
Senior Security Engineer - Product Security
Ecolab Inc.2 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Conduct Product Security risk assessments for mobile, web, API, and IoT applications.
- Perform and remediate findings from SAST, DAST, and manual penetration testing.
- Simulate attacks and produce detailed vulnerability reports.
- Review software applications and source code for security flaws and recommend mitigations.
- Guide engineering teams on secure development practices, architecture, remediation strategies, and secure coding.
- Deliver secure coding training to development and engineering teams.
- Integrate security into CI/CD pipelines, developer workflows, and DevSecOps processes.
- Automate security processes and maintain security integrations in development pipelines.
- Assess and improve the security of AI APIs, ML pipelines, and LLM-based applications.
- Stay current on emerging threats, vulnerabilities, countermeasures, and AI security frameworks.
- Build relationships with stakeholders and business partners.
Requirements
- Bachelor’s degree in computer science, information technology, or a related discipline.
- 6–8 years of experience in the Product Security domain.
- Strong expertise in OWASP Top 10, CWE Top 25, and data protection principles.
- Experience with application architecture in multi-cloud and hybrid environments.
- Hands-on experience with SAST, DAST, container security, and manual penetration testing.
- Ability to interpret and write Python, JavaScript/TypeScript, Java, C# (.NET), and Apex.
- Deep knowledge of software vulnerabilities, secure design patterns, and threat mitigation strategies.
- Experience integrating security into CI/CD pipelines and developer workflows.
- Strong working knowledge of Web Application Firewall technologies.
- Knowledge of OWASP Top 10 for LLMs and emerging AI security frameworks.
- Understanding of prompt injection, data poisoning, and model theft threats.
- Knowledge of API Security, Infrastructure as Code security, Secrets Management, threat modeling, and attack simulation techniques.