Senior Engineer, Product Security

3 Months ago • 3-5 Years • Cyber Security

Job Summary

Job Description

Senior Product Security Engineer responsible for reviewing code for vulnerabilities, writing custom rules for automated source code scanning, managing security integration into CI/CD pipelines, identifying areas for automation, building security into infrastructure, writing reports and recommendations, establishing metrics, working with engineering teams on remediation, conducting security reviews, threat modeling, risk analysis, mentoring junior team members, and acting as a subject matter expert. The ideal candidate possesses deep understanding of attack surfaces in modern applications and operating systems and can analyze closed source applications using various tools. The role requires proficiency in multiple programming languages, DevOps principles, cloud security (AWS/Azure), and experience with application security tools.
Must have:
  • Review code for security vulnerabilities
  • Write custom rules for code scanning tools
  • Manage security integration into CI/CD
  • Experience with application security tools
  • Proficient in Python, Java, Ruby etc.
  • DevOps principles and code pipelines
  • Understanding of AWS and cloud security
  • Threat modeling and risk analysis
Good to have:
  • Security Certifications
  • Programming Certifications

Job Details

About the job

Equal Opportunity Employer

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, or disability status. EEO/AA/M/F/Disabled/Vets

Job Description :

Title: Senior Product Security Engineer

Location: Bengaluru

Working Type: Hybrid (Mandate to be in office for 3 days)

Job Description Details:

We are currently seeking a Senior Engineer, Product Security to join our Information Security team, based in Bangalore, Karnataka, India. The ideal candidate will possess a deep understanding of attack surfaces in modern compiled applications and operating systems.

Candidates must demonstrate the ability to analyze closed source applications using several off-the-shelf or custom developed tools. Additionally, the ideal candidate will be able to demonstrate exceptional organizational skills, work efficiently under minimal supervision, be able to deliver results that meet or exceed organization’s expectations, be a strong team player, and actively participate in a fast-paced and challenging global environment.

Key Responsibilities:

  • Review code for security vulnerabilities and practices dangerous to security and privacy.
  • Write custom rules on automated source code scanning tools
  • Script (Python, Perl, Ruby,Java) and build automation tools on an ad-hoc basis
  • Manage security integration into the CI/CD pipeline
  • Manage integration with manual and automated tools for static and dynamic testing
  • Identify areas for automation and tooling to increase code coverage
  • Build security into infrastructure and architecture designs and guide the implementation with the operations team
  • Write reports including recommendations, root cause analysis, security summary analysis, and project roadmaps
  • Establish metrics and reporting to track coverage and effectiveness of security processes,work with Engineering teams to drive remediation efforts.
  • Engage with product and developers to conduct security reviews and define security requirements
  • Mentor junior members of the team and act as a subject matter expert for application security issues
  • Conduct threat modeling and risk analysis to identify exposure and develop mitigation plans

Requirements:

  • Bachelor’s degree in computer science, software engineering or equivalent experience
  • 3 to 5 years of software development with at least 2 years in developing secure systems.
  • Experience in one or more of the following modern languages/frameworks - Python, Java,Ruby, node.js, JavaScript, PHP
  • Proficiency in version control tools like Git.
  • Thorough understanding of DevOps principles and building code pipelines
  • Experience with cloud security, particularly for AWS and/or Azure Experience with integrating security into a DevOps culture. Familiarity with Docker images, AWS Secrets Manager and Parameter Store.
  • A strong understanding of modern development processes including agile development
  • Solid understanding of application security topics such as authn, authz, encryption, session management, Identity Federation (Open ID, OAuth, SAML)
  • Extensive experience with application security tools like code scanners(Checkmarx,Fortify,Synk, Nexus) and dynamic analysis tools (Burp,Zap etc)
  • Experience with common information security management frameworks like NIST CSF, NIST SP 800,OWASP
  • Hands-on with AWS and how to deploy/run Python applications in the cloud.
  • Hands-on experience with OWASP Top 10 standards, including mitigation of common threats like SQL Injection and Cross-Site Scripting etc.

Minimum Qualifications:

  • 3 to 5 years of software development with at least 2 years in developing secure systems.
  • Experience in one or more of the following modern languages/frameworks - Python, Java,Ruby, node.js, JavaScript, PHP
  • Proficiency in version control tools like Git.
  • Thorough understanding of DevOps principles and building code pipelines
  • A passion for application security related problems.Working knowledge of web application vulnerabilities and mitigations.
  • Known for being a great communicator and collaborator with excellent written and verbal communication skills

Additional licensing, certifications preferred:

  • Security Certifications
  • Programming Certifications

This job is posted with NTS Technology Services Pvt. Ltd.

Job Category:

Similar Jobs

SuperPlay - BUSINESS DATA ANALYST LEAD

SuperPlay

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
3 Months ago
Enphase Energy - Staff Engineer - Enlighten Cloud - Frontend

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
1 Month ago
ION - Cloud Engineer Kubernetes

ION

Rome, Lazio, Italy (Hybrid)
4 Months ago
ByteDance - Backend Software Engineer Graduate (Global E-commerce-US) - 2025 Start (BS/MS)

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
Larian Studios - SENIOR 3D RIGGER

Larian Studios

Quebec, Canada (On-Site)
2 Months ago
Saviynt - Consultant, Professional Services, IAM/IGA

Saviynt

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Canva - Engineering Manager (BE) - Security Platform Engineering (Remote across ANZ)

Canva

Melbourne, Victoria, Australia (Remote)
3 Months ago
Google - Staff Software Engineer, Security/Privacy, Google Cloud

Google

Sunnyvale, California, United States (On-Site)
1 Month ago
PwC - Practice Lead Identity and Access Management (IAM)

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago
The Walt Disney Company - Vice President, Global Security - APAC

The Walt Disney Company

Singapore, Singapore (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

ByteDance - Global SRE Lead, Security Engineering

ByteDance

Singapore (On-Site)
3 Months ago
Activision - Data Analyst Co-op

Activision

Vancouver, British Columbia, Canada (Hybrid)
1 Month ago
Light Speed Studios - Senior Technical Artist

Light Speed Studios

Irvine, California, United States (On-Site)
2 Months ago
Playrix - Middle C++ Software Engineer (Gameplay)

Playrix

Portugal (Remote)
4 Months ago
Appier - Software Engineer, Data Backend(Data Platform)

Appier

Taipei City, Taiwan (On-Site)
3 Months ago
Qventus,  Inc  - Senior Data Engineer

Qventus, Inc

Noida, Uttar Pradesh, India (Hybrid)
3 Months ago
N-iX - Lead/Senior Power BI Engineer

N-iX

(Flexible)
1 Month ago
Playrix - Lead C++ Software Engineer (Gameplay)

Playrix

Ireland (Remote)
4 Months ago
Meta - Global Sales Analytics Lead

Meta

New York, New York, United States (Remote)
3 Months ago
Enphase Energy - Sr. Software Engineer (QA Lead)

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Mott MacDonald - Senior Pipelines Engineer

Mott MacDonald

Mumbai, Maharashtra, India (On-Site)
3 Months ago
Enphase Energy - Senior Embedded Firmware Engineer

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Aspire - QA Lead

Aspire

Gurugram, Haryana, India (On-Site)
4 Months ago
DISCO - Engineering Manager , Feature

DISCO

Gurugram, Haryana, India (On-Site)
3 Months ago
AkzoNobel - Regional Talent and Performance Lead

AkzoNobel

Gurugram, Haryana, India (On-Site)
5 Months ago
InvenioLSI - SAP Associate Consultant - Application Suppport

InvenioLSI

India (On-Site)
3 Months ago
MyGwork - Software Development Engineer in Test

MyGwork

Bengaluru, Karnataka, India (On-Site)
4 Months ago
CleverTap - Senior Backend Engineer - Platform

CleverTap

Mumbai, Maharashtra, India (Hybrid)
4 Months ago
ALIQAN Technologies - Sr. VR Developer

ALIQAN Technologies

Hyderabad, Telangana, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

The Walt Disney Company - Asset Protection Agent - Part Time

The Walt Disney Company

New York, New York, United States (On-Site)
4 Weeks ago
HP - Cybersecurity Metrics Analyst

HP

Tlaquepaque, Jalisco, Mexico (On-Site)
5 Months ago
Globalization Partners - Information Security Manager - GRC

Globalization Partners

(Remote)
2 Months ago
Microsoft - Principal Security Program Manager

Microsoft

Redmond, Washington, United States (On-Site)
1 Month ago
PwC - SRC_HITRUST_Senior Associate

PwC

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Axinous - Senior Product Marketing Manager - Risk Management

Axinous

San Jose, California, United States (Hybrid)
3 Months ago
ByteDance - Insider Threat Program Manager, Information Security

ByteDance

Singapore (On-Site)
3 Months ago
PwC - Cybersecurity Associate

PwC

Makati, Metro Manila, Philippines (On-Site)
4 Months ago
Luxoft - IAM Lead Expert

Luxoft

Bucharest, Bucharest, Romania (Hybrid)
2 Months ago
Trend Micro - Automotive Research Engineer - Threat Intelligence & Content Creation (VicOne)

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded