Senior Product Security Engineer

enableIT

Bengaluru

Hybrid

INR 3,500,000 - 5,500,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

enableIT is seeking a Senior Product Security Engineer to strengthen the security of our FinTech products throughout the SDLC. The role focuses on embedding security into engineering and product development and protecting customer data.

The candidate will drive application security, cloud security, and security automation, collaborating with engineering, product, and platform teams to reduce risk and enhance security controls.

Qualifications

  • 10–12+ years in Product/Application Security or DevSecOps.
  • Strong knowledge of web/mobile security and OWASP Top 10.
  • Experience building secure SDLC and integrating security into engineering.

Responsibilities

  • Define and implement a comprehensive Product Security strategy aligned with business goals.
  • Collaborate with Engineering and Product to foster a security‑first culture.
  • Integrate security controls and tooling across the SDLC.
  • Lead security architecture reviews, threat modeling, and vulnerability assessments.
  • Establish secure development standards for APIs, IaC, and cloud environments.
  • Oversee SAST/DAST/IAST programs and vulnerability remediation.
  • Drive security automation within CI/CD pipelines.
  • Lead incident response, vulnerability disclosure, and post‑incident improvements.
  • Provide security guidance to developers and communicate risks to stakeholders.

Skills

Product Security
Application Security
DevSecOps
Vulnerability Management
Security Automation
Cloud Security
CI/CD
Threat Modeling
Security Audits
API Security
OWASP Top 10
SAST
DAST
IAST

Tools

SAST tools
DAST tools
IAST tools

Job description

Senior Product Security Engineer

Experience: 10–12+ Years

Employment Type: Contract / Full-Time

Location: Bangalore (Hybrid)

Industry: FinTech / Financial Services

Job Summary

We are seeking an experienced Senior Product Security Engineer to help strengthen the security of our products and services throughout the entire software development lifecycle. This role will play a critical hands‑on role in defining and implementing product security strategies, embedding security into engineering and product development processes, and protecting customer data.

The ideal candidate will have strong expertise in application security, product security, cloud security, secure SDLC, DevSecOps, vulnerability management, and security automation, with proven experience working closely with engineering, product, and platform teams.

Key Responsibilities
  • Support the development and execution of a comprehensive Product Security strategy aligned with business objectives, security requirements, and organizational risk appetite.
  • Partner with Engineering and Product teams to foster a strong security-first culture and promote security ownership across the organization.
  • Integrate security best practices, automated security controls, and tooling throughout the Software Development Lifecycle (SDLC).
  • Perform and support security architecture reviews, threat modeling, vulnerability assessments, and secure design reviews.
  • Establish and enforce secure development standards covering API security, secure coding, infrastructure-as-code (IaC), application architecture, and cloud environments.
  • Lead and manage application security programs covering SAST, DAST, IAST, SCA, vulnerability management, and manual penetration testing.
  • Implement and manage product security tooling across web and mobile applications, including API security, mobile application protection, runtime security, and application scanning.
  • Partner closely with Engineering, Product, DevOps, Cloud, and Platform teams to identify, prioritize, track, and remediate security vulnerabilities.
  • Develop and improve security automation within CI/CD pipelines to identify and prevent vulnerabilities earlier in the development lifecycle.
  • Establish and maintain processes for product security incident response, vulnerability disclosure, investigation, remediation, and post-incident improvements.
  • Work with engineering and product teams to enhance application security features and security controls.
  • Evaluate emerging threats, vulnerabilities, attack techniques, and security technologies and continuously improve product security controls.
  • Provide security guidance to developers and engineering teams on secure coding, application architecture, APIs, cloud security, and vulnerability remediation.
  • Communicate security risks and recommendations effectively to both technical and non-technical stakeholders.
Required Qualifications
  • 10–12+ years of experience in Product Security, Application Security, Application Security Engineering, DevSecOps, or a closely related security engineering role.
  • Deep technical knowledge of web and mobile application security and common vulnerabilities, including the OWASP Top 10.
  • Strong understanding of secure software development practices and secure SDLC methodologies.
  • Hands‑on experience implementing and managing Product Security and Application Security tools.
  • Strong experience with SAST, DAST, IAST, SCA, vulnerability scanning, and penetration testing.
  • Strong understanding of API security, including authentication, authorization, API vulnerabilities, and API security testing.
  • Strong understanding of CI/CD pipelines and integrating security tools and controls into DevOps workflows.
  • Hands‑on experience with security automation and DevSecOps practices.
  • Experience securing mobile applications and implementing mobile application protection/security controls.
  • Strong understanding of AWS cloud security principles and services.
  • Experience with Infrastructure as Code (IaC) security and cloud-native application security.
  • Experience conducting threat modeling, security assessments, architecture reviews, and vulnerability remediation.
  • Strong ability to collaborate with Engineering, Product, Platform, and DevOps teams.
  • Excellent written and verbal communication skills with the ability to explain complex security concepts to technical and non-technical audiences.
  • Ability to operate effectively in a fast-paced, highly collaborative environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security / Product Security Engineer Cybersecurity & Networking Practice Mum[...]
Senior Application Security / Product Security Engineer Cybersecurity & Networking Practice Mum[...]

Galaxy Office Automation Pvt. Ltd. • Mumbai

On-site
INR 4,000,000 - 7,000,000
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
TECHNICAL LEAD - Application Security
TECHNICAL LEAD - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Lead- Product Security
Lead- Product Security

AstroFarm by 42Gears • Bengaluru

On-site
INR 2,800,000 - 5,200,000
Product Security Engineer
Product Security Engineer

Hugohub • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Product Security Engineer (Vulnerability Management)
Product Security Engineer (Vulnerability Management)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru Urban

On-site
INR 1,800,000 - 2,400,000
Security Architect
Security Architect

Accenture • Bengaluru

On-site
INR 1,500,000 - 2,500,000