Product Security Engineer (Devsec Ops)

IndiaIndia·Gurugrammid
Product Security EngineerCybersecurity
1 views0 saves0 applied

Quick Summary

Overview

We are looking for a Product Security Engineer with 3 to 5 years of hands-on experience in identifying, assessing, and mitigating security risks across our products and platforms.

Key Responsibilities

Conduct application security assessments, threat modeling, and code reviews for products and services. Perform static (SAST), dynamic (DAST), and software composition (SCA) analysis using modern tools.

Technical Tools
awsazuregcpgithub-actionsgitlab-cijenkinskubernetespythonterraformci-cdcode-reviewsecurity-best-practices

We are looking for a Product Security Engineer with 3 to 5 years of hands-on experience in identifying, assessing, and mitigating security risks across our products and platforms. The ideal candidate will work closely with engineering, DevOps, and product teams to integrate security throughout the software development lifecycle (SDLC) and ensure the security of our applications and infrastructure.

Responsibilities

~1 min read
  • Conduct application security assessments, threat modeling, and code reviews for products and services.

  • Perform static (SAST), dynamic (DAST), and software composition (SCA) analysis using modern tools.

  • Collaborate with development teams to embed security controls in CI/CD pipelines.

  • Review and enhance security architecture for web, mobile, and API-based applications.

  • Work with DevOps teams to strengthen cloud security posture (AWS/GCP/Azure).

  • Investigate and respond to product security incidents and vulnerability reports.

  • Support bug bounty triage and coordinate fixes with engineering teams.

  • Document and enforce secure coding practices and security guidelines.

  • Participate in design and architecture reviews to ensure security-by-design principles.

  • 3 to 5 years of experience in Application Security or Product Security roles.

  • Strong knowledge of OWASP Top 10 Web, Mobile, API Security Top 10, and secure development practices.

  • Experience in Infrastructure security ( External and Internal)

  • Hands-on experience with tools like Burp Suite, ZAP, Check Marx, SonarQube, Veracode, GitLab Security, etc.

  • Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and integrating security scans.

  • Knowledge of cloud security (AWS, Azure, GCP) and exposure to IAM, KMS, and network controls.

  • Scripting knowledge (Python, Bash, or PowerShell) for automating security tasks.

  • Understanding of container and Kubernetes security concepts.

  • Experience with threat modeling (STRIDE, PASTA, etc.).

  • Familiarity with infrastructure as code (Terraform, CloudFormation) security validation.

  • Exposure to DevSecOps practices and security orchestration.

  • Certifications such as CEH, OSCP, CSSLP, or AWS Security Specialty are a plus.

Location & Eligibility

Where is the job
Gurugram, India
On-site at the office
Who can apply
IN

Listing Details

First seen
May 6, 2026
Last seen
May 29, 2026

Posting Health

Days active
23
Repost count
0
Trust Level
14%
Scored at
May 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

lenskartcareersProduct Security Engineer (Devsec Ops)