Product Security Engineer

slice

Bengaluru

On-site

INR 600,000 - 1,200,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Flexible working hours
Vacation policy
Learning opportunities
Healthy office environment

Job summary

slice is seeking a Cyber Security Engineer to strengthen our Application and Product Security program across the SDLC. You will partner with engineering, product, and infrastructure teams to identify risks, perform assessments, and help build secure, scalable products that meet industry standards and compliance.

Ideal candidates are passionate about offensive security, secure design, mobile and API security, and DevSecOps, with hands-on experience in web, API, and mobile security testing and

Qualifications

  • 1–2 years of experience in Application Security, Product Security, or Cyber Security.
  • Strong understanding of web app, API, Android, and iOS security concepts.
  • Hands-on experience performing security testing of web apps, APIs and mobile apps.

Responsibilities

  • Perform end-to-end VAPT for web apps, APIs, Android and iOS apps.
  • Conduct Secure Design Reviews during the design phase.
  • Perform Threat Modeling for new apps and major releases.

Skills

Application Security
VAPT
Threat Modeling
Secure Coding
OSS/DevSecOps
Security Audits

Tools

Burp Suite
MobSF
Frida
Postman
Nmap

Job description

As a Cyber Security Engineer at slice, you will play a key role in strengthening our Application and Product Security program by embedding security throughout the Software Development Lifecycle (SDLC). You will work closely with engineering, product, and infrastructure teams to identify security risks early, conduct security assessments, and help build secure, scalable products that meet industry standards and compliance requirements.

This role is ideal for someone passionate about offensive security, secure design, mobile and API security, and DevSecOps.

What you will do:
Application Security
  • Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, Android, and iOS applications.
  • Conduct Secure Design Reviews and identify potential security risks during the design phase.
  • Perform Threat Modeling sessions for new applications, services, and major feature releases.
  • Validate security controls and perform security re-testing after vulnerabilities are remediated.
  • Prepare detailed security assessment reports with clear remediation guidance and risk prioritization.
  • Perform static and dynamic security analysis of Android and iOS applications.
  • Assess REST APIs and microservices for authentication, authorization, business logic, and data exposure vulnerabilities.
Identify vulnerabilities such as:
  • Sensitive Data Exposure
  • Business Logic flaws
  • Security Misconfiguration
  • SSRF, XXE, CSRF, XSS, and related web security issues
  • Provide secure coding recommendations and remediation guidance.
  • Contribute to the implementation and improvement of SAST, DAST, SCA, Secret Scanning, and Infrastructure-as-Code (IaC) security practices.
  • Evaluate new technologies and architectures from a security perspective and recommend appropriate security controls.
  • Develop scripts and automation to improve security testing and vulnerability management workflows.
  • Contribute to internal security tools and automation initiatives.
  • Assist in improving security processes, standards, and documentation.
  • Partner with developers, architects, product managers, and infrastructure teams to drive secure-by-design principles.
  • Provide technical security guidance during feature development and product releases.
  • Ensure applications and infrastructure comply with internal security requirements and applicable industry standards.
What you will need:
  • 1–2 years of experience in Application Security, Product Security, or Cyber Security.
  • Strong understanding of web application, API, Android, and iOS security concepts.
  • Hands‑on experience performing penetration testing of web applications, APIs, and mobile applications.
  • Hands‑on experience in identifying and assessing network security vulnerabilities and security misconfigurations.
Good understanding of:
  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP Mobile Application Security (MASVS/MSTG)
  • Knowledge of authentication and authorization mechanisms including OAuth2, JWT, OIDC, and session management.
  • Good understanding of Secure Software Development Lifecycle (SSDLC) and secure coding practices.
  • Familiarity with common security vulnerabilities and exploitation techniques.
  • Experience writing technical security reports and communicating remediation recommendations.
  • Strong analytical, problem‑solving, and communication skills.
  • Experience with Linux systems and networking fundamentals.
  • Experience with scripting using Python, Bash, or similar languages for automation.
Tools & Technologies
  • Experience with one or more of the following tools is preferred:
  • Burp Suite
  • MobSF
  • Frida
  • Objection
  • Postman
  • Nmap
  • Subfinder
  • Amass
Good to Have
  • Familiarity with AWS security concepts.
  • Experience with SAST, DAST, SCA, Secret Scanning, and IaC Security.
  • Experience with cloud‑native application security.
  • Participation in Bug Bounty programs or responsible disclosure programs.
  • Contributions to open‑source security projects.
  • Familiarity with AI‑assisted security testing and automation.
Preferred Certifications
  • eJPT
  • eWPT
  • eMAPT
  • PNPT
  • OSCP (Good to Have)
What We Look For
  • Passion for offensive security and continuous learning.
  • Strong ownership and accountability.
  • Curiosity to understand how systems work and how they can be secured.
  • Ability to communicate effectively with engineering and business stakeholders.
  • A collaborative mindset and willingness to improve security processes across the organization.
Life at slice

Life so good, you’d think we’re kidding:

  • An extensive medical insurance that looks out for our employees & their dependents. We’ll love you and take care of you, our promise.
  • Flexible working hours. Just don’t call us at 3AM, we like our sleep schedule.
  • Tailored vacation & leave policies so that you enjoy every important moment in your life.
  • A reward system that celebrates hard work and milestones throughout the year. Expect a gift coming your way anytime you kill it here.
  • Learning and upskilling opportunities. Seriously, not kidding.
  • Good food, games, and a cool office to make you feel like home. An environment so good, you’ll forget the term “colleagues can’t be your friends”

At slice, we are committed to building a diverse and talented workforce. We never discriminate on the basis of race, sex, religion, colour, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, medical condition, disability, or any other class or characteristic protected by the applicable law.

We consider all qualified job‑seekers with criminal histories in a manner consistent with the applicable law. Additionally, we are committed to providing reasonable accommodations to qualified individuals with physical or mental disabilities in order to participate in the job application or interview process, perform essential job functions, and receive other benefits and privileges of employment. Come join our crew!

About us

slice

slice’s purpose is to make the world better at using money and time, with a major focus on

building the best consumer experience for your money. We’ve all felt how slow, confusing, and complicated banking can be. So, we’re reimagining it. We’re building every product from scratch to be fast, transparent, and feel good, because we believe that the best products transcend demographics, like how great music touches most of us.

Our cornerstone products and services: slice savings account, slice UPI credit card, slice UPI, and slice business are designed to be simple, rewarding, and completely in your control. At slice, you’ll get to build things you’d use yourself and shape the future of banking in India. We tailor our working experience with the belief that the present moment is the only real thing in life. And we have harmony in the present the most when we feel happy and successful together.

We’re backed by some of the world’s leading investors, including Tiger Global, Insight Partners, Advent International, Blume Ventures, and Gunosy Capital.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager -Internal Audit (Information Security and System Audit)
Senior Manager -Internal Audit (Information Security and System Audit)

slice • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Extensive medical insurance
Flexible working hours
Tailored vacation & leave policies
+3
Engineer 1 - IS Compliance
Engineer 1 - IS Compliance

slice • Bengaluru

On-site
INR 600,000 - 1,200,000
Competitive salary
Medical insurance
Flexible hours
+3
Analytics Engineer 2 - Data Platform
Analytics Engineer 2 - Data Platform

slice • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Competitive salaries
Medical insurance for you and depend -
Flexible working hours
+4
Cyber Security Engineer
Cyber Security Engineer

slice • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Medical insurance
Flexible working hours
Learning opportunities
+1
End User Technology Engineer II
End User Technology Engineer II

slice • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive salary
Medical insurance for employees and 
r
Flexible working hours
+4
Lead Analyst
Lead Analyst

slice • Bengaluru

On-site
INR 1,100,000 - 1,700,000
Extensive medical insurance
Flexible working hours
Tailored vacation policies
+3
Assistant Manager - Operations
Assistant Manager - Operations

slice • Bengaluru

On-site
INR 900,000 - 1,300,000
Competitive salaries
Medical insurance for employees and/or
Flexible working hours
+2
Lead Talent Acquisition - Tech
Lead Talent Acquisition - Tech

slice • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Competitive salary
Medical insurance
Flexible hours
+5
SRE2
SRE2

slice • Bengaluru

On-site
INR 2,000,000 - 4,000,000
Medical insurance
Flexible working hours
Generous vacation policies
+2
AVP - Anti Money Laundering
AVP - Anti Money Laundering

slice • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Medical insurance
Flexible hours
Learning & upskilling