Senior Product Security Engineer

5 days ago


Bengaluru, Karnataka, India Toast Full time ₹ 8,00,000 - ₹ 12,00,000 per year

Senior Product Security Engineer

Toast is driven by building the restaurant platform that helps restaurants adapt, take control, and get back to what they do best: building the businesses they love.

Product Security at Toast isn't just about running tools and reporting vulnerabilities we're the vigilant chefs ensuring the Toast never gets burned. We bake security into every layer of our products, from the first sprinkle of an idea to the final serving of a fully-baked solution. Our team is the secret ingredient that makes Toast's digital recipe both delicious and secure. We collaborate closely with R&D, seasoning the development process with robust security measures that protect the services and applications our customers rely on to run their businesses.

Like master chefs, we blend cutting-edge technology with strategic thinking, kneading security into the dough of every product we create. By joining our Product Security team, you'll be part of the kitchen crew that keeps our customers' trust from going stale. You'll tackle complex challenges that have real-world impact, helping to serve up a safer, more secure digital experience for businesses that count on Toast every day. It's not just about finding vulnerabilities it's about crafting a recipe for digital trust that keeps our customers coming back for more.

About this roll* (Responsibilities)

  • Identify, triage, and provide remediation guidance for application vulnerabilities.
  • Select, implement, design, or build tools to thwart attacks of all shapes and sizes.
  • Improve developer tooling and adoption to build a more robust SSDLC.
  • Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious. decisions when building new software.
  • Support and expand the Security Champions program, providing edge security guidance and training.
  • Assist incident response teams with application security expertise and tools.
  • Think like an attacker to identify weaknesses in application architecture.

In addition:

  • Support Cloud and Network Infrastructure Engineering's implementation of edge security solutions.
  • Influence the implementation and rule maintenance of our WAF strategy and other edge security solutions.
  • Advise on WAF rules and policies to protect against common and emerging threats.
  • Conduct regular assessments of our edge security posture and recommend improvements.
  • Provide expertise on Content Delivery Networks (CDNs) and their security features.

Do you have the right ingredients*? (Requirements)

  • 5+ years of experience in application security
  • Strong knowledge of common web application vulnerabilities and edge-based attack vectors.
  • Proficiency in analyzing web traffic patterns and identifying anomalies.
  • Knowledge of compliance standards relevant to the financial industry (e.g., PCI DSS, SOC 2).
  • Excellent problem-solving skills and ability to think creatively about edge security challenges.
  • Strong communication skills, with the ability to explain complex edge security concepts to both technical and non-technical audiences.
  • Strong understanding of cloud application architecture and common weaknesses.

Special Sauce* (Nonessential Skills/Nice to Haves)

Experience with:

  • Understanding of WAF configuration, tuning, and optimization.
  • Popular WAF solutions (e.g., AWS WAF, Cloudflare, Akamai, ModSecurity).
  • Familiarity with CDN technologies and their security features.
  • Cloud and container security technologies and SSDLC tooling (e.g. SAST/DAST/SCA)
  • Infrastructure-as-code (IaC) technologies like Terraform to manage cloud security services
  • Securing financial technologies
  • Relevant security certifications (e.g., CCSP, CISSP, CSSLP) are a plus


  • Bengaluru, Karnataka, India Cloud Software Group Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    The Senior product security engineer is responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness, as well as drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development...


  • Bengaluru, Karnataka, India Cloud Software Group Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    The Senior product security engineer is responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness, as well as drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development...


  • Bengaluru, Karnataka, India Atlassian Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    OverviewWorking at AtlassianAtlassians can choose where they work – whether in an office, from home, or a combination of the two. That way, Atlassians have more control over supporting their family, personal goals, and other priorities. We can hire people in any country where we have a legal entity. Interviews and onboarding are conducted virtually, a part...


  • Bengaluru, Karnataka, India Vimaan Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    Bangalore, IndiaPosted 2 years agoSenior Security EngineerVIMAAN is looking to hire a talented senior security engineer to join our exceptional engineering team developing the next generation of information systems for the warehouse. You will work with cross-functional teams, plan, and work on security threats identification, prevention and mitigation. You...


  • Bengaluru, Karnataka, India Skyhigh Security Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title:Senior Software Development Engineer - C | Linux Kernel | Networking | 5-8yAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness...


  • Bengaluru, Karnataka, India Procore Technologies Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Job Description We're looking for a Senior Security Engineer to join Procore's Security Engineering team. In this role, you'll be a senior member of the team, responsible for building and running the foundational security controls that protect our platform, data, and users. Your primary goal is to build and maintain a secure, scalable, and resilient cloud...


  • Bengaluru, Karnataka, India APNA Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title: Senior Security Engineer (Sr.SE )Location: Bengaluru Employment Type: Full-time Team: Security EngineeringRole OverviewAs a Senior Security Engineer, you will play a key role in strengthening the company's overall security posture across our AI platforms, microservices, data pipelines and mobile/web products. You will design, build and automate...


  • Bengaluru, Karnataka, India Apna Full time ₹ 10,00,000 - ₹ 25,00,000 per year

    Job Title: Senior Security Engineer (Sr.SE )Location: BengaluruEmployment Type: Full-timeTeam: Security Engineering Role OverviewAs a Senior Security Engineer, you will play a key role in strengthening the company's overall security posture across our AI platforms, microservices, data pipelines and mobile/web products. You will design, build and automate...


  • Bengaluru, Karnataka, India Apna Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title: Senior Security Engineer (Sr.SE )Location: BengaluruEmployment Type: Full-timeTeam: Security Engineering Role OverviewAs a Senior Security Engineer, you will play a key role in strengthening the company's overall security posture across our AI platforms, microservices, data pipelines and mobile/web products. You will design, build and automate...


  • Bengaluru, Karnataka, India Anlage Infotech Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Role OverviewWe are looking for a Senior Security Engineer with deep expertise in penetration testing,data security, endpoint security, DLP, compliance, data privacy, ethical hacking, andsecurity research.This role requires a hands-on security mindset, with experience in offensive & defensivesecurity, along with cutting-edge research in vulnerabilities, AI...