Security Engineer-2

Cashfree Payments India Private Limited

Bengaluru

On-site

INR 1,500,000 - 2,300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cashfree Payments India Private Limited is seeking a security engineer to proactively identify vulnerabilities in our products and work with teams to mitigate risks. The role emphasizes threat modeling, secure design reviews, and secure coding practices while promoting security awareness across the development community.

The candidate will engage with in-house engineering, support pre-assessment analyses, and help automate security testing within the DevOps pipeline.

Qualifications

  • Familiarity with threat modeling, risk modeling, and vulnerability classification.
  • Experience with pre-assessment architectural and API analysis (white/grey-box).
  • Experience in S-SDLC/CICD, QA processes.
  • Knowledge of multiple vulnerabilities (XSS, SQLi, CSRF, crypto weaknesses).

Responsibilities

  • Examine products to discover vulnerabilities and demonstrate exploitability and risk.
  • Follow emerging threats and perform independent research.
  • Collaborate with developers to implement mitigations per policy.
  • Engage with design reviews and threat modeling with Dev teams.
  • Deliver security training and workshops for developers and QA.

Skills

Threat modeling
Secure coding
Security assessments
Programming languages (Java, Python,Go
Cloud security

Education

B.Tech in CS/EE/CE or equivalent

Job description

Responsibilities


  • Examine the products in detail to discover vulnerabilities and collaborate with the other security engineers to practically demonstrate the exploitability and risk factors.

  • Be on the forefront of emerging vulnerabilities/threats that could affect Cashfree products through independent research and study.

  • Engage with the developers in developing workarounds/mitigation plans and ensure they are implemented per policy.

  • Threat Modelling: Engage with the development teams to conduct secure design reviews/threat modeling exercise to enumerate threats and mitigation strategies.

  • Enable the developers with knowledge of threat modeling by conducting focused workshops.

  • Secure Coding: Priorities critical defects and ensure these are identified and mitigated during the sprint.

  • Integration and automation of SAST in the DevOps pipeline.

  • Build secure coding principles and propagate them across the development community.

  • Be the to-go person for developers in solving critical issues relating to secure product development.

  • Build and enhance secure coding / security assessments training contents for developers and QA team.

  • Deliver training programs at various levels in the organizations.

  • Conduct workshops/security tech-talks to disseminate security knowledge and awareness. Qualifications.

  • Good knowledge in multiple classes of vulnerabilities that includes cross-site scripting, SQL Injection, CSRF, cryptographic related weakness, and code injection.

  • Good knowledge of any programming/scripting languages such as Java, Ruby, and Python.

  • Good knowledge relating to services/technology relating to the cloud.

  • Ability to automate security testing and improve productivity in security assessments.

  • Ability to communicate and interpret security vulnerabilities to various audiences such as development and management teams.


Requirements


  • You have great interpersonal skills, deep technical ability, and a history of successful execution in the assessments industry. If you enjoy discussing anything from procedural linking tables in kernels to remote code execution in JVMs, then we want you on the team.

  • Familiarity with industry-standard threat modeling, risk modeling, and vulnerability classification.

  • Experience with pre-assessment architectural and API analysis to scope and prepare white-box and grey-box assessments.

  • Experience working with in-house engineering organizations, S-SDLC/CICD software lifecycle and QA processes

  • B. Tech. in Computer Science, Electrical, or Computer Engineering, or equivalent work experience as a software engineering or security practitioner.

  • 3+ years of relevant engineering or security assessment experience, experience in application security.

  • Possess a broad knowledge of attack vectors, exploits, and mitigations that work at scale or may be linked together for chained attacks.

  • Experience with Java, Go, Python, or Node.js (bonus points for more than one).

  • Experience with assessing Cloud-native services, service meshes, and K notes-platform-based micro-services.

  • Be able to apply unconventional thinking and problem-solve on the boundary of your knowledge base, learning new technologies or languages as needed to complete pen-test tasks.

  • Be able to think both offensively (like a hacker) and defensively (evaluating product security and design)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Testing Engineer
Senior Security Testing Engineer

Allied Boston Consultants India • Dadri

On-site
INR 900,000 - 1,300,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Security Tester
Security Tester

Disprz • Chennai District

On-site
INR 1,800,000 - 3,600,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Security Consultant
Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 500,000 - 700,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000