Product Security Engineer (App Security)

35 Minutes ago • 1-5 Years

Job Summary

Job Description

The Application Security Engineer will be responsible for strengthening the security of web applications, APIs, and mobile apps. This involves performing penetration testing, conducting secure code reviews (primarily in Java, Python, and JavaScript), and developing security automation solutions using Python. The engineer will work closely with development teams, create and maintain threat models, and educate developers on secure coding practices. The role requires identifying and mitigating vulnerabilities, ensuring timely resolution of security issues within fast-paced release cycles, and effectively communicating security findings to stakeholders.
Must have:
  • 1-5 years of experience in application security or related fields.
  • Strong penetration testing expertise with tools like Burp Suite and OWASP ZAP.
  • Experience integrating security into SDLC and familiarity with DevSecOps tools.
  • Proficiency in secure coding principles, OWASP Top 10, and exploit techniques.
  • Strong scripting skills (Python preferred) for security automation.
  • Excellent communication and stakeholder management abilities.
Good to have:
  • Certifications like OSCP, OSWE, CRTP.
  • Proven Bug Bounty track record and/or CTF participation
Perks:
  • Insurance Benefits (Medical, Critical Illness, Accidental, Life)
  • Wellness Program (Employee Assistance, Onsite Medical Center, Emergency Support)
  • Parental Support (Maternity, Paternity, Adoption Assistance, Day-care Support)
  • Mobility Benefits (Relocation, Transfer Support, Travel)
  • Retirement Benefits (PF, Gratuity, NPS, Leave Encashment)
  • Other Benefits (Higher Education Assistance, Car Lease, Salary Advance)

Job Details

About PhonePe Group: 

PhonePe is India’s leading digital payments company with 50 crore (500 Million) registered users and 3.7 crore (37 Million) merchants covering over 99% of the postal codes across India. On the back of its leadership in digital payments, PhonePe has expanded into financial services (Insurance, Mutual Funds, Stock Broking, and Lending) as well as adjacent tech-enabled businesses such as Pincode for hyperlocal shopping and Indus App Store which is India's first localized App Store. The PhonePe Group is a portfolio of businesses aligned with the company's vision to offer every Indian an equal opportunity to accelerate their progress by unlocking the flow of money and access to services.

Culture

At PhonePe, we take extra care to make sure you give your best at work, Everyday! And creating the right  environment for you is just one of the things we do. We empower people and trust them to do the right  thing. Here, you own your work from start to finish, right from day one. Being enthusiastic about tech is a  big part of being at PhonePe. If you like building technology that impacts millions, ideating with some of  the best minds in the country and executing on your dreams with purpose and speed, join us!

Job Description – 


We are looking for a skilled Application Security Engineer to strengthen our security posture by proactively identifying and mitigating vulnerabilities across our web applications, APIs, and mobile apps. The ideal candidate will have a strong background in penetration testing, secure code review, and security automation.

Roles & Responsibilities(What will you do):

-Perform penetration testing of web applications, APIs, and mobile apps, providing in-depth vulnerability analysis and remediation guidance.

-Conduct manual and automated secure code reviews, primarily in Java, Python, and JavaScript.

-Develop security automation solutions using Python to streamline testing, improve coverage, and reduce manual effort.

-Work closely with development teams to ensure timely resolution of security issues within fast-paced release cycles.

-Create and maintain threat models, applying threat modeling techniques to proactively identify and mitigate design-level security risks.

-Foster a security-first mindset by educating developers on secure coding practices, common vulnerabilities, and attack vectors while effectively communicating security findings to stakeholders.



What Makes You a Great Fit

-1-5 years of experience in application security, penetration testing, or related fields.

-Strong penetration testing expertise with tools like Burp Suite, OWASP ZAP, semgrep, MobSF, Jadx-GUI and other mobile security testing frameworks.

-Experience integrating security into SDLC and familiarity with DevSecOps tools.

-Proficiency in secure coding principles, OWASP Top 10, CWE, and exploit techniques.

-Strong scripting skills (Python preferred) for security automation.

-Excellent communication and stakeholder management abilities.

-Passion for continuous learning and staying updated on security trends.

-Certifications like OSCP, OSWE, CRTP, or a proven Bug Bounty track record and/or CTF partipation are a plus

PhonePe Full Time Employee Benefits (Not applicable for Intern or Contract Roles)

  • Insurance Benefits - Medical Insurance, Critical Illness Insurance, Accidental Insurance, Life Insurance
  • Wellness Program - Employee Assistance Program, Onsite Medical Center, Emergency Support System
  • Parental Support - Maternity Benefit, Paternity Benefit Program, Adoption Assistance Program, Day-care Support Program
  • Mobility Benefits - Relocation benefits, Transfer Support Policy, Travel Policy
  • Retirement Benefits - Employee PF Contribution, Flexible PF Contribution, Gratuity, NPS, Leave Encashment 
  • Other Benefits - Higher Education Assistance, Car Lease, Salary Advance Policy

Working at PhonePe is a rewarding experience! Great people, a work environment that thrives on creativity, the opportunity to take on roles beyond a defined job description are just some of the reasons you should work with us. Read more about PhonePe on our blog.

Life at PhonePe

PhonePe in the news

Similar Jobs

KBG Blockchain Game Studios - Blockchain Developer (BSC)

KBG Blockchain Game Studios

Thành Phố Hồ Chí Minh, Vietnam (On-Site)
10 Months ago
ByteDance - Backend Software Engineer - Global E-Commerce Supply Chain

ByteDance

Seattle, Washington, United States (On-Site)
6 Months ago
gravitee.io - Sales Engineer

gravitee.io

London, England, United Kingdom (Hybrid)
1 Month ago
ByteDance - Test Development Engineer - Global Payment - San Jose

ByteDance

San Jose, California, United States (On-Site)
5 Months ago
ByteDance - Big Data Engineer, Data Lake / Feature Store

ByteDance

Singapore (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Blitre Rewards - Back End Engineer

Blitre Rewards

New York, New York, United States (On-Site)
2 Weeks ago
Microsoft - Member of Technical Staff - Full Stack Software Engineer

Microsoft

Redmond, Washington, United States (Hybrid)
4 Weeks ago
Google - Early Career Software Engineer, People with Disabilities

Google

State Of Minas Gerais, Brazil (On-Site)
4 Months ago
LeoVegas - Data Engineer

LeoVegas

Stockholm, Stockholm County, Sweden (Hybrid)
1 Month ago
Zazz - Machine Learning Engineer

Zazz

(Remote)
3 Months ago
Token Metrics - Crypto Senior Backend Engineer (Remote)

Token Metrics

Medellín, Antioquia, Colombia (Remote)
6 Months ago
Litmus - Lead Software Engineer - Java

Litmus

Pune, Maharashtra, India (On-Site)
2 Weeks ago
Limit Break - Unity UI Engineer (Japan)

Limit Break

Tokyo, Japan (On-Site)
1 Month ago
Meta - Software Engineer, Machine Learning

Meta

Fremont, California, United States (Remote)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Google - Technical Program Manager, Health and Home Engineering Productivity

Google

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Mobiloitte - Senior UI/UX Designer

Mobiloitte

New Delhi, Delhi, India (On-Site)
3 Months ago
PwC - IN_Manager _Technical Delivery Manager_ Emerging Technologies_ Advisory_ Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Skillz - Executive Assistant II

Skillz

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Aeries Technology - Staff Accountant

Aeries Technology

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Philips - Sales Manager

Philips

Bengaluru, Karnataka, India (On-Site)
1 Year ago
INTEL - Bluetooth Systems Validation Engineer

INTEL

Bengaluru, Karnataka, India (On-Site)
1 Day ago
PwC - Senior Associate -SAP SD-Bangalore-TC

PwC

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Salesforce - Database Systems Development - Senior/Lead/Principal Member Technical Staff

Salesforce

Hyderabad, Telangana, India (On-Site)
6 Months ago
Truecaller - Lead -Customer Success

Truecaller

Mumbai, Maharashtra, India (On-Site)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

PhonePe was founded in December 2015 and has emerged as India’s largest payments app, enabling digital inclusion for consumers and merchants alike. With 48 crore (480 Million) registered users, one in four Indians are now on PhonePe. The company has also successfully digitized 3.6 crore (36 Million) offline merchants spread across Tier 2,3,4 and beyond, covering 99% of the postal codes across India. PhonePe is also the leader in Bharat Bill Pay System (BBPS), processing over 45% of the transactions on the BBPS platform. PhonePe forayed into financial services in 2017, providing users with safe and convenient investing options on its platform. Since then, the company has introduced several Mutual Funds and Insurance products that offer every Indian an equal opportunity to unlock the flow of money and access to services. PhonePe was recently recognized as the Most Trusted Brand for Digital Payments as per the Brand Trust Report 2023 by Trust Research Advisory (TRA).



Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Kota, Rajasthan, India (On-Site)

Karnataka, India (On-Site)

India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Mumbai, Maharashtra, India (On-Site)

View All Jobs

Get notified when new jobs are added by Phonepe

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug