HamburgerMenu
hirist

Job Description

Position : Product Security Engineer (B2B SaaS)

Total Experience : 4-7 years

Location : Bengaluru

Working Days : 5 Days from Office

Notice Period Requirement : 60 Days (Maximum)

Client's Company Size : Startup / Small Enterprise

Roles & Responsibilities :

- Conduct security audits, vulnerability assessments, and penetration testing across our infrastructure and applications.

- Implement and maintain security controls for our cloud infrastructure (AWS), databases, and data pipelines.

- Build security into our development lifecycle - review code, APIs, and new features for security implications.

- Monitor, detect, and respond to security incidents and vulnerabilities.

- Manage access controls, secrets management, authentication, and authorization systems.

- Drive compliance initiatives to meet enterprise customer requirements.

- Establish security best practices and educate the engineering team on secure development.

- Secure our API integrations and ensure safe handling of financial data and PII.

Candidate Requirements :

- Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles.

- Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience.

- Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.

- Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.

- Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.

- Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.

- Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.

- Preferred Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...