Product Security Specialist

2 days ago


Bengaluru, Karnataka, India Infosys Finacle Full time

About Infosys Finacle

We are a product subsidiary of Infosys, a global leader in next-generation digital services and consulting.

Our company, EdgeVerve, focuses on developing and delivering innovative software products that empower businesses to thrive in today's dynamic landscape.

As part of the EdgeVerve brand, we develop the industry-leading platform for digital banking solutions, trusted by financial institutions in over 84 countries.

In this role as a Product Security Engineer, you will play a vital role in ensuring the security of our cloud-native products.

You will oversee vulnerability assessments, penetration testing, and contribute to a secure development lifecycle (SDL) to safeguard our financial products from emerging threats.

Key Responsibilities:

  • Conduct comprehensive vulnerability assessments and penetration testing on critical financial web applications.
  • Leverage SAST and DAST tools to identify and analyze security vulnerabilities, recommending effective remediation strategies.
  • Perform security assessments of web services and APIs, focusing on identity and token authentication and authorization mechanisms.
  • Design and implement secure software systems, ensuring that security is an integral part of the software design process.
  • Collaborate with the development team to apply secure design principles and patterns.
  • Identify potential security vulnerabilities during the design phase and propose secure solutions.
  • Analyze and assess cryptography implementations, key management practices, and rotation procedures.
  • Deep dive into existing codebases to thoroughly assess security posture and identify potential vulnerabilities.
  • Collaborate with development teams to implement secure architecture and design principles throughout the SDL.
  • Maintain up-to-date knowledge of emerging threats like DDoS, ransomware, supply chain attacks, and implement countermeasures to mitigate risks.
  • Stay abreast of industry best practices, including OWASP Top 10, SANS Top 25, BDH, and Palo Alto advisories.
  • Ensure adherence to proper security postures and standard processes for both public and private cloud deployments.

Qualification

You should have

  • 10-15 years of experience in production/cloud security, with a focus on the financial domain and product security.
  • A thorough understanding of HTTPS, TLS 1.2, TLS 1.3, and public/symmetric key cryptography.
  • Proven experience in software design, with a focus on integrating security into the design process.
  • Experience with one or more of the following: Front-end technologies such as Angular, React, or JavaScript; Back-end technologies such as Java, Node.js, TypeScript, Spring, or C.
  • A strong understanding of secure design principles and patterns.
  • Experience identifying and addressing security vulnerabilities during the design phase.
  • Familiarity with security tools and screening/reporting experience is a plus, but the primary focus should be on software design experience.
  • Proficiency in security tools like Burp Suite, Nmap, ZAP, Black duck Hub, NVD/CVE/CWEs, and experience managing FOSS CVE tracking.
  • Experience in implementing secure coding practices aligned with OWASP Top 10, SANS Top 25, BDH, and Palo Alto advisories (a plus).
  • A solid understanding of secure deployments on public and private cloud platforms like AWS, Azure, GCP, OpenShift, and VMWare.
  • Bonus points if you have experience working within the financial services industry, experience with secure development methodologies (SDLC) and DevSecOps practices, and strong communication and collaboration skills.

Estimated Salary: ₹20,00,000 - ₹30,00,000 per annum

About Infosys Finacle

We are an equal opportunity employer, committed to embracing diversity and creating an inclusive environment for all employees.

All aspects of employment at Infosys Finacle are based on merit, competence, and performance.



  • Bengaluru, Karnataka, India Overture Rede Private Limited. Full time

    Product Security Specialist RoleAt Overture Rede Private Limited, we are seeking a highly skilled Product Security Specialist to join our team. As a Product Security Specialist, you will play a critical role in helping us provide product security consultation to application and product development teams and the Product Security Center of Excellence.Main...


  • Bengaluru, Karnataka, India Andromeda Security Full time

    Job Title: Data and Security SpecialistOverview:Andromeda Security is an early stage, top-tier Silicon Valley VC-funded multinational startup building a team in Bengaluru, India. You will have the opportunity to grow with the company and help secure enterprises from cloud security breaches. Job Responsibilities:We're looking for dreamers, coders, and hackers...


  • Bengaluru, Karnataka, India Cisco Full time

    At Cisco, we're committed to simplifying technology and empowering our customers to focus on what matters most. As a Product Security Specialist, you'll play a critical role in ensuring the security of our device firmware, built on Linux and open-source software.The Secure Development Lifecycle (SDL) is at the heart of our security strategy, and as a key...


  • Bengaluru, Karnataka, India Infoblox Full time

    Company OverviewInfoblox is a leading cybersecurity company that provides innovative solutions to protect against cyber threats. With a strong culture of innovation and a commitment to excellence, we are shaping the future of cybersecurity.SalaryWe offer a competitive salary ranging from $120,000 to $180,000 per year, depending on experience and...


  • Bengaluru, Karnataka, India SAP Full time

    Empowering Innovation through Secure SolutionsSAP is a global leader in enterprise software, and we're seeking a skilled Product Security Specialist to join our team. As a key member of our Security Patch Quality Assurance Team, you'll play a critical role in ensuring the security and integrity of our products.Key Responsibilities:Collaborate with...


  • Bengaluru, Karnataka, India SAP Full time

    About the RoleWe are seeking a highly skilled Product Security Specialist to join our team at SAP. As a key member of our Product Security Incident Response Team, you will play a critical role in managing coordinated disclosure of vulnerabilities on all SAP products and cloud solutions.Key ResponsibilitiesCombine technical expertise with experience in...


  • Bengaluru, Karnataka, India Cloud Software Group Full time

    The Senior Product Security Specialist will be responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure the software meets customer expectations of security robustness.Duties and ResponsibilitiesDevelop and implement SDL strategies to ensure product security and compliance.Lead a team of...


  • Bengaluru, Karnataka, India SAP Full time

    About the RoleWe are seeking a highly skilled Product Security Senior Specialist to join our SAP BTP Multi Cloud Delivery and DC Buildout Team. As a key member of our team, you will be responsible for defining cloud operations and ensuring the security of our customers' data.Key ResponsibilitiesDevelop technical requirements, architecture, design, and...


  • Bengaluru, Karnataka, India TIBCO Full time

    Secure Software Development Lifecycle LeadAs a Senior Product Security Specialist at TIBCO, you will be responsible for leading the Secure Software Development Lifecycle (SSDLC) for Cloud Software Group On-Prem and Cloud products. This involves ensuring that our software meets the customer expectation of security robustness. You will guide product...


  • Bengaluru, Karnataka, India SAP Full time

    About the RoleWe are seeking a highly skilled Product Security Specialist to join our team at SAP. The successful candidate will be responsible for managing vulnerabilities and ensuring the security of our products.Key ResponsibilitiesManage and coordinate vulnerability disclosure and remediation effortsCollaborate with development teams to implement...


  • Bengaluru, Karnataka, India VIBRANT STAFFING SOLUTIONS PVT LTD Full time

    ### Job Title: IT Security Compliance Specialist#### About the RoleWe are seeking an experienced IT Security Compliance Specialist to join our team at Vibrant Staffing Solutions PVT LTD. As an IT Security Compliance Specialist, you will be responsible for ensuring that our organization's IT systems and infrastructure comply with relevant regulatory...


  • Bengaluru, Karnataka, India Cloud Software Group Full time

    Job SummaryThe Senior Product Security Specialist will lead and execute the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness. This role will drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development...


  • Bengaluru, Karnataka, India SAP Full time

    Empowering Innovation through Secure AISAP is seeking a highly skilled Product Security Specialist to join our team. As a key member of our Security Patch Quality Assurance Team, you will play a critical role in ensuring the security of our products and services.Your Key Responsibilities:Collaborate with cross-functional teams to identify and mitigate...


  • Bengaluru, Karnataka, India SAP Full time

    We Help Businesses Thrive in a Secure EnvironmentAt SAP, we empower our customers to achieve their goals while maintaining a secure and reliable environment. Our team of experts focuses on building trust and confidence in our products and services, ensuring they meet the highest security standards.Your Key Responsibilities:Develop and present security...


  • Bengaluru, Karnataka, India SAP Full time

    About SAPSAP is a leading provider of enterprise software solutions, enabling businesses to run better and make a greater impact on the world.With over 400,000 customers worldwide, we offer a comprehensive portfolio of products and services that help organizations manage their operations, innovate, and grow.Job DescriptionWe are seeking an experienced Chief...


  • Bengaluru, Karnataka, India Cisco Full time

    About the Role:As a Product Security Engineer at Cisco Meraki, you will play a crucial part in ensuring the security of our device firmware. This is a unique opportunity to apply your knowledge of Linux and open-source software to create robust security solutions. Our team uses a Secure Development Lifecycle approach, and as a key member, you will contribute...


  • Bengaluru, Karnataka, India ADCI - Karnataka Full time

    Secure the Future of PaymentsAbout the RoleAmazon Security is seeking a highly skilled Cloud Security Specialist to secure the products and services developed by payments businesses at Amazon. As a Cloud Security Specialist, you will leverage your in-depth understanding of application and infrastructure security to conduct security assessments across the set...


  • Bengaluru, Karnataka, India Nilasu Consulting Services Pvt. Ltd. Full time

    Job Title: Network Security SpecialistDescription:Nilasu Consulting Services Pvt. Ltd. is seeking a highly skilled Network Security Specialist to join our team. As a Network Security Specialist, you will be responsible for designing, implementing and troubleshooting LAN, WAN, Wireless and security products and solutions. You will also be responsible for...


  • Bengaluru, Karnataka, India Imperva Full time

    Job Title: Technical Security SpecialistAt Imperva, we are seeking a highly skilled Technical Security Specialist to join our team. As a Technical Security Specialist, you will be responsible for working with enterprise customers to implement and support our security solutions. This role includes onboarding and support activities, as well as enhancing...


  • Bengaluru, Karnataka, India ADCI - Karnataka Full time

    Protect Our Cloud with Innovative Security SolutionsAbout the RoleWe are seeking a skilled Cloud Security Specialist to join our team at ADCI - Karnataka. As a Cloud Security Specialist, you will play a critical role in designing and implementing secure cloud-based systems that protect our customers' data and applications.Main ResponsibilitiesDesign and...