2 months ago
Bengaluru, IndiaEntry Level / Mid Level
Responsibilities
- Perform secure code reviews for applications written in Java, Python, JavaScript, Golang, and other languages.
- Conduct application security assessments using SAST, DAST, SCA, manual testing, penetration testing, and security assessments of web applications and APIs.
- Perform threat modeling, identify design-phase security risks, and participate in security architecture reviews.
- Validate, prioritize, track, and remediate vulnerabilities in partnership with development teams.
- Integrate security tools into CI/CD pipelines and support vulnerability management.
- Develop secure coding standards and security guidelines, and educate development teams on common vulnerabilities.
- Support incident response and root cause analysis for application security issues.
- Secure applications, APIs, authentication systems, microservices, and cloud-native infrastructure.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 1–3 years of experience in Application Security or Product Security.
- Strong understanding of application security principles, secure SDLC, OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, CWE, and CVSS.
- Experience with SAST tools including Checkmarx, Fortify, SonarQube, Semgrep, or CodeQL.
- Experience with DAST tools including Burp Suite or OWASP ZAP.
- Experience with SCA tools including Snyk, Mend, Black Duck, or Dependency-Check.
- Experience with container security tools such as Trivy, Prisma Cloud, or Aqua.
- Experience securing REST APIs, microservices, and cloud-native applications.
- Familiarity with OAuth 2.0, OpenID Connect, JWT, and SAML authentication and authorization mechanisms.
- Knowledge of AWS, Azure, or GCP cloud platforms.
- Understanding of DevSecOps practices and CI/CD tools including Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
- Familiarity with infrastructure-as-code security using Terraform or CloudFormation.
- Experience using Git.
- Preferred experience includes financial services, banking, NBFC, FinTech, identity and authentication products, or other regulated industries.
- Preferred qualifications include familiarity with SIEM, security monitoring, alert triage, HashiCorp Vault, AWS Secrets Manager, bug bounty programs, threat intelligence, MITRE ATT&CK, and security automation using Python, PowerShell, or Bash.
Benefits
- Opportunity to build secure, scalable products protecting millions of users.
- High ownership and the ability to influence security architecture and engineering practices.
- Collaborative engineering culture focused on practical security and continuous improvement.
- Competitive compensation and comprehensive benefits.
- Flexible work environment with opportunities for professional growth and learning.
- Opportunity to work alongside experienced engineers on complex security challenges.
Tech Stack
AWSAzureBashGitGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaJavaScriptJenkinsPowerShellPythonSonarQubeTerraform