Chennai, Tamil Nadu
Job Summary
We are looking for a Security Engineer to join our Product Security Engineering
team. This role sits at the intersection of application security, cloud
security, and security tooling — you will work hands-on to secure products,
build internal security solutions, and drive vulnerability management programs
across multiple product lines.
This is not a pure compliance or audit role. You will be expected to think like
an attacker, build like an engineer, and communicate like a consultant.
Key Responsibilities
Secrets Management & Security Tooling
-
- Drive adoption and operationalization of enterprise secrets management
solutions (e.g., HashiCorp Vault, credential managers)
- Design and implement secure credential distribution workflows for CI/CD
pipelines (Jenkins, GitLab, container registries)
- Build and maintain internal security tools and automation that serve
engineering teams at scale
- Evaluate, compare, and recommend security tools based on organizational needs
- Integrate authentication and access control (SSO, RBAC, Okta) into internal
security platforms
Vulnerability Management & Triage
-
- Manage and triage vulnerability findings from SAST tools (Coverity),
container scanners (Trivy, Wiz), DAST, and AI-driven discovery tools
- Prioritize vulnerabilities based on exploitability, attack surface, CVSS
analysis, and business context — not just severity scores
- Perform false positive analysis with source code evidence and contextual
understanding
- Build automation for vulnerability classification, prioritization, and
ticket management
- Track remediation progress across engineering teams and drive closure of
high-priority findings
Penetration Testing Support & Security Reviews
-
- Coordinate with external penetration testing teams — define scope, share
relevant findings, review interim and final reports
- Validate reported findings for real-world exploitability and accurate
severity ratings
- Challenge and negotiate CVSS scores with evidence-based reasoning
- Perform security group reviews, network segmentation analysis, and
infrastructure security assessments
- Review and assess debug API exposure, access control gaps, and input
validation weaknesses
Cloud Security
-
- Assess and improve security posture of cloud environments (AWS, Azure, GCP)
- Work with cloud security platforms (Wiz, CyCognito, MS Defender) for
vulnerability discovery and posture management
- Perform subscription ownership mapping, security group analysis, and
network architecture reviews
- Support cloud migration security readiness assessments
Security Program Contributions
-
- Contribute to security programs including: Threat Modeling, SAST/DAST
integration, Secure CI/CD, Infrastructure Security, and XSS Management
- Participate in CVE analysis and impact assessment for zero-day and emerging
vulnerabilities
- Support PCI DSS, SOC2, and other compliance activities as they intersect
with engineering
- Create and present security solutions and findings to engineering leadership
Skill Requirements
Must Have:
-
- 6+ years in application security, product security, or security engineering
- Hands-on experience with at least one secrets management tool (HashiCorp
Vault, CyberArk, AWS Secrets Manager, or similar)
- Experience with vulnerability management — SAST/DAST/SCA tool findings
triage, prioritization, and remediation tracking
- Understanding of CI/CD pipelines and how to secure them (Jenkins, GitLab CI,
GitHub Actions)
- Familiarity with cloud platforms (AWS/Azure/GCP) and cloud-native security
tools
- Scripting/automation skills (Python, PowerShell, or Bash) for building
security workflows
- Strong understanding of OWASP Top 10, CWE, CVE, and CVSS scoring
- Ability to read and understand code (Java, Python, Go) for vulnerability
validation
Good to Have:
-
- Experience coordinating or participating in penetration tests
- Familiarity with Coverity, Black Duck, Trivy, or similar SAST/SCA tools
- Experience with Wiz, CyCognito, or similar CSPM platforms
- Understanding of network security concepts (security groups, VPCs,
segmentation, boundary protection)
- Experience with SSO/IAM integration (Okta, LDAP, SAML)
- Exposure to compliance frameworks (PCI DSS, SOC2, NIST)
- Experience with Jira-based security defect management workflows
- Familiarity with AI/LLM security concepts is a plus
Other Requirements
- You can take a security tool from evaluation to production rollout with
minimal hand-holding
- You can look at a vulnerability finding and determine its real-world
exploitability
- You can build automation that saves the team hours of manual triage work
- You can review a pentest report and push back on inaccurate severity with
technical evidence
- You can explain a security risk to an engineering director in 2 minutes and
to a developer in 10 minutes with full technical detail
- You take ownership of problems end-to-end, from discovery to remediation
validation
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-