30 Sep
|
Billow People Services
|
Bengaluru
30 Sep
Billow People Services
Bengaluru
Role & responsibilities
- Conduct manual and automated security testing of web applications and APIs to identify and validate security vulnerabilities.
- Perform penetration testing across applications, APIs, cloud environments, and network infrastructure.
- Assess applications against OWASP Top 10 and API Security Top 10 vulnerabilities.
- Perform threat modeling for current features, applications, and services.
- Conduct secure code reviews and validate findings from SAST, DAST, and dependency-scanning tools.
- Assess AWS, Azure, and GCP environments for security misconfigurations, IAM issues, storage access controls, and container security risks.
- Perform security assessments of Kubernetes and cloud-native environments.
- Identify, prioritize, and track vulnerabilities based on CVSS, business impact, and remediation SLAs.
- Develop scripts and security tooling using Python, Bash, or similar technologies to automate penetration-testing and security-testing workflows.
- Contribute to security automation, testing playbooks, detection improvements, and DevSecOps initiatives.
- Support AI/LLM security assessments, red-team exercises, and offensive security activities.
- Prepare detailed security assessment reports with clear technical findings, business impact, and remediation recommendations.
- Collaborate with Engineering, DevOps, Cloud,
and other technical teams to improve overall product security.
Preferred candidate profile
- 69 years of experience in Application Security, Product Security, Offensive Security, or a related cybersecurity domain.
- Strong hands-on experience in Web + API Penetration Testing.
- Practical experience in AI/LLM Security, Cloud/Network Security, Security/Pentest Automation, and Red Teaming.
- Strong understanding of OWASP Top 10, API Security Top 10, common attack vectors, authentication, authorization, HTTP, and networking fundamentals.
- Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Snyk, and Checkmarx.
- Hands-on experience with AWS, Azure, or GCP security.
- Experience with Kubernetes, containers, and modern DevOps/cloud-native environments.
- Good understanding of vulnerability management, CVSS, risk prioritization, and remediation tracking.
- Experience with secure code review and SAST/DAST tools.
- Working knowledge of Python, Bash, or similar scripting languages.
- Experience implementing or supporting DevSecOps and security automation.
- Exposure to bug bounty/responsible disclosure programs is an advantage.
- Security certifications such as CEH, Security+, eJPT, or OSCP are an advantage.
📌 Senior Product Security Engineer (Bengaluru)
🏢 Billow People Services
📍 Bengaluru