Senior Engineer, Product Security Testing

News Corporation

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equal opportunity employer
Reasonable accommodation

Job summary

News Corp is seeking a Senior Engineer in Product Security in Bengaluru to drive security testing across web, mobile, APIs, and cloud environments. The role emphasizes AI/LLM security, threat modeling, and collaboration with product teams to integrate robust security practices.

The candidate should have 6+ years in product security, proficiency with industry tools, and hands-on experience in reporting and risk mitigation. A strong communicator with mentoring abilities is essential.

Qualifications

  • Bachelors/MTech in cyber security or related field.
  • Minimum 6 years in Product and Application Security with pentesting, SAST/SSDLC, and threat modeling.
  • 1–2 years software development, with at least 1 year building secure systems.
  • Experience in Python/Java/JavaScript/Go and DevOps/DevSecOps basics.
  • Strong communication, technical writing, and cross-team collaboration skills.
  • Knowledge of CVSS rating calculations and security reporting.

Responsibilities

  • Perform penetration testing across web, mobile, APIs, and cloud.
  • Analyze findings, create reports with root-cause and mitigations.
  • Lead AI/LLM security assessments and model security testing.
  • Mentor junior team members and interact with development teams.

Skills

Penetration testing
Threat modeling
AI/LLM security
Cloud security
Security reporting
Communication skills
DevSecOps

Education

Bachelor's/MTech in Cyber Security

Tools

Checkmarx
Fortify
Ghidra
Hopper
MobSF
Burp Suite
ZAP

Job description

Bangalore

Full time

Job Description :

Job Description Details: Senior Engineer - Product Security : Bangalore, India

We are currently seeking a Senior Engineer, Product Security to join our Product Security team, based in Bangalore, Karnataka, India. The ideal candidate will possess a deep understanding of attack surfaces in modern compiled applications and operating systems. Candidates must demonstrate the ability to analyze closed source applications using several off-the-shelf or custom-developed tools. Additionally, the ideal candidate will be able to demonstrate exceptional organizational skills, work efficiently under minimal supervision, be able to deliver results that meet or exceed the organization’s expectations, be a strong team player, and actively participate in a fast-paced and challenging global environment.

As part of our Product Security team, you shall perform penetration testing which includes internet,

intranet, wireless, web application, APIs, Mobile Applications and social engineering. You shall also

perform in-depth analysis of penetration testing results and create reports that describe findings,

exploitation procedures, risks and recommendation

Key Responsibilities:
  • Hands-on experience with OWASP Web and Mobile Top 10 standards,NIST CSF, NIST SP 800,PCI DSS including mitigation of common threats.
  • Strong understanding of the OWASP Top 10 for LLM Applications and OWASP Top 10 for Generative AI, with hands-on experience identifying and validating AI/LLM-specific security risks.
  • Strong knowledge of OWASP Top 10 web and the ability to effectively communicate methodologies and techniques with development teams
  • Execute penetration testing projects using the established methodology, tools and rules of engagements.
  • Solid understanding of application security topics such as authentication, authorization, encryption, session management, federation, API security, etc.
  • Extensive experience with web and mobile application security tools like code scanners (Checkmarx, Fortify, Ghidra, Hopper, MobSF) and dynamic analysis tools (Burp Suite, ZAP, etc.).
  • Experienced in performing security assessments of AI models, LLM-powered applications, chatbots, AI agents, and AI-integrated APIs, covering both traditional and AI-specific attack vectors.
  • Hands-on experience with AI security testing tools, prompt engineering, adversarial testing techniques, and integrating Model Context Protocol (MCP) servers with security tools to automate and enhance AI security assessments.
  • Skilled in evaluating AI systems for vulnerabilities such as prompt injection, indirect prompt injection, sensitive information disclosure, insecure tool usage, excessive agency, model manipulation, and unsafe output handling.
  • Proficient in designing and executing end-to-end AI penetration testing methodologies, leveraging automation and custom tooling to improve assessment efficiency and coverage.
  • Write reports including recommendations, root cause analysis, security summary analysis, and project roadmaps.
  • Review application code for security vulnerabilities and practices dangerous to security and privacy.
  • Convey complex technical security concepts to technical and non-technical audiences including executives.
  • Mentor junior members of the team and act as a subject matter expert for application security issues.
  • Manage integration with manual and automated tools for static and dynamic testing.
  • Conduct threat modeling and risk analysis to identify exposure and develop mitigation plans.
  • Build security into infrastructure and architecture designs and guide the implementation with the operations team
  • Experience with cloud security, particularly for AWS and/or Azure Experience with integrating security into a DevOps culture.
Minimum Qualifications.
  • Bachelor's degree/MTech with an emphasis on cyber security.
  • Minimum 6 years of experience in Product and Application Security performing, Penetration Testing on Web Application, Mobile (Android and IOS) APIs, SAST, SCA, SSDLC. Threat Modeling and Secure design review would be an added advantage.
  • 1-2 years of software development with at least 1 year in developing secure systems.
  • Experience in one or more of the following modern languages/frameworks - Python, Java, Ruby, node.js, JavaScript, PHP, Go.
  • Basic understanding of DevOps & DevSecOps principles and building code pipelines.
  • A passion for application security and working knowledge of web application vulnerabilities and mitigations.
  • Known for being a great communicator and collaborator with excellent written and verbal communication skills.
  • Demonstrable flair for technical writing, including engagement reports, presentations and operating procedures
  • Experience with severity ratings systems, and ability to calculate CVSS ratings for identified vulnerabilities.
Preferred Certifications
  • CPENT, LPT, GPEN, OSCP
Equal Opportunity Employer

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic.

Reasonable Accommodation

We are committed to providing reasonable accommodation for qualified individuals with disabilities in our job application and/or interview process. If you need assistance or accommodation in completing your application or participating in an interview due to a disability, email us at humanresources@newscorp.com . Please put \"Reasonable Accommodation\" in the subject line and provide a brief description of the type of assistance you need. This inbox will not be monitored for application status updates.

Please refer to the privacy notice at the bottom of this page for submitting any data access, deletion, or other data subject rights requests, where permitted under your local laws and regulations.

News Corp (Nasdaq: NWS, NWSA; ASX: NWS, NWSLV) is a global, diversified media and information services company focused on creating and distributing authoritative and engaging content and other products and services. The company comprises businesses across a range of media, including: information services and news, digital real estate services and book publishing. Headquartered in New York, News Corp operates primarily in the United States, Australia and the United Kingdom, and its content and other products and services are distributed and consumed worldwide. More information is available at: http://newscorp.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer, Data Engineering
Senior Engineer, Data Engineering

Storyful • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Senior Engineer, Data Engineering
Senior Engineer, Data Engineering

News Corporation • India

On-site
INR 2,500,000 - 4,500,000
Senior Engineer, HR Data Analytics
Senior Engineer, HR Data Analytics

News Corporation • Bengaluru

On-site
INR 2,200,000 - 3,400,000
Senior Engineer, Data Engineering
Senior Engineer, Data Engineering

News Corporation • Bengaluru

On-site
INR 2,600,000 - 4,800,000
Engineer, IAM & Collaboration
Engineer, IAM & Collaboration

News Corporation • Bengaluru

On-site
INR 800,000 - 1,300,000
Product Security Engineer
Product Security Engineer

HCLTech • Jigani

Hybrid
INR 3,000,000 - 5,500,000
Remote-friendly work environment
Competitive salary and growth
Senior Application Security Specialist
Senior Application Security Specialist

[24]7.ai • Bengaluru

On-site
INR 1,500,000 - 2,500,000
4486-Security Engineer II
4486-Security Engineer II

Innovaccer • Dadri

On-site
INR 1,500,000 - 2,500,000
Leaves up to 40 days
Parental leave
Sabbatical
+3
Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Cornerstone • Mumbai, Pune District

On-site
INR 2,000,000 - 4,000,000