Product Security Engineer (Devsec Ops)

Posted 7 Days Ago
Be an Early Applicant
Gurugram, Haryana, IND
In-Office
Mid level
eCommerce • Information Technology
The Role
Perform application and product security assessments, threat modeling, and code reviews. Integrate SAST/DAST/SCA into CI/CD, improve cloud and infrastructure security, triage vulnerabilities and bug bounty reports, and guide secure design and coding practices across engineering and DevOps teams.
Summary Generated by Built In

We are looking for a Product Security Engineer with 3 to 5 years of hands-on experience in identifying, assessing, and mitigating security risks across our products and platforms. The ideal candidate will work closely with engineering, DevOps, and product teams to integrate security throughout the software development lifecycle (SDLC) and ensure the security of our applications and infrastructure.

Key Responsibilities

  • Conduct application security assessments, threat modeling, and code reviews for products and services.

  • Perform static (SAST), dynamic (DAST), and software composition (SCA) analysis using modern tools.

  • Collaborate with development teams to embed security controls in CI/CD pipelines.

  • Review and enhance security architecture for web, mobile, and API-based applications.

  • Work with DevOps teams to strengthen cloud security posture (AWS/GCP/Azure).

  • Investigate and respond to product security incidents and vulnerability reports.

  • Support bug bounty triage and coordinate fixes with engineering teams.

  • Document and enforce secure coding practices and security guidelines.

  • Participate in design and architecture reviews to ensure security-by-design principles.

  • 3 to 5 years of experience in Application Security or Product Security roles.

  • Strong knowledge of OWASP Top 10 Web, Mobile, API Security Top 10, and secure development practices.

  • Experience in Infrastructure security ( External and Internal)

  • Hands-on experience with tools like Burp Suite, ZAP, Check Marx, SonarQube, Veracode, GitLab Security, etc.

  • Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and integrating security scans.

  • Knowledge of cloud security (AWS, Azure, GCP) and exposure to IAM, KMS, and network controls.

  • Scripting knowledge (Python, Bash, or PowerShell) for automating security tasks.

  • Understanding of container and Kubernetes security concepts.

Good to Have

  • Experience with threat modeling (STRIDE, PASTA, etc.).

  • Familiarity with infrastructure as code (Terraform, CloudFormation) security validation.

  • Exposure to DevSecOps practices and security orchestration.

  • Certifications such as CEH, OSCP, CSSLP, or AWS Security Specialty are a plus.

Skills Required

  • 3 to 5 years of experience in Application Security or Product Security roles
  • Strong knowledge of OWASP Top 10 Web, Mobile, and API Security Top 10 and secure development practices
  • Experience in infrastructure security (external and internal)
  • Hands-on experience with tools such as Burp Suite, ZAP, Checkmarx, SonarQube, Veracode, GitLab Security
  • Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and integrating security scans
  • Knowledge of cloud security (AWS, Azure, GCP) and exposure to IAM, KMS, and network controls
  • Scripting knowledge (Python, Bash, or PowerShell) for automating security tasks
  • Understanding of container and Kubernetes security concepts
  • Experience with threat modeling (STRIDE, PASTA, etc.)
  • Familiarity with IaC security validation (Terraform, CloudFormation)
  • Exposure to DevSecOps practices and security orchestration
  • Certifications such as CEH, OSCP, CSSLP, or AWS Security Specialty
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Gurgaon
9,675 Employees
Year Founded: 2008

What We Do

Lenskart is Asia’s largest eyewear company serving 40 Million people - helping them see better and lead better quality lives. We have more than 1500 omnichannel stores across 175 cities in India, Singapore and Dubai. Our aim is to serve One Billion eyes by 2025 globally. And in this journey, we want to go beyond vision correction to transform the way people see and experience the world. That’s our new purpose - and we can only get there through cutting-edge technology and exceptional people.

Similar Jobs

Optum Logo Optum

Machine Learning Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Optum Logo Optum

Channel Specialist - Direct Marketing

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Optum Logo Optum

Consultant

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Capco Logo Capco

Liquidity Reporting

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Similar Companies Hiring

Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account