×
Register Here to Apply for Jobs or Post Jobs. X

Senior Product Security Engineer

Job in Bengaluru, 560001, Bangalore, Karnataka, India
Listing for: enableIT
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations, IT Consultant
Job Description & How to Apply Below
Location: Bengaluru

Senior Product Security Engineer

Experience:

10–12+ Years

Employment Type:

Contract / Full-Time

Location:

Bangalore (Hybrid)
Industry:  Fin Tech / Financial Services

Job Summary:

We are seeking an experienced  Senior Product Security Engineer  to help strengthen the security of our products and services throughout the entire software development lifecycle. This role will play a critical hands-on role in defining and implementing product security strategies, embedding security into engineering and product development processes, and protecting customer data.
The ideal candidate will have strong expertise in  application security, product security, cloud security, secure SDLC, Dev Sec Ops , vulnerability management, and security automation , with proven experience working closely with engineering, product, and platform teams.

Key Responsibilities:

Support the development and execution of a comprehensive  Product Security strategy  aligned with business objectives, security requirements, and organizational risk appetite.
Partner with Engineering and Product teams to foster a strong  security-first culture  and promote security ownership across the organization.
Integrate security best practices, automated security controls, and tooling throughout the  Software Development Lifecycle (SDLC) .
Perform and support  security architecture reviews, threat modeling, vulnerability assessments, and secure design reviews .
Establish and enforce secure development standards covering  API security, secure coding, infrastructure-as-code (IaC), application architecture, and cloud environments .
Lead and manage application security programs covering  SAST, DAST, IAST, SCA, vulnerability management, and manual penetration testing .
Implement and manage product security tooling across web and mobile applications, including  API security, mobile application protection, runtime security, and application scanning .
Partner closely with Engineering, Product, Dev Ops, Cloud, and Platform teams to identify, prioritize, track, and remediate security vulnerabilities.
Develop and improve security automation within  CI/CD pipelines  to identify and prevent vulnerabilities earlier in the development lifecycle.
Establish and maintain processes for  product security incident response , vulnerability disclosure, investigation, remediation, and post-incident improvements.
Work with engineering and product teams to enhance application security features and security controls.
Evaluate emerging threats, vulnerabilities, attack techniques, and security technologies and continuously improve product security controls.
Provide security guidance to developers and engineering teams on secure coding, application architecture, APIs, cloud security, and vulnerability remediation.
Communicate security risks and recommendations effectively to both technical and non-technical stakeholders.

Required Qualifications:

10–12+ years of experience  in Product Security, Application Security, Application Security Engineering, Dev Sec Ops , or a closely related security engineering role.
Deep technical knowledge of  web and mobile application security  and common vulnerabilities, including the  OWASP Top 10 .
Strong understanding of  secure software development practices  and secure SDLC methodologies.
Hands-on experience implementing and managing  Product Security and Application Security tools .
Strong experience with  SAST, DAST, IAST, SCA, vulnerability scanning, and penetration testing .
Strong understanding of  API security , including authentication, authorization, API vulnerabilities, and API security testing.
Strong understanding of  CI/CD pipelines  and integrating security tools and controls into Dev Ops workflows.
Hands-on experience with security automation and  Dev Sec Ops  practices .
Experience securing  mobile applications  and implementing mobile application protection/security controls.
Strong understanding of  AWS cloud security principles and services .

Experience with  Infrastructure as Code (IaC) security  and cloud-native application security.
Experience conducting  threat modeling, security assessments, architecture reviews, and vulnerability remediation .
Strong ability to collaborate with Engineering, Product, Platform, and Dev Ops teams.
Excellent written and verbal communication skills with the ability to explain complex security concepts to technical and non-technical audiences.
Ability to operate effectively in a  fast-paced, highly collaborative environment .
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary