HamburgerMenu
hirist

Product Security Engineer - B2B SaaS

HR Works Consultancy
4 - 7 Years
Bangalore

Posted on: 14/08/2026

Job Description

About the Role:

You'll be responsible for ensuring the security of our platform, protecting customer data, and establishing security practices that scale with our growth. This is a critical early security hire where you'll have significant impact and ownership.

What You'll Do:

- Conduct security audits, vulnerability assessments, and penetration testing across our infrastructure and applications.

- Implement and maintain security controls for our cloud infrastructure (AWS), databases, and data pipelines.

- Build security into our development lifecycle - review code, APIs, and new features for security implications.

- Monitor, detect, and respond to security incidents and vulnerabilities.

- Manage access controls, secrets management, authentication, and authorization systems.

- Drive compliance initiatives to meet enterprise customer requirements.

- Establish security best practices and educate the engineering team on secure development.

- Secure our API integrations and ensure safe handling of financial data and PII.

Requirements:

- Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience.

- Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.

- Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.

- Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.

- Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.

- Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.

- Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...