5 days ago
Bengaluru, IndiaStaff+
Responsibilities
- Perform security assessments of web applications, APIs, microservices, and cloud-native applications.
- Conduct threat modeling and security design reviews for products, features, and architectural changes.
- Perform secure code reviews and identify vulnerabilities, insecure coding patterns, and design weaknesses.
- Implement and improve SAST, DAST, SCA, secrets scanning, and related application-security tooling.
- Integrate automated security checks and risk-based quality gates into CI/CD pipelines.
- Validate, triage, prioritize, and track vulnerabilities through remediation and closure.
- Assess authentication, authorization, session management, cryptography, data protection, and input-validation controls.
- Perform security testing of REST APIs and service interfaces, including authorization, injection, data exposure, and business-logic risks.
- Develop security automation and scripts to scale the application-security program.
- Define secure-coding guidance, security checklists, developer enablement materials, metrics, and reporting.
- Support secure-development practices and threat modeling for AI-enabled features and services.
Requirements
- At least 7 years of relevant experience in application security, product security, DevSecOps, penetration testing, or secure software development.
- Strong understanding of OWASP Top 10, OWASP API Security Top 10, CWE, vulnerability classes, and secure-coding principles.
- Hands-on experience with SAST, DAST, SCA, secrets scanning, and web/API security testing tools such as Burp Suite or OWASP ZAP.
- Experience conducting threat modeling with STRIDE or a comparable methodology.
- Ability to review source code in one or more of Java, C/C++, C#, Python, JavaScript/TypeScript, or Go.
- Understanding of Jenkins, GitHub Actions, and Git-based development workflows.
- Experience with AWS, Azure, or GCP; Docker, Kubernetes, and infrastructure-as-code security.
- Experience with Black Duck, Coverity, Trivy, and TruffleHog.
- Familiarity with OAuth 2.0, OpenID Connect, SAML, JWT, RBAC, software supply-chain security, SBOM, dependency governance, and secrets management.
- Strong communication skills for explaining vulnerability impact, exploit scenarios, remediation options, and risk to engineering stakeholders.
- CSSLP, CISSP, or CCSP certification is advantageous but not required.
- Video-streaming, broadcast, OTT, Pay-TV, DRM, conditional-access, content-security, cloud-native SaaS, or media-technology experience is desirable.
- Familiarity with securing applications that use LLMs, AI agents, or generative AI, including prompt injection, sensitive-data disclosure, insecure output handling, excessive agency, and AI supply-chain risks, is desirable.
Benefits
- Flexible working arrangements.
- Competitive pay hikes and bonus packages.
- Skill-enhancement and growth opportunities through resources from AWS, SkillSoft, and other partners.
- Health and wellbeing programs, including mental-health initiatives.
- Collaborative work with a global team across Synamedia’s office locations.
- Family-friendly, inclusive employment policies and engagement activities.
- Equal-opportunity employment and accommodations during the application process.
Tech Stack
AWSAzureC#C++DockerGitGitHub ActionsGoGoogle Cloud PlatformJavaJavaScriptJenkinsKubernetesPythonTypeScript
