Meesho

Security Engineer III

Meesho
Apply
9 hours ago
Bengaluru, IndiaSenior

Responsibilities

  • Lead threat modeling and secure design reviews for complex, multi-service features and drive security requirements into production.
  • Conduct advanced vulnerability assessments and penetration testing across web platforms, APIs, and iOS and Android applications.
  • Plan and execute red team and purple team exercises and translate attack paths into durable architectural fixes.
  • Perform manual and automated source code reviews and help eliminate vulnerability classes at the framework or platform level.
  • Own the integration, tuning, scaling, and automation of SAST, DAST, SCA, secret scanning, and container scanning tools in CI/CD pipelines.
  • Drive cloud security reviews and hardening for AWS, Kubernetes/EKS, and containerized workloads, including identity, tenant isolation, network controls, and secrets management.
  • Contribute to AI/LLM security through threat modeling, prompt-injection and data-leakage controls, tenant isolation, and secure SDLC patterns.
  • Own vulnerability remediation tracking and help operate the self-managed bug bounty program.
  • Define security coverage, remediation SLA, and mean-time-to-remediate metrics.
  • Provide secure-coding guidance, security consultations, code reviews, and mentorship to SE1 and SE2 engineers.
  • Drive security culture initiatives and contribute to ISO 27001 readiness, TPRM, and BCP/BIA efforts.

Requirements

  • 5–7 years of hands-on product security or application security experience with end-to-end ownership of security workstreams.
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field is preferred.
  • Experience leading threat modeling sessions and integrating findings into the SDLC across cross-functional teams.
  • Strong web and API security assessment skills, including OWASP Top 10, authentication, authorization, session management, and business-logic vulnerabilities.
  • Manual source code review experience and ability to reason about Java, Node.js, Python, and React code.
  • Experience integrating and tuning security tooling in CI/CD pipelines and building custom security automation.
  • Cloud security experience with AWS or GCP and working knowledge of Docker and Kubernetes security.
  • Experience planning and executing red team or purple team exercises.
  • Working knowledge of Android and iOS application security assessments, OWASP MASVS, and mobile-specific vulnerabilities.
  • Familiarity with Frida, Objection, Drozer, and MobSF.
  • Strong analytical, problem-solving, communication, risk-prioritization, and mentoring skills.
  • Relevant certifications such as OSCP, OSWE, GWAPT, or CKS are beneficial.
  • Bug bounty participation, published CVEs, security research, conference speaking, AI/LLM security, software supply-chain security, and knowledge of India’s DPDP Act or CERT-In directions are beneficial.

Benefits

  • Competitive cash and equity-based compensation tailored to role, experience, and skills.
  • Extensive medical insurance for employees and their families, plus telehealth, wellness events, and fitness-related perks.
  • Generous leave policies, parental support, retirement benefits, and learning and development assistance.
  • Recognition programs, engaging workplace activities, salary advance support, relocation assistance, and flexible benefit plans.
  • Inclusive and accessible workplace with reasonable accommodations and accessible application and interview processes.
Meesho

About Meesho

10,000+ employees

Meesho operates an India-focused e-commerce marketplace that connects consumers with small and medium sellers, providing catalog tools, integrated payments, and partner-led shipping. The platform offers zero-commission listings for merchants and supports deliveries through Valmo, an asset-light logistics network run via third-party partners. Founded in 2015 and headquartered in Bangalore, it is privately held.

Contact me