
Product Security Engineer
4 weeks ago
Job Description
Product Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software architecture and should be able to perform manual security code review. They need to be able to integrate security in the software development process with defense-in-depth strategies such as automated testing in CI/CD pipeline. A Product Security Engineer preferably needs to have a software development background and should have practical programming knowledge.
They will work very closely with our Software Engineering Team to implement Secure SDLC in Traveloka. They will also need to have proficiency in handling multiple projects based on different frameworks and groups.
Responsibilities
- Carry out manual and automated review of source code to identify security vulnerabilities and risks
- Implement automated security testing tools (SAST, DAST, IAST) and their deployment within continuous integration systems
- Implement hardening and secure framework such as RASP, WAF, safe library, and security decorator functions
- Perform vulnerability assessment & penetration testing on web API, front-end service, internal RPC, and mobile application
- Attend design reviews and actively lead the discussions from a security standpoint
- Analyze possible security incident related to application security such as payment abuse or sensitive data exposure via web API
- Ensure that product security requirements are identified early on and are being baked into all projects
- Provide effective recommendations or patches to mitigate security vulnerabilities
- Develop in-house tools to integrate with SDLC and to track and derive security metrics
Skills & Experience
- Academic background in Computer Science or equivalent
- Relevant professional experience or extensive experience in security activities (e.g. CTF, bug bounty, security research, publications, blog)
- Practical knowledge of modern software development such as microservices, application containerization, REST architecture, object oriented programming, stateless/stateful authentication, and cloud platform
- Working knowledge of one or more of these programming languages: Java, JavaScript, Kotlin, C#, Objective-C, Swift
- Experience in security code review, vulnerability assessment, and penetration testing.
- Knowledge of common vulnerabilities such as OWASP Top 10 and CWE including business logic issue (e.g. IDOR)
- Core skill set in two or more of the following areas:
- JavaScript framework (e.g. React)
- Java framework (e.g. Spring)
- Android / iOS platform
- DevOps
- AWS
- Automation tool development
- Dynamic debugging
- Unit testing
- Algorithm & data structure
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us
-
Security Engineer II
2 weeks ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Security Engineer II
2 weeks ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 5,00,000 - ₹ 15,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Security Engineer II
2 weeks ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 6,00,000 - ₹ 18,00,000 per yearAt SAFE Security, our mission is bold and ambitious:We Will Build CyberAGI— a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Senior Security Engineer
1 week ago
Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per yearJob Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...
-
Product Security Engineer
2 days ago
Bengaluru, Karnataka, India GE Healthcare Private Limited Full time ₹ 12,00,000 - ₹ 36,00,000 per yearStaff Product Security Engineer Job Description SummaryAs a Staff Product Security Engineer, you will be part of the Ultrasound Digital team with the vision of building and sustaining product competencies and customer orientation to provide timely patient care. We are looking for a person with strong technical acumen in Cyber security in the cloud and...
-
Product Security Engineer
4 weeks ago
Bengaluru, Karnataka, India Avalara Technologies Full timeJob Description- You will engage with the best and brightest engineers and architects as they build our future application and service capabilities, while ensuring our current generation solutions continue to deliver the trust and reliability our customers expect.- If you want to make a big difference in a fast-moving environment without endless meetings, if...
-
Product Security Engineer
6 days ago
Bengaluru, Karnataka, India Cisco Full time ₹ 20,00,000 - ₹ 25,00,000 per yearWho We AreAs the leader in cloud-managed IT, Cisco connects passionate people to their mission by simplifying the digital workplace. Our impact is driven by the innovative, purposeful, and vibrant people who make up our inclusive community. When technology is intuitive, our customers can focus on what mattersAbout The TeamAs a member of the Device Trust...
-
Product Security Engineer
20 hours ago
Bengaluru, Karnataka, India, Karnataka Traveloka Full timeJob DescriptionProduct Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software...
-
Product Security Engineer
1 week ago
Bengaluru, Karnataka, India Sprinklr Full time ₹ 20,00,000 - ₹ 25,00,000 per yearSprinklr is a leading enterprise software company for all customer-facing functions. With advanced AI, Sprinklr's unified customer experience management (Unified-CXM) platform helps companies deliver human experiences to every customer, every time, across any modern channel. Headquartered in New York City with employees around the world, Sprinklr works with...
-
Senior Product Security Engineer
4 weeks ago
Bengaluru, Karnataka, India Pocket FM Full timeAbout Pocket FM Pocket FM is the world's largest audio entertainment platform, revolutionizing the way stories are told and consumed. We bring together storytelling, technology, and creativity to deliver an immersive and engaging experience through audio series, audiobooks, and podcasts. With over 150 million+ users , and billions of minutes streamed...