Synamedia

Lead InfoSec Engineer

Synamedia
Apply
5 days ago
Bengaluru, IndiaStaff+

Responsibilities

  • Perform security assessments of web applications, APIs, microservices, and cloud-native applications.
  • Conduct threat modeling and security design reviews for products, features, and architectural changes.
  • Perform secure code reviews and identify vulnerabilities, insecure coding patterns, and design weaknesses.
  • Implement and improve SAST, DAST, SCA, secrets scanning, and related application-security tooling.
  • Integrate automated security checks and risk-based quality gates into CI/CD pipelines.
  • Validate, triage, prioritize, and track vulnerabilities through remediation and closure.
  • Assess authentication, authorization, session management, cryptography, data protection, and input-validation controls.
  • Perform security testing of REST APIs and service interfaces, including authorization, injection, data exposure, and business-logic risks.
  • Develop security automation and scripts to scale the application-security program.
  • Define secure-coding guidance, security checklists, developer enablement materials, metrics, and reporting.
  • Support secure-development practices and threat modeling for AI-enabled features and services.

Requirements

  • At least 7 years of relevant experience in application security, product security, DevSecOps, penetration testing, or secure software development.
  • Strong understanding of OWASP Top 10, OWASP API Security Top 10, CWE, vulnerability classes, and secure-coding principles.
  • Hands-on experience with SAST, DAST, SCA, secrets scanning, and web/API security testing tools such as Burp Suite or OWASP ZAP.
  • Experience conducting threat modeling with STRIDE or a comparable methodology.
  • Ability to review source code in one or more of Java, C/C++, C#, Python, JavaScript/TypeScript, or Go.
  • Understanding of Jenkins, GitHub Actions, and Git-based development workflows.
  • Experience with AWS, Azure, or GCP; Docker, Kubernetes, and infrastructure-as-code security.
  • Experience with Black Duck, Coverity, Trivy, and TruffleHog.
  • Familiarity with OAuth 2.0, OpenID Connect, SAML, JWT, RBAC, software supply-chain security, SBOM, dependency governance, and secrets management.
  • Strong communication skills for explaining vulnerability impact, exploit scenarios, remediation options, and risk to engineering stakeholders.
  • CSSLP, CISSP, or CCSP certification is advantageous but not required.
  • Video-streaming, broadcast, OTT, Pay-TV, DRM, conditional-access, content-security, cloud-native SaaS, or media-technology experience is desirable.
  • Familiarity with securing applications that use LLMs, AI agents, or generative AI, including prompt injection, sensitive-data disclosure, insecure output handling, excessive agency, and AI supply-chain risks, is desirable.

Benefits

  • Flexible working arrangements.
  • Competitive pay hikes and bonus packages.
  • Skill-enhancement and growth opportunities through resources from AWS, SkillSoft, and other partners.
  • Health and wellbeing programs, including mental-health initiatives.
  • Collaborative work with a global team across Synamedia’s office locations.
  • Family-friendly, inclusive employment policies and engagement activities.
  • Equal-opportunity employment and accommodations during the application process.
Contact me