9 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Lead threat modeling and secure design reviews for complex, multi-service features and drive security requirements into production.
- Conduct advanced vulnerability assessments and penetration testing across web platforms, APIs, and iOS and Android applications.
- Plan and execute red team and purple team exercises and translate attack paths into durable architectural fixes.
- Perform manual and automated source code reviews and help eliminate vulnerability classes at the framework or platform level.
- Own the integration, tuning, scaling, and automation of SAST, DAST, SCA, secret scanning, and container scanning tools in CI/CD pipelines.
- Drive cloud security reviews and hardening for AWS, Kubernetes/EKS, and containerized workloads, including identity, tenant isolation, network controls, and secrets management.
- Contribute to AI/LLM security through threat modeling, prompt-injection and data-leakage controls, tenant isolation, and secure SDLC patterns.
- Own vulnerability remediation tracking and help operate the self-managed bug bounty program.
- Define security coverage, remediation SLA, and mean-time-to-remediate metrics.
- Provide secure-coding guidance, security consultations, code reviews, and mentorship to SE1 and SE2 engineers.
- Drive security culture initiatives and contribute to ISO 27001 readiness, TPRM, and BCP/BIA efforts.
Requirements
- 5–7 years of hands-on product security or application security experience with end-to-end ownership of security workstreams.
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field is preferred.
- Experience leading threat modeling sessions and integrating findings into the SDLC across cross-functional teams.
- Strong web and API security assessment skills, including OWASP Top 10, authentication, authorization, session management, and business-logic vulnerabilities.
- Manual source code review experience and ability to reason about Java, Node.js, Python, and React code.
- Experience integrating and tuning security tooling in CI/CD pipelines and building custom security automation.
- Cloud security experience with AWS or GCP and working knowledge of Docker and Kubernetes security.
- Experience planning and executing red team or purple team exercises.
- Working knowledge of Android and iOS application security assessments, OWASP MASVS, and mobile-specific vulnerabilities.
- Familiarity with Frida, Objection, Drozer, and MobSF.
- Strong analytical, problem-solving, communication, risk-prioritization, and mentoring skills.
- Relevant certifications such as OSCP, OSWE, GWAPT, or CKS are beneficial.
- Bug bounty participation, published CVEs, security research, conference speaking, AI/LLM security, software supply-chain security, and knowledge of India’s DPDP Act or CERT-In directions are beneficial.
Benefits
- Competitive cash and equity-based compensation tailored to role, experience, and skills.
- Extensive medical insurance for employees and their families, plus telehealth, wellness events, and fitness-related perks.
- Generous leave policies, parental support, retirement benefits, and learning and development assistance.
- Recognition programs, engaging workplace activities, salary advance support, relocation assistance, and flexible benefit plans.
- Inclusive and accessible workplace with reasonable accommodations and accessible application and interview processes.
Categories
About Meesho
Meesho operates an India-focused e-commerce marketplace that connects consumers with small and medium sellers, providing catalog tools, integrated payments, and partner-led shipping. The platform offers zero-commission listings for merchants and supports deliveries through Valmo, an asset-light logistics network run via third-party partners. Founded in 2015 and headquartered in Bangalore, it is privately held.
