Application Security - Vulnerability Discovery

Posted 8 Days Ago
Be an Early Applicant
Hiring Remotely in Chennai, IND
In-Office or Remote
Mid level
Information Technology
The Role
Triage, validate, prioritize, and track remediation of application vulnerabilities from various sources (SAST/DAST/SCA/bug bounties). Perform code reviews, support on-call incident triage, manage scanning tools, develop security tooling and automation, collaborate with engineering to drive remediation, and contribute to secure SDLC practices and developer education.
Summary Generated by Built In

This is a remote position.

Product Security Engineer CW Job Description

This document outlines the job description for an Application Security Engineer (Contractor) that will be partnering with the Product Security organization 

 

Team Description 

As part of the Product Security Engineering team, you’ll be working to reduce overall security risk across Dropbox. We partner with engineering and product teams during each point of the software development lifecycle (SDLC) and help drive broader security initiatives across Dropbox.

 

Product Security Engineers provide security impact by developing secure-by-default libraries and frameworks that teams across Dropbox can frictionlessly integrate into their products. They also offer their expertise on security matters through documentation and educational initiatives.

Responsibilities

  • Triage, validate, and prioritize security vulnerabilities identified through manual reviews, automated tooling, bug bounty reports, and AI-assisted security analysis platforms.
  • Participate in on-call rotation to support security incident triage, perform code reviews, and address security questions.
  • Partner closely with engineering teams to drive remediation efforts, provide actionable guidance, and ensure timely closure of security findings based on risk and severity.
  • Review security-related pull requests and code changes, providing guidance on secure implementation patterns and identifying potential vulnerabilities before production deployment.
  • Analyze findings generated by AI-powered security agents and automation platforms, validate results, reduce false positives, and help drive remediation workflows across engineering teams.
  • Collaborate with Product Security Architecture and development teams to improve vulnerability detection, prioritization, and remediation processes.
  • Support security incident investigations and root cause analysis when vulnerabilities or application security issues are discovered.
  • Develop security tooling, automation, and workflows that improve security coverage and reduce manual effort for security reviews and vulnerability management.
  • Administer and manage vulnerability scanning tools (e.g., Tenable or similar)
  • Configure, optimize, and maintain scanning tools, policies, and schedules
  • Track and report on remediation progress, security metrics, and risk reduction initiatives across assigned engineering organizations.
  • Contribute to security documentation, best practices, and developer education efforts to improve secure coding practices across Dropbox.

 

Requirements

  • Available to work until 11:00AM Pacific Standard Time (PST).
  • 3+ years experience in application security engineering
  • Strong communication skills and relationship building skills
  • Experience in building and scaling the Secure Development Lifecycle
  • Experience with handling vulnerability, and bug bounty reports
  • Experience partnering with cross-functional engineering and product teams
  • Experience triaging, validating, and prioritizing security vulnerabilities from static analysis, dynamic analysis, dependency scanning, penetration testing, or bug bounty programs.
  • Experience partnering with software engineering teams to drive remediation and risk reduction efforts.
  • Strong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.).
  • Experience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks.
  • Familiarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms.
  • Experience working with cloud-native architectures and public cloud environments (AWS preferred).
  • Ability to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations.
  • Familiarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases is a plus.

 



Skills Required

  • Available to work until 11:00AM Pacific Standard Time (PST).
  • 3+ years experience in application security engineering
  • Strong communication skills and relationship building skills
  • Experience in building and scaling the Secure Development Lifecycle
  • Experience with handling vulnerability and bug bounty reports
  • Experience partnering with cross-functional engineering and product teams
  • Experience triaging, validating, and prioritizing security vulnerabilities from static analysis, dynamic analysis, dependency scanning, penetration testing, or bug bounty programs
  • Experience partnering with software engineering teams to drive remediation and risk reduction efforts
  • Strong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography)
  • Experience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks
  • Familiarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms
  • Experience working with cloud-native architectures and public cloud environments
  • Experience with AWS
  • Ability to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations
  • Familiarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chennai
1,396 Employees
Year Founded: 1998

What We Do

SRM Technologies is a global IT services company specialising in automotive technologies, digital transformation and product engineering services. We provide technology consulting, platform development, data analytics, artificial intelligence, cloud enablement, digital infrastructure, quality assurance, embedded software and design to manufacturing product solutions to various industries and enterprises across the North America, Japan, Europe and India. At the heart of our organization are passionate employees who embody our core belief - 'ideas@work.' We firmly believe that ideas and innovation truly matter only when they create a meaningful impact on our customers' businesses and the lives of their end customers. Therefore, we prioritize the practical application of these ideas and their transformative impact through our talented and ever-growing workforce. 𝘚𝘙𝘔 𝘛𝘦𝘤𝘩 𝘪𝘴 𝘢 𝘱𝘳𝘰𝘶𝘥 𝘮𝘦𝘮𝘣𝘦𝘳 𝘰𝘧 𝘵𝘩𝘦 𝘚𝘙𝘔 𝘎𝘳𝘰𝘶𝘱, 𝘢 𝘮𝘶𝘭𝘵𝘪𝘯𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘤𝘰𝘯𝘨𝘭𝘰𝘮𝘦𝘳𝘢𝘵𝘦 𝘸𝘪𝘵𝘩 𝘢 𝘳𝘪𝘤𝘩 𝘩𝘪𝘴𝘵𝘰𝘳𝘺 𝘴𝘱𝘢𝘯𝘯𝘪𝘯𝘨 𝘰𝘷𝘦𝘳 𝘧𝘰𝘶𝘳 𝘥𝘦𝘤𝘢𝘥𝘦𝘴. 𝘛𝘩𝘦 𝘚𝘙𝘔 𝘎𝘳𝘰𝘶𝘱 𝘰𝘱𝘦𝘳𝘢𝘵𝘦𝘴 𝘪𝘯 𝘥𝘪𝘷𝘦𝘳𝘴𝘦 𝘴𝘦𝘤𝘵𝘰𝘳𝘴, 𝘪𝘯𝘤𝘭𝘶𝘥𝘪𝘯𝘨 𝘌𝘥𝘶𝘤𝘢𝘵𝘪𝘰𝘯, 𝘛𝘦𝘤𝘩𝘯𝘰𝘭𝘰𝘨𝘺, 𝘏𝘦𝘢𝘭𝘵𝘩𝘤𝘢𝘳𝘦, 𝘢𝘯𝘥 𝘔𝘦𝘥𝘪𝘢

Similar Jobs

ServiceNow Logo ServiceNow

Staff Security Incident Response Commander_Hyderabad/Bangalore/Remote

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Hyderabad, Telangana, IND
29000 Employees

Micron Technology Logo Micron Technology

Soft Services Manager

Artificial Intelligence • Hardware • Information Technology • Machine Learning
Remote
Gujarat, IND
45000 Employees

Micron Technology Logo Micron Technology

Staff Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
Remote
Gujarat, IND
45000 Employees

Micron Technology Logo Micron Technology

Staff Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
Remote
Gujarat, IND
45000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account