Ready to apply? Sign up free to apply for jobs, save favorites, and track your applications!
$40K - $80K
USD per year
Job Description
Security Engineer-2
Job type: Full Time Department: Engineering Work type: On-Site Location: Bellandur, Karnataka, India
Responsibilities:
- Examine the products in detail to discover vulnerabilities and collaborate with other security engineers to demonstrate exploitability and risk factors.
- Stay updated on emerging vulnerabilities/threats affecting Cashfree products through independent research.
- Engage with developers to develop and implement workarounds/mitigation plans per policy.
- Conduct secure design reviews/threat modeling exercises with development teams.
- Conduct focused workshops on threat modeling for developers.
- Prioritize critical defects and ensure mitigation during sprints.
- Integrate and automate SAST in the DevOps pipeline.
- Promote secure coding principles across the development community.
- Serve as a go-to person for developers on secure product development issues.
- Build and enhance secure coding/security assessment training content for developers and QA teams.
- Deliver training programs at various organizational levels.
- Conduct workshops/security tech-talks to disseminate security knowledge.
Qualifications:
- Good knowledge of multiple classes of vulnerabilities including cross-site scripting, SQL Injection, CSRF, cryptographic weaknesses, and code injection.
- Proficiency in programming/scripting languages such as Java, Ruby, Python.
- Knowledge of cloud-related services/technology.
- Ability to automate security testing and improve productivity in security assessments.
- Ability to communicate security vulnerabilities effectively to development and management teams.
Requirements:
- Great interpersonal skills, deep technical ability, successful execution history in assessments industry.
- Familiarity with industry-standard threat modeling, risk modeling, vulnerability classification.
- Experience with pre-assessment architectural and API analysis for white-box and grey-box assessments.
- Experience working with engineering organizations, S-SDLC/CICD lifecycle, QA processes.
- B. Tech. in Computer Science, Electrical or Computer Engineering or equivalent experience as software engineer or security practitioner.
- 3+ years relevant engineering or security assessment experience; application security experience preferred.
- Broad knowledge of attack vectors, exploits, mitigations at scale or chained attacks.
- Experience with Java, Go, Python or Node.js (bonus for multiple).
- Experience assessing Cloud-native services, service meshes, Kubernetes-platform-based micro-services.
- Ability to apply unconventional thinking and problem-solve beyond current knowledge base; learn new technologies/languages as needed for pen-test tasks.
- Ability to think offensively (like a hacker) and defensively (product security/design evaluation).
How to Apply
About Cashfree
Cashfree Payments enables 1 Million+ growing businesses in India and across the globe to collect payments, make payouts, manage international payments, and more. Cashfree Payments is backed by SBI, Y Combinator, Krafton, and Apis partners and was incubated by PayPal. It is an RBI Authorised Payment Aggregator License holder and RBI Authorised Prepaid Payment Instrument (PPI) Provider.
View Company Profile