27 Sep
|
Synamedia
|
Bengaluru
27 Sep
Synamedia
Bengaluru
Greetings from Synamedia!!!!
About the Job
We are looking for an Application Security Engineer to strengthen the security of Synamedia products and the software development lifecycle. The role partners with engineering, architecture, DevOps, cloud and security teams to identify risks early, automate security controls, and help teams build secure products at scale. The ideal candidate combines hands-on AppSec skills with strong software engineering awareness and can translate security findings into practical remediation guidance.
Responsibilities
- Perform security assessments of web applications, APIs, microservices and cloud-native applications.
- Conduct threat modelling and security design reviews for new products, features and architectural changes.
- Perform secure code reviews and identify vulnerabilities, insecure coding patterns and design weaknesses.
- Implement and improve SAST, DAST, SCA, secrets scanning and related AppSec tooling.
- Integrate automated security checks and risk-based quality gates into CI/CD pipelines.
- Validate, triage and prioritize vulnerabilities based on exploitability, technical impact and business risk.
- Work with engineering teams to provide actionable remediation guidance and track vulnerabilities through closure.
- Assess authentication, authorization, session management, cryptography, data protection and input-validation controls.
- Perform security testing of REST APIs and service interfaces, including authorization, injection, data exposure and business-logic issues.
- Develop security automation and scripts to improve the scalability and effectiveness of the AppSec program.
- Define secure coding guidance, security checklists and developer enablement material.
- Contribute to application-security metrics, reporting and continuous improvement of the Secure SDLC.
Skills Required
- 7+ years of relevant experience in Application Security, Product Security, DevSecOps, penetration testing or secure software development.
- Strong understanding of OWASP Top 10, OWASP API Security Top 10, CWE/common vulnerability classes and secure coding principles.
- Hands-on experience with SAST, DAST, Software Composition Analysis (SCA), secrets scanning and web/API security testing tools such as Burp Suite or OWASP ZAP.
- Experience conducting threat modelling using STRIDE or a comparable methodology.
- Ability to review source code from a security perspective in one or more languages such as Java, C/C++, C#, Python, JavaScript/TypeScript or Go.
- Understanding of CI/CD technologies such as Jenkins, GitHub Actions, along with Git-based development workflows.
- Ability to clearly communicate vulnerability impact, exploit scenarios, remediation options and risk to engineering stakeholders.
- Experience with AWS, Azure or GCP; Docker, Kubernetes and Infrastructure-as-Code security.
- Experience with tools such as Black Duck, Coverity, Trivy, and TruffleHog
- Familiarity with OAuth 2.0, OpenID Connect, SAML, JWT, RBAC and up-to-date identity/security patterns.
- Exposure to software supply-chain security, SBOM, dependency governance and secrets management.
- Security certifications such as CSSLP, CISSP, CCSP are advantageous but not mandatory.
Good to Have Synamedia Product & Video Domain
- Experience or domain knowledge in video streaming, broadcast, OTT, Pay-TV or media technology environments.
- Exposure to solutions similar to Synamedia Go, Synamedia Iris, Conditional Access, DRM and video/content security platforms.
- Understanding of Conditional Access systems, DRM, entitlement management, content protection, anti-piracy and secure video delivery.
- Familiarity with OTT/video technologies and protocols such as HLS, MPEG-DASH, CDNs, streaming APIs, video players and Server-Side Ad Insertion (SSAI).
- Understanding of application-security risks in addressable advertising and video monetisation platforms, including APIs, audience/customer data, ad-tech integrations, identity controls and cloud services.
- Exposure to securing cloud-native SaaS video platforms, microservices, APIs, containers and distributed systems.
Good to Have AI & AI-Assisted Development
- Familiarity with AI-assisted software development and the secure adoption of Generative AI tools in engineering workflows.
- Understanding of risks in AI-generated code, including insecure patterns, vulnerable dependencies, secrets exposure, licensing concerns and insufficient validation.
- Ability to help define secure-development practices for teams using AI coding assistants and GenAI development tools.
- Experience assessing applications that integrate LLMs, AI agents or Generative AI capabilities is desirable.
- Awareness of AI security risks such as prompt injection, sensitive-data disclosure, insecure output handling, excessive agency, model/API abuse and third-party AI supply-chain risk.
- Ability to support threat modelling and security reviews for AI-enabled features and services.
- Awareness of OWASP guidance for LLM / Generative AI application security.
- Interest in using AI and automation to improve vulnerability triage, secure code review, threat modelling, remediation guidance and security testing.
📌 Lead InfoSec Engineer (Bengaluru)
🏢 Synamedia
📍 Bengaluru