About Parking Base
Parking Base is an innovative, cloud-based platform designed to streamline parking business operations. From real-time inventory management to reservation systems, payment processing, and enforcement, Parking Base offers comprehensive solutions. Our platform also includes customer and back-office management tools, as well as seamless integration capabilities with other systems. Trusted by hundreds of facilities and over 100,000 accounts, Parking Base helps businesses save time and money while enhancing customer satisfaction. Visit our website https://www.parkingbase.com/ to discover more about our offerings.
Job Description
We are looking for a Senior Application Security Engineer to own the security of the Parking Base platform at the source-code level. Parking Base is a multi-tenant SaaS platform that handles payment data and personally identifiable information, which places this role at the centre of how we protect our customers. You will audit our React front end and Java back end for vulnerabilities, drive remediation alongside the engineering teams, run and tune our SAST, DAST, and SCA tooling, lead threat modelling for new features, and embed security automation directly into our SDLC and CI/CD pipelines. This is a hands-on engineering role you will read and write production code, not only report findings.
Responsibilities
- Perform secure code reviews across the React / TypeScript front end and the Java Spring Boot back end, and remediate the issues you find rather than handing them off.
- Own and tune the application security toolchain SAST (SonarQube, Checkmarx), DAST, and SCA / dependency scanning (Snyk) keeping findings actionable and false-positive noise low.
- Lead threat modelling for new features and third-party integrations, identifying attack surface before code is written.
- Enforce server-side authorization as the security boundary, verifying that client-side gating is never relied upon for access control.
- Review data-access paths for injection risk, ensuring database queries use bound parameters rather than string concatenation.
- Assess outbound service calls for SSRF exposure, covering host allowlisting, redirect handling, and protection of internal network resources.
- Protect PII, payment, and tenant-scoped data end to end, maintaining strict tenant isolation and supporting PCI DSS compliance.
- Own secret hygiene across repositories and environments, including detection, rotation guidance, and preventing production credentials from reaching lower environments.
- Embed automated security gates into the CI/CD pipeline and the pull request review process so issues are caught before merge.
- Triage and drive remediation of vulnerabilities surfaced by scanners, penetration tests, and responsible disclosure reports.
- Partner with developers through code review, pairing, and internal training to raise the secure-coding baseline across the engineering team.
- Maintain security standards, documentation, and the evidence required for customer security reviews and compliance audits.
Qualifications
- 5+ years of software engineering experience, including at least 3 years focused on application security.
- Strong hands-on proficiency in Java and Spring Boot, together with working proficiency in React.js and TypeScript you must be able to read and modify production code in both.
- Demonstrated experience performing manual secure code review, not only interpreting scanner output.
- Practical experience with SAST, DAST, and SCA tooling such as SonarQube, Checkmarx, Snyk, or equivalents.
- Solid grounding in the OWASP Top 10 and OWASP ASVS, with real remediation experience across injection, broken access control, SSRF, and authentication flaws.
- Experience with threat modelling methodologies and secure design review.
- Familiarity with securing cloud-hosted, multi-tenant SaaS applications and container-based deployments (Docker, Kubernetes).
- Working knowledge of PCI DSS and of handling PII under modern data-protection expectations.
- Experience integrating automated security checks into CI/CD pipelines.
- Security certifications such as OSCP, GWAPT, CSSLP, or CEH are an advantage but not a requirement.
- Strong problem-solving skills, with the judgement to distinguish a theoretical finding from a genuinely exploitable risk.
- Excellent verbal and written communication skills in English, including the ability to explain risk to both engineers and non-technical stakeholders.
- Bachelor's degree or higher in Computer Science or a related field.
Benefits to Get Excited About
- Competitive salary package.
- Comprehensive health and wellness benefits.
- Opportunities for professional development and growth.
- Dynamic and collaborative work environment.
If you meet the qualifications and are excited about the opportunity to join our growing team, please share your resume to [email protected]
Pay: Up to ₹3,000,000.00 per year
Benefits:
- Health insurance
- Paid sick time
- Work from home
Application Question(s):
- Do you have hands-on experience performing manual secure code reviews, beyond reviewing findings generated by automated security scanners?
- Which application-security tools have you used hands-on?
- Have you configured or integrated SAST, DAST, or SCA security checks into CI/CD pipelines and/or pull-request workflows?
- Have you personally identified and/or remediated vulnerabilities involving broken access control, SQL/injection vulnerabilities, SSRF, or authentication/authorization flaws?
- What is your current Annual CTC? (eg. 15,00,000)
- What is your Expected Annual CTC? (eg. 15,00,000)
Experience:
- professional software engineering: 5 years (Required)
- hands-on Application Security / Product Security: 3 years (Required)
- hands-on Java and Spring Boot: 3 years (Required)
- React.js/TypeScript: 3 years (Required)
Work Location: Remote