Alaan

Product Security Engineer

Alaan
Apply
2 months ago
Bengaluru, IndiaEntry Level / Mid Level

Responsibilities

  • Perform secure code reviews for applications written in Java, Python, JavaScript, Golang, and other languages.
  • Conduct application security assessments using SAST, DAST, SCA, manual testing, penetration testing, and security assessments of web applications and APIs.
  • Perform threat modeling, identify design-phase security risks, and participate in security architecture reviews.
  • Validate, prioritize, track, and remediate vulnerabilities in partnership with development teams.
  • Integrate security tools into CI/CD pipelines and support vulnerability management.
  • Develop secure coding standards and security guidelines, and educate development teams on common vulnerabilities.
  • Support incident response and root cause analysis for application security issues.
  • Secure applications, APIs, authentication systems, microservices, and cloud-native infrastructure.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 1–3 years of experience in Application Security or Product Security.
  • Strong understanding of application security principles, secure SDLC, OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, CWE, and CVSS.
  • Experience with SAST tools including Checkmarx, Fortify, SonarQube, Semgrep, or CodeQL.
  • Experience with DAST tools including Burp Suite or OWASP ZAP.
  • Experience with SCA tools including Snyk, Mend, Black Duck, or Dependency-Check.
  • Experience with container security tools such as Trivy, Prisma Cloud, or Aqua.
  • Experience securing REST APIs, microservices, and cloud-native applications.
  • Familiarity with OAuth 2.0, OpenID Connect, JWT, and SAML authentication and authorization mechanisms.
  • Knowledge of AWS, Azure, or GCP cloud platforms.
  • Understanding of DevSecOps practices and CI/CD tools including Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Familiarity with infrastructure-as-code security using Terraform or CloudFormation.
  • Experience using Git.
  • Preferred experience includes financial services, banking, NBFC, FinTech, identity and authentication products, or other regulated industries.
  • Preferred qualifications include familiarity with SIEM, security monitoring, alert triage, HashiCorp Vault, AWS Secrets Manager, bug bounty programs, threat intelligence, MITRE ATT&CK, and security automation using Python, PowerShell, or Bash.

Benefits

  • Opportunity to build secure, scalable products protecting millions of users.
  • High ownership and the ability to influence security architecture and engineering practices.
  • Collaborative engineering culture focused on practical security and continuous improvement.
  • Competitive compensation and comprehensive benefits.
  • Flexible work environment with opportunities for professional growth and learning.
  • Opportunity to work alongside experienced engineers on complex security challenges.

Tech Stack

AWSAzureBashGitGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaJavaScriptJenkinsPowerShellPythonSonarQubeTerraform

Categories

Alaan

About Alaan

201-500 employees
Contact me