24 Sep
|
Tenarai
|
Bengaluru
Senior Application/Product Security Engineer
This is a hands-on role for someone who wants to work inside engineering delivery: reviewing code and designs, helping developers fix security issues, improving CI/CD security checks, and driving product-security findings to verified closure.
Role:
- Perform hands-on security reviews of applications, APIs, services, and supporting components.
- Review pull requests, application designs, authentication and authorization flows, secrets handling, logging, and data-exposure risks.
- Triage SAST, SCA, DAST, secret-scanning, container-scanning, penetration-test, and product vulnerability findings.
- Work directly with developers to implement secure fixes and reduce recurring issue classes.
- Improve CI/CD security checks, branch protection, merge controls, and release-readiness signals.
- Support secure-design reviews, focused application security testing, and remediation validation.
- Coach developers and help identify local Security Champions.
Required Skills:
- Atleast 8+ yrs hands-on experience in application security, product security, DevSecOps, or software security engineering.
- Proven ability to work directly with developers to fix security issues in code, configuration, and delivery pipelines.
- Experience triaging and remediating vulnerabilities in large or legacy codebases.
- Practical experience with SAST, SCA, DAST, secret scanning, container scanning, and vulnerability management workflows.
- Ability to read and review application code in languages such as Java, .NET, JavaScript / TypeScript, Python, or similar.
- Robust understanding of web, API, authorization, session, secrets, dependency, logging, and secure deployment risks.
- Comfortable working inside engineering rhythms: standups, sprint planning, pull requests, release readiness, and backlog refinement.
Good to have:
- Experience with cloud-native environments, AWS, Kubernetes, or containers.
- Experience with legacy modernization, dependency remediation, software-supply-chain risk, or product vulnerability management.
- OSCP, CSSLP, CISSP, GWAPT, cloud security, secure software, or application security certifications.
📌 Senior Application Security Engineer (Bengaluru)
🏢 Tenarai
📍 Bengaluru