Our first dedicated security hire. You will be an individual contributor building the function.
Seekho is built on one simple belief: make learning fun and easy for everyone.
We are India's #1 video edutainment platform, helping people learn real-world skills through short, expert-led videos across digital services, business, Spoken English, and much more. Founded in 2020 by IIT Kanpur alumni Rohit Choudhary, Keertay Agarwal and Yash Banwani, we are trusted by 4M+ paid subscribers and were ranked No. 2 in Google Play's Top Trending App 2025 list.
You'll own security across all of our products. With a large engineering team shipping daily, that means building secure defaults and tooling that scale rather than reviewing everything by hand — security that's automatic, continuous and owned. It's a high-ownership role with significant independence, and you'll succeed by partnering closely with engineering teams.
- Enforce server-side authorization; defend against account takeover, promo abuse, payment tampering, and content piracy.
- Secure our mobile and AI surfaces, and keep children's, health, and payment data least-privilege and audited.
- Make SAST, DAST, SCA and secret scanning default in CI/CD, and keep results trustworthy so engineers act on them.
- Own our cloud posture — VPCs, security groups, IAM, secrets management, and threat detection.
- Run vulnerability management — the VAPT cadence and a channel for outside researchers to report issues and see fixes through.
- Build security incident management end to end, detection to postmortem, against India's short breach-reporting clock.
- Build Seekho's security platform — the internal libraries and guardrails engineers build on.
- 4+ years in security, with real depth in application and API security.
- You think in terms of how systems get exploited, not just vulnerability categories.
- You can explain an authorization flaw in unfamiliar code, and code in Python or Go to build tooling.
- Working knowledge of cloud security — IAM, secrets, network controls, and threat detection.
- You've found real vulnerabilities yourself — a bounty, a VAPT finding, a CVE, or in your own product.
- Practical incident management, detection through postmortem — you've worked a real incident, not just written the plan.
- You've owned security in-house for a shipping product, as the first or only security person.
- India's data-protection landscape (DPDP, SPDI/IT Act) and comfort partnering with legal/DPO
- Payments and subscription fraud, RBI autopay and tokenization;
- Children's-data obligations and Play Families / Apple Kids compliance;
- AI/LLM application security
- Exposure to ISO 27001 or SOC 2.