Product Security Engineer (Devsec Ops)

Lenskart

Gurugram District

On-site

INR 1,500,000 - 2,300,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Lenskart is seeking a Product Security Engineer with 3–5 years of hands-on security experience to protect products and platforms across web, mobile, and APIs. You will partner with engineering, DevOps, and product teams to bake security into the SDLC, perform assessments, and strengthen cloud security posture across AWS/GCP/Azure.

You will work on threat modeling, code reviews, and tooling for SAST/DAST/SCA, while coordinating fixes with engineering and contributing to secure-by-design design

Qualifications

  • 3–5 years in Application or Product Security roles.
  • Strong knowledge of OWASP Top 10 for Web, Mobile and API security.
  • Experience securing cloud environments (AWS/Azure/GCP).
  • Familiarity with CI/CD security integration and automation.

Responsibilities

  • Perform security assessments, threat modeling, and code reviews.
  • Conduct SAST/DAST/SCA analyses with modern tools.
  • Embed security controls in CI/CD pipelines.
  • Review and enhance security architecture for web, mobile, and API apps.
  • Strengthen cloud security posture and respond to incidents.
  • Support bug bounty triage and coordinate fixes with teams.
  • Document secure coding practices and guidelines.

Skills

Application Security
Threat Modeling
Code Reviews
SAST
DAST
SCA Analysis
CI/CD Security
Cloud Security
Scripting
Container Security

Tools

Burp Suite
ZAP
Checkmarx
SonarQube
Veracode
GitLab Security
GitHub Actions
Jenkins

Job description

We are looking for a Product Security Engineer with 3 to 5 years of hands-on experience in identifying, assessing, and mitigating security risks across our products and platforms. The ideal candidate will work closely with engineering, DevOps, and product teams to integrate security throughout the software development lifecycle (SDLC) and ensure the security of our applications and infrastructure.

Key Responsibilities
  • Conduct application security assessments, threat modeling, and code reviews for products and services.

  • Perform static (SAST), dynamic (DAST), and software composition (SCA) analysis using modern tools.

  • Collaborate with development teams to embed security controls in CI/CD pipelines.

  • Review and enhance security architecture for web, mobile, and API-based applications.

  • Work with DevOps teams to strengthen cloud security posture (AWS/GCP/Azure).

  • Investigate and respond to product security incidents and vulnerability reports.

  • Support bug bounty triage and coordinate fixes with engineering teams.

  • Document and enforce secure coding practices and security guidelines.

  • Participate in design and architecture reviews to ensure security-by-design principles.


  • 3 to 5 years of experience in Application Security or Product Security roles.

  • Strong knowledge of OWASP Top 10 Web, Mobile, API Security Top 10, and secure development practices.

  • Experience in Infrastructure security ( External and Internal)

  • Hands-on experience with tools like Burp Suite, ZAP, Check Marx, SonarQube, Veracode, GitLab Security, etc.

  • Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and integrating security scans.

  • Knowledge of cloud security (AWS, Azure, GCP) and exposure to IAM, KMS, and network controls.

  • Scripting knowledge (Python, Bash, or PowerShell) for automating security tasks.

  • Understanding of container and Kubernetes security concepts.

Good to Have
  • Experience with threat modeling (STRIDE, PASTA, etc.).

  • Familiarity with infrastructure as code (Terraform, CloudFormation) security validation.

  • Exposure to DevSecOps practices and security orchestration.

  • Certifications such as CEH, OSCP, CSSLP, or AWS Security Specialty are a plus.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Senior Application Security Engineer
Senior Application Security Engineer

Tenarai • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Staff Product Security Engineer
Staff Product Security Engineer

Teladoc Health • Hyderabad

On-site
INR 4,000,000 - 6,000,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Omnissa • Bengaluru

On-site
INR 2,800,000 - 4,600,000
Senior Security Engineer
Senior Security Engineer

HappyFox Inc. • Chennai District

On-site
INR 1,200,000 - 1,700,000