▷ (19/09/2025) Product Security Engineer

2 days ago


Bengaluru, India Traveloka Full time

Job Description

Product Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software architecture and should be able to perform manual security code review. They need to be able to integrate security in the software development process with defense-in-depth strategies such as automated testing in CI/CD pipeline. A Product Security Engineer preferably needs to have a software development background and should have practical programming knowledge.

They will work very closely with our Software Engineering Team to implement Secure SDLC in Traveloka. They will also need to have proficiency in handling multiple projects based on different frameworks and groups.

Responsibilities

- Carry out manual and automated review of source code to identify security vulnerabilities and risks
- Implement automated security testing tools (SAST, DAST, IAST) and their deployment within continuous integration systems
- Implement hardening and secure framework such as RASP, WAF, safe library, and security decorator functions
- Perform vulnerability assessment & penetration testing on web API, front-end service, internal RPC, and mobile application
- Attend design reviews and actively lead the discussions from a security standpoint
- Analyze possible security incident related to application security such as payment abuse or sensitive data exposure via web API
- Ensure that product security requirements are identified early on and are being baked into all projects
- Provide effective recommendations or patches to mitigate security vulnerabilities
- Develop in-house tools to integrate with SDLC and to track and derive security metrics

Skills & Experience

- Academic background in Computer Science or equivalent
- Relevant professional experience or extensive experience in security activities (e.g. CTF, bug bounty, security research, publications, blog)
- Practical knowledge of modern software development such as microservices, application containerization, REST architecture, object oriented programming, stateless/stateful authentication, and cloud platform
- Working knowledge of one or more of these programming languages: Java, JavaScript, Kotlin, C#, Objective-C, Swift
- Experience in security code review, vulnerability assessment, and penetration testing.
- Knowledge of common vulnerabilities such as OWASP Top 10 and CWE including business logic issue (e.g. IDOR)
- Core skill set in two or more of the following areas:
- JavaScript framework (e.g. React)
- Java framework (e.g. Spring)
- Android / iOS platform
- DevOps
- AWS
- Automation tool development
- Dynamic debugging
- Unit testing
- Algorithm & data structure

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us



  • Bengaluru, India Tata Consultancy Services Full time

    Direct Walk-In interview opportunity TCS Bangalore on Saturday, 30th Aug, 2025 Note: Candidates with relevant experience in Mortgage Servicing can directly attend Walk-in interview. Please go through Norms and Eligibility criteria. Job Role: Process Associate / Senior Process Associate Process: Mortgage Servicing Walk in Drive Date: Saturday, 30th...


  • Bengaluru, India Fortanix Full time

    Fortanix is a dynamic start-up solving some of the world's most demanding data protection challenges for companies and governments around the world. Our disruptive technology maintains data privacy across its entire lifecycle -- at rest, in motion, and in use across any enterprise IT infrastructure -- public cloud, on-premise, hybrid cloud, and SaaS. In...


  • Bengaluru, India Tata Technologies Full time

    Area of Responsibility - Lead the end-to-end hardware development of power electronics systems including BMS and battery management interfaces. - Define system hardware architecture and component specifications for high-voltage (400V–800V) battery systems. - Collaborate with cross-functional teams including mechanical, thermal, and systems engineering to...


  • Bengaluru, India Texas Instruments Full time

    Why IPP-MPP IPP-MPP product line offers high performance, innovative and cost-effective power solutions for a broad range of customer applications in enterprise, communications and automotive which include multiple phase DC/DC controllers, smart power stages, and sequencers. In MPP, our mission is to deliver the converter solutions which power large CPU,...


  • Bengaluru, India Palo Alto Networks Full time

    Our Mission At Palo Alto Networks® everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re...


  • Thiruvananthapuram / Trivandrum, Bengaluru, Chennai, India Tata Elxsi Limited Full time

    Job Description - Experience in threat analysis and risk assessment (TARA) and vulnerability analysis - Good understanding of cybersecurity requirements of automotive ECUs - Work experience in requirement management - Good experience in system requirements writing - Work experience with cybersecurity processes and automotive /rail standards like ISO 21434,...


  • Bengaluru, Karnataka, India Menlo Security Full time

    Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense. Menlo is well-funded for growth and our investors...

  • Engineer II

    2 days ago


    Bengaluru, India lululemon Full time

    Engineer II Shape Region: India State: Karnataka City: Bangalore Description & Requirements: Who We Are? We are proud to be a growing global company with locations all around the world, from Vancouver to Shanghai, and places in between. We owe our success to our innovative product, our emphasis on our stores, our commitment to our people, and the...


  • Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per year

    Job Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...


  • Bengaluru, India Winfort Full time

    We are seeking a Vice President – Engineering (Telecom - Roaming & Networks) for Software Engineering organization. Experience- 20+ years Location - Bangalore Key Responsibilities Strategic & Technical Leadership Technical Expertise in Roaming & Networks People & Operational Leadership Extensive experience in Core Network architecture and...