29 Aug
|
SRM Technologies
|
Chennai
29 Aug
SRM Technologies
Chennai
Role & responsibilities
- Triage, validate, and prioritize security vulnerabilities identified through manual reviews, automated tooling, bug bounty reports, and AI-assisted security analysis platforms.
- Participate in on-call rotation to support security incident triage, perform code reviews, and address security questions.
- Partner closely with engineering teams to drive remediation efforts, provide actionable guidance, and ensure timely closure of security findings based on risk and severity.
- Review security-related pull requests and code changes, providing guidance on secure implementation patterns and identifying potential vulnerabilities before production deployment.
- Analyze findings generated by AI-powered security agents and automation platforms, validate results, reduce false positives, and help drive remediation workflows across engineering teams.
- Collaborate with Product Security Architecture and development teams to improve vulnerability detection, prioritization, and remediation processes.
- Support security incident investigations and root cause analysis when vulnerabilities or application security issues are discovered.
- Develop security tooling, automation, and workflows that improve security coverage and reduce manual effort for security reviews and vulnerability management.
- Administer and manage vulnerability scanning tools (e.g., Tenable or similar)
- Configure, optimize, and maintain scanning tools, policies, and schedules
- Track and report on remediation progress, security metrics, and risk reduction initiatives across assigned engineering organizations.
- Contribute to security documentation,
best practices, and developer education efforts to improve secure coding practices
Preferred candidate profile
- Available to work until 11:00AM Pacific Standard Time (PST).
- 3+ years experience in application security engineering
- Strong communication skills and relationship building skills
- Experience in building and scaling the Secure Development Lifecycle
- Experience with handling vulnerability, and bug bounty reports
- Experience partnering with cross-functional engineering and product teams
- Experience triaging, validating, and prioritizing security vulnerabilities from static analysis, agile analysis, dependency scanning, penetration testing, or bug bounty programs.
- Experience partnering with software engineering teams to drive remediation and risk reduction efforts.
- Strong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.).
- Experience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks.
- Familiarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms.
- Experience working with cloud-native architectures and public cloud environments (AWS preferred).
- Ability to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations.
- Familiarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases is a plus.
📌 Application Product Security Engineer - (Vulnerability) (Chennai)
🏢 SRM Technologies
📍 Chennai