jenkins, Azure DevOps, or GitHub Actions; familiarity with web servers and reverse proxies (Nginx or equivalent).
  • Fluency in agentic AI‑assisted engineering (Claude Code or equivalent), driven by written specifications and test harnesses, together with the judgement to review AI‑generated code for security defects. Effectiveness of AI leverage is treated as a measure of performance.
  • Demonstrable evidence of building: a public repository, tooling, automation, or technical writing.
  • Two to five years of relevant experience; demonstrated delivery will be given due weight alongside tenure.

Preferred Qualifications (Nice to Have)
  • eBPF runtime security tooling (Falco, Tetragon); distributed tracing and APM applied as security evidence.
  • Chaos engineering tooling (Chaos Mesh, LitmusChaos) and adversary emulation frameworks (Atomic Red Team, Caldera, or equivalent).
  • Exposure to privacy engineering under the Digital Personal Data Protection Act or the GDPR.
  • Mobile application security testing tooling.
  • Working literacy in Kafka, MongoDB, and MySQL; Ansible.
  • GCP Professional Cloud Security Engineer; Certified Kubernetes Security Specialist (CKS).
  • Bug bounty or CTF background.

Why Join Fynd?
A greenfield, AI‑native security function within the Office of the Chief Agentic Security Officer, with build ownership rather than ticket operation.
Meaningful scale: a large multi‑project, multi‑cloud estate with self‑managed Kubernetes.
A culture that treats AI as a development multiplier, backed by substantial investment in AI tooling.

What do we offer?
Growth
At Fynd, growth is limitless. We nurture a culture that encourages innovation, embraces challenges, and supports continuous learning. As we expand into new product lines and global markets, we're seeking talented individuals eager to grow with us.

We believe in empowering our people to take ownership, lead with confidence, and shape their careers.

Learning Wallet: Enrol in external courses or certifications to upskill—we'll reimburse the costs to support your development.

Culture
We believe in building strong teams and lasting connections.
- Regular community engagement and team-building activities
- Biannual events to celebrate achievements, foster collaboration, and strengthen our workplace culture

Wellness
Your well-being is our priority. Comprehensive Mediclaim policy for you, your spouse, children, and parents.

Work Environment
We thrive on collaboration and creativity. Our teams work from the office five days a week to encourage open communication, teamwork, and innovation.
Join us to be part of a dynamic environment where your ideas make an impact!