1 year ago
Chennai, IndiaSenior
Responsibilities
- Review product designs and architectures to identify security risks and recommend controls and mitigations.
- Conduct threat modeling for applications and systems.
- Perform manual and automated security code reviews for OWASP Top 10, CWE, and other vulnerabilities.
- Support vulnerability triage, prioritization, tracking, and remediation across penetration tests, bug bounties, and internal scans.
- Integrate SAST, DAST, and SCA security testing into development and CI/CD pipelines.
- Evaluate and maintain product security tools and develop automation scripts for security tasks.
- Deliver security training and awareness programs for engineering teams.
- Provide security expertise during product-related incidents and promote security-first development practices.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- At least 5 years of experience in product security, application security, or a similar role.
- Strong understanding of application security, secure coding, and web application vulnerabilities including OWASP Top 10.
- Proficiency in at least one programming language such as Python, Java, Go, Node.js, or C#, including the ability to review code for security flaws.
- Experience with SAST, DAST, SCA, and related security testing methodologies.
- Familiarity with cloud security principles and practices, particularly AWS.
- Understanding of cryptographic principles and secure communication protocols.
- Experience integrating security into CI/CD pipelines and the software development lifecycle.
- Knowledge of security frameworks and standards such as NIST and ISO 27001 is preferred.
Benefits
- Chennai-based work-in-office arrangement.
- Equal opportunity employment.
