Senior Product Security Engineer

Pocket FM Corp.

Bengaluru

Vor Ort

INR 2.000.000 - 3.200.000

Vollzeit

vor 34 Stunden
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, fertig zum Versenden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Pocket FM Corp. is seeking a Senior Security Engineer in Product Security to champion security across the product lifecycle.

You will work with engineering, product management, and stakeholders to identify and mitigate risks, ensuring security and compliance are built-in from the start. You will conduct manual testing across web, mobile, and API surfaces, participate in threat modeling, and drive security through CI/CD pipelines with SAST, SCA, and secrets detection.

Qualifikationen

  • 4+ years hands-on in product security, application security, or related field.
  • Experience in manual web, mobile, and API penetration testing methodologies.
  • Experience conducting security-focused code reviews and identifying vulnerability classes (OWASP Top 10, CWE).
  • Hands-on with SAST tooling (Semgrep, CodeQL, or similar) and CI/CD security integration.
  • Experience with secrets detection tooling (Trufflehog, Gitleaks, or GitHub secret scanning) and hygiene programs.
  • Familiarity with SCA/dependency scanning tools (Snyk, OWASP Dependency-Check, Dependabot).
  • Strong secure coding practices and SDLC knowledge.
  • Scripting in Python/Bash for automation.

Aufgaben

  • Conduct manual penetration testing across web, mobile, and API surfaces.
  • Perform security assessments and threat modeling for products.
  • Operate secrets detection across repositories and drive remediation with teams.
  • Tune and integrate SAST tooling into CI/CD pipelines.
  • Run SCA/dependency checks and manage vulnerable dependencies.
  • Define pre-merge security gates for secrets, SAST and dependencies.
  • Develop secure coding guidelines and security standards.
  • Automate security processes and build internal tooling.
  • Support developer security education and awareness.

Kenntnisse

Penetration testing
Threat modeling
SAST tooling
CI/CD security
Secrets detection
SCA tooling
Python scripting
Communication
Collaboration
Cloud security

Tools

Semgrep
CodeQL
Wiz
Trufflehog
Gitleaks
Snyk
OWASP Dependency-Check
Dependabot

Jobbeschreibung

As a Senior Security Engineer in Product Security, you will play a key hands-on role in

championing security throughout the entire product development lifecycle. You will collaborate

with engineering, product management, and other stakeholders to identify and mitigate security risks, ensuring our products are built with security and compliance in mind.

What You Will Be Doing:
Security Testing & Assessments
  • Conduct manual penetration testing across web, mobile (Android/iOS), and API surfaces, including authentication mechanisms, payment and subscription flows, and content delivery pipelines.
  • Participate in security assessments and threat modeling for new and existing products.
  • Leverage AI-assisted testing approaches including LLM-based code auditing, automated payload generation, and AI-augmented threat modeling to increase testing depth and coverage.
Shift-Left Security: SAST, Secrets & Dependencies
  • Own and operate secrets detection across source code repositories using tools like Wiz, Trufflehog or Gitleaks covering hardcoded credentials, API keys, tokens, and cloud access keys and drive remediation with engineering teams.
  • Manage and tune SAST tooling (Wiz, Semgrep, CodeQL) integrated into CI/CD pipelines; reduce false positive noise and work with developers to remediate flagged findings effectively.
  • Run Software Composition Analysis (SCA) to identify vulnerable, outdated, or malicious open-source dependencies; own the pipeline using tools like Wiz, Snyk, OWASP Dependency-Check, or Dependabot.
  • Define and enforce pre-merge security gates for secrets, SAST, and dependency checks across engineering teams.
  • Contribute to and execute the product security strategy, aligned with business objectives and industry best practices.
  • Develop and maintain secure coding guidelines and security engineering standards for development teams.
  • Automate repetitive security processes and build internal tools to boost team productivity and visibility.
  • Actively participate in security awareness initiatives and support developer education on secure coding best practices.
  • Collaborate with product managers to integrate security considerations into the product development lifecycle.
  • Manage and prioritize product security vulnerabilities, working with engineering teams on effective remediation plans.
Monitoring & Reporting
  • Stay current on the latest security threats, vulnerabilities, and attacker techniques; proactively surface and address risks.
  • Develop and maintain security documentation including threat models, security requirements, and incident response runbooks.
  • Contribute to product security metrics and help communicate security posture to relevant stakeholders.
  • Support security incident response activities and provide guidance on mitigation strategies as needed.
What You Will Need:
  • 4+ years of hands-on experience in product security, application security, or a closely related field.
  • Proven experience in manual web, mobile, and API penetration testing methodologies.
  • Experience conducting security-focused code reviews and identifying common vulnerability classes (OWASP Top 10, CWE).
  • Hands-on experience with SAST tooling (Semgrep, CodeQL, or similar) and integrating security checks into CI/CD pipelines.
  • Experience with secrets detection tooling (Trufflehog, Gitleaks, or GitHub secret scanning) and driving secrets hygiene programs.
  • Familiarity with SCA/dependency scanning tools (Snyk, OWASP Dependency-Check, Dependabot, or similar).
  • In-depth understanding of secure coding practices and secure SDLC principles.
  • Scripting experience in Python, Bash, or similar for automation and tooling.
  • Strong analytical and problem-solving skills with the ability to manage multiple workstreams.
  • Excellent communication and collaboration skills with the ability to work effectively with engineering and product teams.
Strong Advantage
  • Experience with AWS security services (IAM, GuardDuty, WAF, CloudTrail, Security Hub) and/or GCP security (Security Command Center, Cloud Armor, IAM, VPC Service Controls).
  • Mobile security experience, Android and/or iOS app security testing, including reverse engineering, insecure storage, certificate pinning bypass, and DRM/offline flow analysis.
  • Familiarity with AI-assisted security testing and LLM-based code auditing workflows.
  • Experience with or exposure to Bug Bounty/Vulnerability Disclosure Programs.
Certifications (Nice to Have)
  • OSCP or equivalent hands-on offensive security certification.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Product Security Engineer (Devsec Ops)
Product Security Engineer (Devsec Ops)

Lenskart • Gurugram District

Vor Ort
INR 1.500.000 - 2.300.000
Senior Application Security Engineer
Senior Application Security Engineer

Tenarai • Bengaluru

Vor Ort
INR 2.500.000 - 4.200.000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

Vor Ort
INR 3.500.000 - 6.500.000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

Vor Ort
INR 4.000.000 - 7.000.000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

Vor Ort
INR 1.200.000 - 2.000.000
Application Security Engineer
Application Security Engineer

GCS Recruitment Specialists • Pune District

Vor Ort
INR 1.800.000 - 2.800.000
Application Security Engineer
Application Security Engineer

ESDS Software Solution Limited • Nashik District

Vor Ort
INR 1.200.000 - 1.800.000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

Vor Ort
INR 1.200.000 - 1.800.000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

Vor Ort
INR 1.500.000 - 3.000.000
Product Security Engineer
Product Security Engineer

preciselyinternationaljobs • Indien

Vor Ort
INR 1.200.000 - 1.800.000