15 hours ago
Bengaluru, IndiaMid Level / Senior
Responsibilities
- Conduct manual and automated security testing of web, mobile, and thick-client applications.
- Perform penetration testing and secure code reviews using manual techniques and tools such as Semgrep.
- Review product features, architecture, and designs for security issues and provide risk-based recommendations.
- Facilitate threat modeling and architecture reviews and advise on secure design, attack-surface reduction, and defense-in-depth.
- Define and implement scalable security controls, development guardrails, and security automation.
- Evaluate researcher-submitted and customer-reported vulnerabilities with Incident Response and Bug Bounty teams.
- Conduct variant and root-cause analysis for high-severity P0/P1 vulnerabilities and provide remediation guidance.
- Collaborate with product and engineering leaders and educate developers on secure development practices.
Requirements
- 2 to 8 years of experience in application or product security.
- Mandatory penetration testing and manual source-code review experience.
- Expertise in web, mobile, and thick-client security testing, threat modeling, secure design review, and manual code review across multiple languages and frameworks.
- Experience with Semgrep, SAST/DAST tools, custom scripts, and security automation.
- Proficiency with Java, Kotlin, Swift, JavaScript, Python, or C#/.NET.
- Strong understanding of authentication, authorization, secure storage, and cryptographic best practices.
- Excellent communication skills for presenting security issues and recommendations to technical and non-technical stakeholders.
- Hands-on experience with CI/CD security automation, container security, or AWS, GCP, or Azure is preferred.
- OSWE, OSCP, OSEP, GWAPT, GMOB, or equivalent certifications are preferred.
- Experience with bug bounty programs, VDPs, or vulnerability triage is preferred.
- Contributions to the security community through blogs, talks, open-source tools, or CVEs are preferred.
Tech Stack
Categories
About Omnissa
Omnissa builds an enterprise digital work platform that unifies endpoint management, virtual desktops and apps, digital employee experience, and security to manage devices and access across clouds. It sells software and cloud services to IT teams in enterprises, education, and public sector. The company was spun out of VMware’s End‑User Computing business, is owned by KKR, and is headquartered in Mountain View, California.
