Posted on: 24/09/2026
Senior Application / Product Security Engineer
Experience : 7+ Years
Location : Bangalore/Pune
Employment Type : Full-Time
Job Description :
We are looking for a Senior Application / Product Security Engineer with 7+ years of relevant experience in application security, product security, secure software development, cloud security, and container/Kubernetes security.
The candidate should have strong hands-on experience in securing applications and products throughout the Software Development Life Cycle (SDLC) and should be comfortable working with engineering, DevOps, cloud, and product teams.
Mandatory Technical Skills :
Candidates must have hands-on experience in ALL of the following areas :
- Application Security / Product Security / Secure SDLC :
1. Strong experience integrating security throughout the Software Development Life Cycle.
2. Experience identifying and mitigating application and product security vulnerabilities.
3. Secure coding practices, security reviews, vulnerability management, and security testing.
- Threat Modeling & Risk Assessment :
1. Hands-on experience performing threat modeling for applications/products.
2. Ability to identify security threats, attack vectors, vulnerabilities, and associated risks.
3. Experience with security risk assessment and defining appropriate mitigation strategies.
- Azure / AWS Cloud Security :
1. Strong hands-on experience securing workloads deployed on Microsoft Azure and/or AWS.
2. Knowledge of cloud security architecture, IAM, network security, data protection, security monitoring, and cloud security best practices.
3. Experience identifying and mitigating cloud-specific security risks.
- Container & Kubernetes Security :
1. Hands-on experience securing Docker/containerized applications and Kubernetes environments.
2. Knowledge of container image security, vulnerabilities, runtime security, Kubernetes RBAC, secrets management, network policies, and workload security.
3. Experience implementing security controls in containerized environments.
Key Responsibilities :
- Drive application and product security initiatives across the complete SDLC.
- Conduct threat modeling and security risk assessments for applications and products.
- Work closely with development teams to identify and remediate security vulnerabilities.
- Define and implement secure development practices and security controls.
- Assess and improve security of applications deployed on AWS/Azure.
- Review cloud architectures and identify potential security risks.
- Implement and assess security controls for Docker and Kubernetes environments.
- Collaborate with DevOps, Cloud, Engineering, and Product teams to integrate security into CI/CD pipelines.
- Support vulnerability assessment, remediation, and security validation activities.
- Provide security guidance to engineering teams and help establish secure-by-design practices.
- Contribute to security standards, guidelines, and best practices across products and applications.
Mandatory Requirements :
Candidates must meet ALL of the following :
1. 7+ years of relevant cybersecurity/application security experience
2. Strong experience in Application Security / Product Security / Secure SDLC
3. Hands-on experience in Threat Modeling and Risk Assessment
4. Hands-on experience in Azure and/or AWS Cloud Security
5. Hands-on experience in Container and Kubernetes Security
Profiles missing any one of the above mandatory areas should not be considered.
Preferred Experience :
- DevSecOps / CI/CD security
- SAST / DAST / SCA
- OWASP Top 10
- Vulnerability management
- Security architecture and design reviews
- IAM and secrets management
- Docker security
- Kubernetes security
- Cloud-native security
- Security automation and scripting
Candidate Profile :
The ideal candidate will be a hands-on security professional who can work across Application Security, Product Security, Cloud Security, and Container/Kubernetes Security, rather than someone with experience limited to SOC, network security, or compliance.
Relevant experience matters more than generic cybersecurity experience.
Did you find something suspicious?
Posted by
Recruiter
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1674183