We're building the most loved Fintech in the Middle East - Are you in?

Security Software Engineer

About Alaan

Alaan is the Middle East’s first AI-powered spend management platform, built to help businesses save time and money.
Our all-in-one solution combines smart corporate cards, real-time expense tracking, AI-powered automation, seamless accounting integrations, and deep financial insights- designed to simplify finance operations and maximize control over company spend.

Founded in 2022, Alaan is already the trusted partner of over 2000 leading businesses across the UAE and KSA, including G42, Careem, McDonald’s, Tabby, Al Barari, Rove Hotels, Rivoli, and CarSwitch. Together, our customers have saved over AED 100 million with Alaan.

In just three years, Alaan has become the #1 expense management platform in the Middle East- and we’ve done it while becoming profitable.

Backed by Y Combinator and top global investors- including founders and executives of leading startups- Alaan is built by a world-class team from McKinsey, BCG, Goldman Sachs, Barclays, Zomato, Careem, Rippling, and other high-growth companies.

We’re not just building software. We’re reimagining how finance works for modern businesses across the region.

About the Role

We are looking for a hands-on Security Engineer with 3–5 years of experience in Application Security or Product Security, preferably within FinTech, authentication products, banking, NBFCs, or other regulated industries.

In this role, you will be responsible for securing our applications, APIs, authentication systems, and cloud infrastructure. You will work closely with engineering teams to identify vulnerabilities, improve security architecture, and implement practical security controls that protect our products and customers.

We're looking for someone who has been involved in responding to real-world security incidents—such as fraud, customer-impacting security issues, production breaches, ransomware, or data leaks—and has actively contributed to investigation, remediation, and strengthening security defenses.

What You'll Do

  • Design and develop secure software applications, libraries, and services.
  • Build and maintain authentication and authorization solutions.
  • Implement secure APIs following industry best practices.
  • Develop security automation tools for vulnerability detection and remediation.
  • Perform secure code reviews and identify security weaknesses.
  • Integrate security controls into CI/CD pipelines.
  • Develop solutions for secrets management, encryption, and key management.
  • Implement secure communication using TLS, OAuth2, OpenID Connect, JWT, and related protocols.
  • Collaborate with development teams to remediate application vulnerabilities.
  • Support DevSecOps initiatives by embedding security into software development workflows.
  • Build internal security platforms, SDKs, and reusable security components.
  • Research emerging security threats and recommend mitigation strategies.
  • Contribute to threat modeling, security architecture, and design reviews.

What We're Looking For

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 3-5 years of software development experience with a focus on secure application development.
  • Proficiency in one or more languages: Java, Python, Go, C#, C++, or Rust.
  • Experience building REST APIs and microservices.
  • Strong understanding of secure coding, OWASP Top 10, CWE, and Secure SDLC.
  • Hands-on experience with authentication, authorization, and cryptography fundamentals.
  • Experience with Git, Linux, and Agile development practices.
  • Familiarity with AWS, Azure, or GCP, and container technologies such as Docker and Kubernetes.
  • Experience integrating security into CI/CD pipelines using SAST, DAST, SCA, and container security tools.
  • Knowledge of Infrastructure as Code (Terraform or CloudFormation) and threat modeling.
  • Experience with security automation, developer security tooling, or application security testing is a plus.

Bonus

  • Experience working in Financial Services, Banking, NBFC, FinTech, Identity & Authentication products, or other regulated industries.
  • Familiarity with SIEM platforms, security monitoring, and alert triage.
  • Knowledge of compliance frameworks such as ISO 27001, SOC 2, PCI DSS, or similar security standards.
  • Experience implementing DevSecOps practices and integrating security into CI/CD pipelines.
  • Relevant security certifications such as Security+, CEH, AWS Security Specialty, CCSK, or CISSP.

What's in It for You

  • Opportunity to build secure, scalable products that protect millions of users.
  • High ownership with the ability to influence security architecture and engineering practices.
  • Collaborative engineering culture focused on practical security and continuous improvement.
  • Competitive compensation and comprehensive benefits.
  • Flexible work environment with opportunities for professional growth and learning.
  • Work alongside experienced engineers solving complex security challenges in a fast-growing organization.

Engineering

Bengaluru, India

Share on:

Terms of servicePrivacyCookiesPowered by Rippling