Security Engineer IV
Team: Infrastructure
Location: Bangalore, Karnataka
Commitment: Full Time Employee
Workplace Type: onsite
What you will do
- Lead and manage all aspects of the Secure Software Development Lifecycle (SDLC).
- Implement and manage security tools within the CI/CD pipeline (DevSecOps).
- Conduct and oversee VAPT for web applications, APIs, iOS, and Android apps.
- Perform threat modeling, design, and architecture reviews to identify potential risks.
- Execute manual source code reviews and enhance security in production environments.
- Manage and optimize a self-managed bug bounty program.
- Provide security architectural guidance to Engineering and IT teams.
- Manage issues identified from penetration tests and bug bounty programs.
- Lead security training and awareness campaigns across the organization.
- Manage Web Application Firewalls (WAF) to ensure robust protection.
- Engage in the Security Champions program to integrate security practices within teams.
- Assist in creating and maintaining Security Risk Models for both new and existing systems.
What you will need
- 7+ years of experience in product security, with a focus on application security and Dev SecOps.
- Proven experience in leading architectural changes or cross-team efforts to mitigate security vulnerabilities.
- Proficiency in programming languages such as Java, React, Node.js, and Python.
- Hands-on experience with manual source code reviews and securing production code.
- Expertise in deploying and managing security tools in CI/CD pipelines.
- Experience with Git, Jenkins, Artifactory, or other similar technologies.
- Strong background in securing the software development lifecycle, including eliminating classes of vulnerabilities.
- Proficiency with cloud platforms like AWS or GCP, including their security tools.
- Experience with Docker and containerization technologies is highly desirable.
- Additional experience in infrastructure security, particularly in GCP, Docker, and containerization, is a bonus.
Bonus Points
- Relevant certifications such as GIAC Web Application Penetration Tester (GWAPT), OffSec’s Advanced Web Attacks and Exploitation (WEB-300), etc.
- Strong understanding of SSO protocols, including OAuth and SAML.
- Experience speaking at meetups or conferences.
- Experience participating in bug bounty programs.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
