
Senior Security Engineer - Product Security
Ecolab Inc.2 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Conduct Product Security Risk Assessments for mobile, web, API, and IoT applications.
- Perform and remediate findings from SAST, DAST, manual penetration testing, and other security testing activities.
- Simulate attacks and produce detailed vulnerability reports.
- Review applications and source code for security flaws and recommend mitigation strategies.
- Guide development and engineering teams on secure coding, secure architecture, and remediation practices.
- Deliver secure coding training to development and engineering teams.
- Integrate security into CI/CD pipelines and developer workflows, including DevSecOps processes.
- Automate security processes and maintain security integrations in development pipelines.
- Support threat modeling, attack simulation, API security, IaC security, secrets management, and AI/LLM application security.
- Monitor emerging threats, vulnerabilities, countermeasures, and AI security frameworks.
- Build relationships with internal stakeholders, business partners, and engineering teams.
Requirements
- Bachelor’s degree in computer science, information technology, or a related discipline.
- 6–8 years of experience in the Product Security domain.
- Hands-on experience with application security, SAST, DAST, container security, secure code reviews, and manual penetration testing.
- Strong expertise in OWASP Top 10, CWE Top 25, data protection principles, software vulnerabilities, secure design patterns, and threat mitigation.
- Experience with application architecture in multi-cloud and hybrid environments.
- Proficiency in interpreting and writing Python, JavaScript/TypeScript, Java, C#/.NET, and Apex.
- Experience integrating security into CI/CD pipelines and developer workflows.
- Strong working knowledge of Web Application Firewall technologies.
- Knowledge of OWASP Top 10 for LLMs, emerging AI security frameworks, prompt injection, data poisoning, and model theft threats.
- Experience securing AI APIs, ML pipelines, and LLM-based applications.
- Knowledge of API Security, Infrastructure as Code Security, Secrets Management, threat modeling, and attack simulation techniques.
- Experience with security tools and technologies including Fastly, Cloudflare, Akamai, Snyk, Qualys, Burp Suite, Wiz, Postman, MobSF, Elastic, Agentic Scanner, Azure, AWS, GCP, ADO, and GitHub.