Talent.com
Senior Product Security Engineer
Senior Product Security EngineerConfidential • Noida, India
Senior Product Security Engineer

Senior Product Security Engineer

Confidential • Noida, India
28 days ago
Job description

Who We Are

Zinnia is the leading technology platform for accelerating life and annuities growth. With innovative enterprise solutions and data insights, Zinnia simplifies the experience of buying, selling, and administering insurance products. All of which enables more people to protect their financial futures. Our success is driven by a commitment to three core values : be bold, team up, deliver value – and that we do. Zinnia has over $180 billion in assets under administration, serves 100+ carrier clients, 2500 distributors and partners, and over 2 million policyholders.

Who You Are

As a Senior Security Engineer focusing on Product and Application Security, you will play a key role in ensuring the security of Zinnia's products and customer-facing applications. You will work closely with product engineering teams to integrate security into every phase of the software development lifecycle (SDLC), design secure architectures, and build scalable solutions that prevent and detect vulnerabilities.

You thrive at the intersection of engineering and security—comfortable diving into code reviews, designing security controls, building automation, and mentoring developers on secure coding practices. You are passionate about shifting security left, driving adoption of secure design principles, and building a program that enables developers to deliver secure products quickly and confidently.

What You'll Do

  • Partner with product engineering teams to embed security in the SDLC through threat modelling, design reviews, and secure architecture guidance.
  • Perform secure code reviews, static / dynamic analysis, and dependency scanning, ensuring vulnerabilities are identified and remediated early.
  • Build and maintain security automation and guardrails (CI / CD integrations, pipelines, and developer tools) to scale AppSec across teams.
  • Lead and evolve the threat modelling program, aligning security requirements with product architecture and risk profiles.
  • Collaborate with engineering teams to remediate vulnerabilities and implement secure coding practices.
  • Enhance the usage of SAST, DAST, SCA, and container scanning tools, and build custom automation where needed.
  • Conduct penetration testing of applications and APIs and track findings through remediation.
  • Contribute to and maintain secure coding standards, playbooks, and training for developers.
  • Stay ahead of emerging application security threats, libraries, and frameworks, and proactively recommend improvements.
  • Mentor engineers and contribute to the growth of the Product Security program.

What You'll Need

  • 7+ years of experience in application / product security, software engineering, or related security engineering roles.
  • Strong background in web application, API, and microservices security.
  • Solid knowledge of secure coding practices (Java, Python, Go, JavaScript / TypeScript preferred).
  • Hands-on experience with SAST, DAST, SCA, and container scanning tools (e.g., Semgrep, Checkmarx, Snyk, Burp Suite, OWASP ZAP).
  • Experience with CI / CD security automation and integrating security into pipelines.
  • Strong knowledge of OWASP Top 10, CWE, CAPEC, threat modelling, and secure design principles.
  • Familiarity with identity, authentication, and authorization protocols (OAuth2, OIDC, SAML, JWT).
  • Experience conducting manual and automated penetration testing of applications and APIs.
  • Strong written and verbal communication skills, with the ability to influence developers and non-security stakeholders.
  • A passion for mentoring and building developer-first security culture. Nice to Have (Preferred Qualifications)
  • Knowledge of cloud-native application security (Kubernetes, serverless, containers).
  • Certifications such as OSWE, OSCP, GWAPT, CSSLP, or GIAC AppSec certs.
  • Experience with bug bounty programs or contributing to open-source security projects
  • WHAT'S IN IT FOR YOU

    At Zinnia, you collaborate with smart, creative professionals who are dedicated to delivering cutting-edge technologies, deeper data insights, and enhanced services to transform how insurance is done. Visit our website at www.zinnia.com for more information. Apply by completing the online application on the careers section of our website. We are an Equal Opportunity employer committed to a diverse workforce. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability

    Skills Required

    DAST, Saml, Go, Typescript, Javascript, product security , Application Security, SAST, Python, Java, Oauth2, Jwt, Penetration Testing, SCA, Burp Suite, Owasp Top 10, Checkmarx

    Create a job alert for this search

    Senior Security Engineer • Noida, India

    Related jobs
    Senior Security Engineer

    Senior Security Engineer

    Deep Armor • Delhi, India
    We’re looking for a Senior Security Engineer to lead and support product security efforts for cloud-hosted web applications. You will be responsible for deep-tech product security design reviews, co...Show more
    Last updated: 21 days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.ai • Ghaziabad, IN
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Photon • Delhi, India
    Application Security Engineer (Senior Officer).Reporting to the Global Head of Security, the Application Security Engineer plays a crucial role in leading our Application Security program, ensuring...Show more
    Last updated: 3 days ago • Promoted
    Senior Firmware Engineer

    Senior Firmware Engineer

    Byteforge Systems • New Delhi, Delhi, India
    We are a startup product development firm that specializes in creating wearables, consumer electronics, and medical devices. Clients often approach us with unique challenges that require a creative ...Show more
    Last updated: 9 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Razorpay • Delhi, India
    Title : Senior Product Security Security Engineer The Role : .Razorpay is looking for a Senior Application Security Engineer with solid experience in AppSec fundamentals—secure code review, vulnerabil...Show more
    Last updated: 9 days ago • Promoted
    Senior Product Security Engineer [T500-20534]

    Senior Product Security Engineer [T500-20534]

    REA Cyber City • Delhi, India
    About REA Group : In 1995, in a garage in Melbourne, Australia, REA Group was born from a simple question : “Can we change the way the world experiences property?” Could we? Yes.Fast forward 30 years...Show more
    Last updated: 24 days ago • Promoted
    Product Security Engineer II

    Product Security Engineer II

    FICO • Delhi, India
    Join our world-class team today and fulfill your career potential!.The Opportunity "As a Product Security Engineer II in Cyber Security, you will be supporting security governance for a wide set of...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Security Engineer

    Senior Product Security Engineer

    Zinnia • Noida, Uttar Pradesh, India
    Zinnia is the leading technology platform for accelerating life and annuities growth.With innovative enterprise solutions and data insights Zinnia simplifies the experience of buying selling and ad...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    apna • Delhi, India
    Job Title : Senior Security Engineer (Sr.AI platforms, microservices, data pipelines and mobile / web products.You will design, build and automate scalable security controls that integrate seamlessly ...Show more
    Last updated: 17 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    First American (India) • Delhi, India
    The Senior Security Engineer will be responsible for designing and implementing the Database Activity Monitoring (DAM) function to ensure the security, integrity, and compliance of enterprise data ...Show more
    Last updated: 9 days ago • Promoted
    Senior Security Engineer - SIEM, DevSecOps, IPS / IDS

    Senior Security Engineer - SIEM, DevSecOps, IPS / IDS

    Emburse • Delhi, India
    Emburse software engineers contribute to the development of an engaging and interconnected set of system solutions.As an engineer, you will enhance the experiences of your customers, solve interest...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Security Engineer

    Senior Product Security Engineer

    EdgeVerve • Delhi, India
    Job Title : Senior Product Security Engineer.Perform security assessment, vulnerability assessments and penetration tests on a wide variety of high critical web applications.Perform DAST, analyze se...Show more
    Last updated: 1 day ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Sphera • Ghaziabad, IN
    Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability.Our mission is to create...Show more
    Last updated: 14 days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Arcana • Ghaziabad, IN
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Mobileum • Delhi, India
    Department : Engineering / Development / R&D.Reports To : DevSecOps Lead (Techno-Managerial).We are looking for a Senior Security Expert to drive AppSec practices, secure SDLC processes, and ISO 2700...Show more
    Last updated: 3 days ago • Promoted
    Product Security Engineer 5

    Product Security Engineer 5

    Confidential • Noida, India
    Changing the world through digital experiences is what Adobe's all about.We give everyone—from emerging artists to global brands—everything they need to design and deliver exceptional digital exper...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Bahwan CyberTek • Delhi, India
    Proficiency in Application Security, API, AI- Vulnerability Assessment / Penetration Testing, red teaming.Highly skilled and proficient in manual and automated testing using OWASP Top 10 for Web, API...Show more
    Last updated: 3 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    CBTS • Delhi, India
    Senior level roles as IT Security Architect, IT Security Engineer, IT Security Auditor, Cyber-Security Analyst, Cyber-Intelligence Analyst. Certifications, Accreditations, Licenses One or more of th...Show more
    Last updated: 30+ days ago • Promoted