Product Security Engineer
Job description
Product Security Engineer at Careers.
About the role
As a Product Security Engineer at Careers, you will play a crucial role in safeguarding our products and services from potential security threats. You will collaborate with cross-functional teams to identify vulnerabilities, implement security measures, and ensure compliance with industry standards. Your expertise will help us maintain the trust of our customers while enhancing the overall security posture of our offerings. This position is based in India and offers a dynamic work environment where innovation and security are at the forefront.
Key facts
What you'll do
- Conduct thorough security assessments of Careers's products and services to identify vulnerabilities and recommend appropriate remediation strategies.
- Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC), ensuring that security is a priority from the outset.
- Monitor and analyze security incidents, providing timely responses and implementing lessons learned to prevent future occurrences.
- Develop and maintain security policies, procedures, and guidelines that align with industry standards and regulatory requirements.
- Perform penetration testing and vulnerability assessments to evaluate the security of applications and systems, providing detailed reports and actionable insights.
- Work closely with the incident response team to investigate security breaches and develop strategies for mitigation and recovery.
- Stay current with emerging security threats, trends, and technologies, and provide recommendations for enhancing the security of Careers's products.
- Participate in security awareness training for employees to foster a culture of security and ensure that all staff understand their role in protecting company assets.
- Collaborate with third-party vendors to assess their security practices and ensure compliance with Careers's security standards.
- Assist in the development of security metrics and reporting mechanisms to track the effectiveness of security initiatives and communicate findings to stakeholders.
- Engage in code reviews to identify security flaws and suggest improvements to enhance the security of the codebase.
- Contribute to the continuous improvement of security tools and processes, leveraging automation where possible to enhance efficiency and effectiveness.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 3 years of experience in product security, application security, or a related discipline.
- Strong understanding of security principles, practices, and frameworks, including OWASP Top Ten, NIST, and ISO 27001.
- Proficiency in security testing tools such as Burp Suite, OWASP ZAP, or similar.
- Experience with programming languages such as Python, Java, or C++, and familiarity with secure coding practices.
- Knowledge of cloud security principles and experience with cloud platforms such as AWS, Azure, or Google Cloud.
- Excellent analytical and problem-solving skills, with the ability to think critically and make sound decisions under pressure.
- Strong communication skills, both verbal and written, with the ability to convey complex security concepts to technical and non-technical audiences.
- Proven ability to work collaboratively in a team-oriented environment and manage multiple priorities effectively.
Nice to have
- Relevant security certifications such as CISSP, CEH, or OSCP.
- Experience with DevSecOps practices and tools, including CI/CD pipelines.
- Familiarity with regulatory compliance frameworks such as GDPR, PCI-DSS, or HIPAA.
- Knowledge of threat modeling methodologies and risk assessment techniques.
- Experience in security architecture and design for large-scale systems.
Skills & tools
- Security assessment and testing tools (e.g., Burp Suite, Nessus)
- Programming languages (e.g., Python, Java, C++)
- Cloud platforms (e.g., AWS, Azure, Google Cloud)
- Security frameworks and standards (e.g., OWASP, NIST, ISO 27001)
- Incident response and forensics tools
Practical notes
- This position is based in India, and candidates must be eligible to work in the country.
- Careers offers competitive salaries and benefits, including opportunities for professional development and growth within the organization.
- The role may require occasional travel for training or conferences, depending on business needs.
- Candidates should be prepared to undergo background checks and security clearances as part of the hiring process.
Join Careers as a Product Security Engineer and be part of a team that is dedicated to protecting our customers and their online presence. If you are about security and eager to make a difference, we encourage you to apply today!