01 Sep
|
Slice
|
Bengaluru
Job Description
About the role:
n
nAs a Cyber Security Engineer at slice, you will play a key role in strengthening our Application and Product Security program by embedding security throughout the Software Development Lifecycle (SDLC). You will work closely with engineering, product, and infrastructure teams to identify security risks early, conduct security assessments, and help build secure, scalable products that meet industry standards and compliance requirements.
n
nThis role is ideal for someone passionate about offensive security, secure design, mobile and API security, and DevSecOps.
n
nWhat you will do:
n
nApplication Security
n
n
- n
- Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, Android, and iOS applications.n
- Conduct Secure Design Reviews and identify potential security risks during the design phase.n
- Perform Threat Modeling sessions for new applications, services, and major feature releases.n
- Validate security controls and perform security re-testing after vulnerabilities are remediated.n
- Prepare detailed security assessment reports with clear remediation guidance and risk prioritization.n
n
nMobile & API Security
n
n
- n
- Perform static and dynamic security analysis of Android and iOS applications.n
- Assess REST APIs and microservices for authentication, authorization, business logic, and data exposure vulnerabilities.n
nIdentify vulnerabilities such as:
n
- n
- Broken Authenticationn
- Broken Authorization (BOLA/IDOR)n
- Injection attacksn
- Sensitive Data Exposuren
- Business Logic flawsn
- Security Misconfigurationn
- Rate-limit bypassn
- SSRF, XXE, CSRF, XSS, and related web security issuesn
n
- n
- Provide secure coding recommendations and remediation guidance.n
- Contribute to the implementation and improvement of SAST, DAST, SCA, Secret Scanning, and Infrastructure-as-Code (IaC) security practices.n
- Evaluate current technologies and
📌 Product Security Engineer (Bengaluru)
🏢 Slice
📍 Bengaluru