
Senior Security Engineer - Product Security
Ecolab Inc.2 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Conduct product security risk assessments for mobile, web, API, and IoT applications.
- Perform and remediate SAST, DAST, secure code review, and manual penetration testing findings.
- Simulate attacks and produce detailed vulnerability reports.
- Guide development and engineering teams on secure coding, architecture, remediation, and security training.
- Integrate security processes and automation into CI/CD pipelines and developer workflows.
- Support CI/CD and DevSecOps integration as a technical liaison.
- Assess and secure AI APIs, ML pipelines, and LLM-based applications.
- Monitor emerging threats, vulnerabilities, countermeasures, and AI security frameworks.
- Build relationships with internal stakeholders and business partners.
Requirements
- Bachelor’s degree in computer science, information technology, or a related discipline.
- 6–8 years of experience in the product security domain.
- Strong expertise in OWASP Top 10, CWE Top 25, data protection principles, secure design patterns, and threat mitigation.
- Hands-on experience with SAST, DAST, container security, manual penetration testing, threat modeling, and attack simulation.
- Proficiency in interpreting and writing Python, JavaScript/TypeScript, Java, C# (.NET), and Apex.
- Experience with multi-cloud and hybrid application architectures, API security, Infrastructure as Code security, and secrets management.
- Knowledge of WAF technologies and experience integrating security into CI/CD pipelines and developer workflows.
- Knowledge of OWASP Top 10 for LLMs, emerging AI security frameworks, prompt injection, data poisoning, and model theft.
- Experience securing AI APIs, ML pipelines, and LLM-based applications.
- Experience with Fastly, Cloudflare, Akamai, Snyk, Qualys, Burp Suite, Wiz, Postman, MobSF, Elastic, Agentic Scanner, Azure, AWS, GCP, ADO, and GitHub.