06 Aug
|
Tidyhire
|
India
We are seeking a Product Security Engineer for one of our clients (global-scale payment systems impacting millions of users) to strengthen the security posture of our applications and cloud-native platforms. This role focuses on proactive application security testing, vulnerability management, secure SDLC integration, and collaboration with engineering teams.
You will independently conduct security assessments across web applications, APIs, and cloud environments, while supporting secure development practices and contributing to improving overall product security maturity.
Key Responsibilities :
Application &
- API Security :
- Conduct manual and automated penetration testing of web applications and APIs.
- Identify and validate vulnerabilities aligned with OWASP Top 10 and API Security Top 10.
- Perform threat modeling for current features and services.
- Conduct secure code reviews (static analysis) and recommend remediation.
- Validate findings from SAST, DAST, and dependency scanning tools.
- Provide remediation guidance and conduct fix verification testing.
- Participate in design reviews and architecture discussions from a security perspective.
Cloud &
- Infrastructure Security :
- Assess AWS/Azure/GCP configurations for common misconfigurations.
- Review IAM policies, storage access controls, and container security posture.
- Validate findings from CSPM/CNAPP tools.
- Support cloud-native application security assessments.
Vulnerability Management :
- Prioritize vulnerabilities using CVSS and business impact context.
- Track remediation SLAs and support risk acceptance decisions.
- Provide actionable recommendations to development teams.
Security Testing &
- Automation :
- Develop scripts and tooling (Python/Bash) to automate testing workflows.
- Improve security testing playbooks and documentation.
- Contribute to enhancing detection and monitoring coverage.
Collaboration &
- Reporting :
- Prepare high-quality technical reports with clear risk articulation.
- Translate technical findings into business-impact language.
- Work cross-functionally with DevOps, Cloud, and Engineering teams.
Required Skills :
- 6 - 12 years of experience in Application Security, Product Security, or Offensive Security.
- Hands-on experience conducting web and API penetration testing.
- Strong understanding of OWASP Top 10 and common attack vectors.
- Experience using tools such as Burp Suite, OWASP ZAP, Nmap, Snyk, Checkmarks, etc.
- Experience working with cloud platforms (AWS/Azure/GCP).
- Familiarity with container security and modern DevOps environments.
- Experience reviewing code for security issues.
- Strong understanding of HTTP, authentication mechanisms, and networking fundamentals.
- Basic scripting experience (Python, Bash, or similar).
Preferred Experience :
- Experience in SaaS, fintech, or product-based organizations.
- Exposure to Kubernetes and container security testing.
- Familiarity with bug bounty or responsible disclosure programs.
- Experience implementing DevSecOps practices.
- Certifications such as CEH, Security , eJPT, OSCP (nice to have).
📌 Senior Product Security Engineer - VAPT (India)
🏢 Tidyhire
📍 India