Senior Product Security Engineer
enableIT · Karnataka, India
FULL TIMEcontract
Job Description
Senior Product Security Engineer Experience: 10–12 Years Employment Type: Contract / Full-Time Location: Bangalore (Hybrid) Industry: FinTech / Financial Services Job Summary: We are seeking an experienced Senior Product Security Engineer to help strengthen the security of our products and services throughout the entire software development lifecycle. This role will play a critical hands-on role in defining and implementing product security strategies, embedding security into engineering and product development processes, and protecting customer data. The ideal candidate will have strong expertise in application security, product security, cloud security, secure SDLC, DevSecOps, vulnerability management, and security automation , with proven experience working closely with engineering, product, and platform teams. Key Responsibilities: Support the development and execution of a comprehensive Product Security strategy aligned with business objectives, security requirements, and organizational risk appetite. Partner with Engineering and Product teams to foster a strong security-first culture and promote security ownership across the organization. Integrate security best practices, automated security controls, and tooling throughout the Software Development Lifecycle (SDLC) . Perform and support security architecture reviews, threat modeling, vulnerability assessments, and secure design reviews . Establish and enforce secure development standards covering API security, secure coding, infrastructure-as-code (IaC), application architecture, and cloud environments . Lead and manage application security programs covering SAST, DAST, IAST, SCA, vulnerability management, and manual penetration testing . Implement and manage product security tooling across web and mobile applications, including API security, mobile application protection, runtime security, and application scanning . Partner closely with Engineering, Product, DevOps, Cloud, and Platform teams to identify, prioritize, track, and remediate security vulnerabilities. Develop and improve security automation within CI/CD pipelines to identify and prevent vulnerabilities earlier in the development lifecycle. Establish and maintain processes for product security incident response , vulnerability disclosure, investigation, remediation, and post-incident improvements. Work with engineering and product teams to enhance application security features and security controls. Evaluate emerging threats, vulnerabilities, attack techniques, and security technologies and continuously improve product security controls. Provide security guidance to developers and engineering teams on secure coding, application architecture, APIs, cloud security, and vulnerability remediation. Communicate security risks and recommendations effectively to both technical and non-technical stakeholders. Required Qualifications: 10–12 years of experience in Product Security, Application Security, Application Security Engineering, DevSecOps, or a closely related security engineering role. Deep technical knowledge of web and mobile application security and common vulnerabilities, including the OWASP Top 10 . Strong understanding of secure software development practices and secure SDLC methodologies. Hands-on experience implementing and managing Product Security and Application Security tools . Strong experience with SAST, DAST, IAST, SCA, vulnerability scanning, and penetration testing . Strong understanding of API security , including authentication, authorization, API vulnerabilities, and API security testing. Strong understanding of CI/CD pipelines and integrating security tools and controls into DevOps workflows. Hands-on experience with security automation and DevSecOps practices . Experience securing mobile applications and implementing mobile application protection/security controls. Strong understanding of AWS cloud security principles and services . Experience with Infrastructure as Code (IaC) security and cloud-native application security. Experience conducting threat modeling, security assessments, architecture reviews, and vulnerability remediation . Strong ability to collaborate with Engineering, Product, Platform, and DevOps teams. Excellent written and verbal communication skills with the ability to explain complex security concepts to technical and non-technical audiences. Ability to operate effectively in a fast-paced, highly collaborative environment .
Details
| Company | enableIT |
| Location | Karnataka, India |
| Type | FULL TIME |
| Niche | tech |
| Experience | contract |
