Security Engineer - 3 (Appsec)
Responsibilities:
- Perform web and mobile application security assessments, vulnerability analysis, and penetration testing.
- Identify, validate, and remediate vulnerabilities across APIs, web applications, Android, and iOS platforms.
- Drive implementation of secure SDLC practices across engineering teams.
- Conduct code reviews, threat modeling, and security architecture assessments.
- Collaborate with developers to remediate security issues and improve application security posture.
- Perform security testing for APIs, authentication flows, session management, and business logic vulnerabilities.
- Integrate security tools and automation into CI/CD pipelines.
- Develop and maintain security standards, policies, and best practices for application security.
- Conduct root cause analysis for security incidents and recommend preventive measures.
- Stay updated on emerging threats, OWASP standards, and evolving attack vectors.
Requirements:
- 8+ years of experience in Application Security / Product Security.
- Strong expertise in Web and Mobile Application Security.
- Hands-on experience with penetration testing for web, API, Android, and iOS applications.
- Deep understanding of OWASP Top 10 Mobile, OWASP API Security, and secure coding practices.
- Experience with SAST, DAST, and mobile security testing tools.
- Strong knowledge of authentication, authorization, encryption, and session management.
- Familiarity with cloud-native and microservices-based architectures.
- Experience integrating security into CI/CD pipelines and DevSecOps workflows.
- Strong analytical, debugging, and communication skills.