Security Engineer-2
Bellandur, Karnataka, India
Full Time
19 hours ago
Mid LevelEngineering
$40K - $80K

USD per year

Job Description

Security Engineer-2

Job type: Full Time Department: Engineering Work type: On-Site Location: Bellandur, Karnataka, India

Responsibilities:

  • Examine the products in detail to discover vulnerabilities and collaborate with other security engineers to demonstrate exploitability and risk factors.
  • Stay updated on emerging vulnerabilities/threats affecting Cashfree products through independent research.
  • Engage with developers to develop and implement workarounds/mitigation plans per policy.
  • Conduct secure design reviews/threat modeling exercises with development teams.
  • Conduct focused workshops on threat modeling for developers.
  • Prioritize critical defects and ensure mitigation during sprints.
  • Integrate and automate SAST in the DevOps pipeline.
  • Promote secure coding principles across the development community.
  • Serve as a go-to person for developers on secure product development issues.
  • Build and enhance secure coding/security assessment training content for developers and QA teams.
  • Deliver training programs at various organizational levels.
  • Conduct workshops/security tech-talks to disseminate security knowledge.

Qualifications:

  • Good knowledge of multiple classes of vulnerabilities including cross-site scripting, SQL Injection, CSRF, cryptographic weaknesses, and code injection.
  • Proficiency in programming/scripting languages such as Java, Ruby, Python.
  • Knowledge of cloud-related services/technology.
  • Ability to automate security testing and improve productivity in security assessments.
  • Ability to communicate security vulnerabilities effectively to development and management teams.

Requirements:

  • Great interpersonal skills, deep technical ability, successful execution history in assessments industry.
  • Familiarity with industry-standard threat modeling, risk modeling, vulnerability classification.
  • Experience with pre-assessment architectural and API analysis for white-box and grey-box assessments.
  • Experience working with engineering organizations, S-SDLC/CICD lifecycle, QA processes.
  • B. Tech. in Computer Science, Electrical or Computer Engineering or equivalent experience as software engineer or security practitioner.
  • 3+ years relevant engineering or security assessment experience; application security experience preferred.
  • Broad knowledge of attack vectors, exploits, mitigations at scale or chained attacks.
  • Experience with Java, Go, Python or Node.js (bonus for multiple).
  • Experience assessing Cloud-native services, service meshes, Kubernetes-platform-based micro-services.
  • Ability to apply unconventional thinking and problem-solve beyond current knowledge base; learn new technologies/languages as needed for pen-test tasks.
  • Ability to think offensively (like a hacker) and defensively (product security/design evaluation).
How to Apply
About Cashfree

Cashfree Payments enables 1 Million+ growing businesses in India and across the globe to collect payments, make payouts, manage international payments, and more. Cashfree Payments is backed by SBI, Y Combinator, Krafton, and Apis partners and was incubated by PayPal. It is an RBI Authorised Payment Aggregator License holder and RBI Authorised Prepaid Payment Instrument (PPI) Provider.

View Company Profile