Talent.com
Senior Product Security Engineer

Senior Product Security Engineer

ConfidentialNoida, India
4 days ago
Job description

Who We Are

Zinnia is the leading technology platform for accelerating life and annuities growth. With innovative enterprise solutions and data insights, Zinnia simplifies the experience of buying, selling, and administering insurance products. All of which enables more people to protect their financial futures. Our success is driven by a commitment to three core values : be bold, team up, deliver value – and that we do. Zinnia has over $180 billion in assets under administration, serves 100+ carrier clients, 2500 distributors and partners, and over 2 million policyholders.

Who You Are

As a Senior Security Engineer focusing on Product and Application Security, you will play a key role in ensuring the security of Zinnia's products and customer-facing applications. You will work closely with product engineering teams to integrate security into every phase of the software development lifecycle (SDLC), design secure architectures, and build scalable solutions that prevent and detect vulnerabilities.

You thrive at the intersection of engineering and security—comfortable diving into code reviews, designing security controls, building automation, and mentoring developers on secure coding practices. You are passionate about shifting security left, driving adoption of secure design principles, and building a program that enables developers to deliver secure products quickly and confidently.

What You'll Do

  • Partner with product engineering teams to embed security in the SDLC through threat modelling, design reviews, and secure architecture guidance.
  • Perform secure code reviews, static / dynamic analysis, and dependency scanning, ensuring vulnerabilities are identified and remediated early.
  • Build and maintain security automation and guardrails (CI / CD integrations, pipelines, and developer tools) to scale AppSec across teams.
  • Lead and evolve the threat modelling program, aligning security requirements with product architecture and risk profiles.
  • Collaborate with engineering teams to remediate vulnerabilities and implement secure coding practices.
  • Enhance the usage of SAST, DAST, SCA, and container scanning tools, and build custom automation where needed.
  • Conduct penetration testing of applications and APIs and track findings through remediation.
  • Contribute to and maintain secure coding standards, playbooks, and training for developers.
  • Stay ahead of emerging application security threats, libraries, and frameworks, and proactively recommend improvements.
  • Mentor engineers and contribute to the growth of the Product Security program.

What You'll Need

  • 7+ years of experience in application / product security, software engineering, or related security engineering roles.
  • Strong background in web application, API, and microservices security.
  • Solid knowledge of secure coding practices (Java, Python, Go, JavaScript / TypeScript preferred).
  • Hands-on experience with SAST, DAST, SCA, and container scanning tools (e.g., Semgrep, Checkmarx, Snyk, Burp Suite, OWASP ZAP).
  • Experience with CI / CD security automation and integrating security into pipelines.
  • Strong knowledge of OWASP Top 10, CWE, CAPEC, threat modelling, and secure design principles.
  • Familiarity with identity, authentication, and authorization protocols (OAuth2, OIDC, SAML, JWT).
  • Experience conducting manual and automated penetration testing of applications and APIs.
  • Strong written and verbal communication skills, with the ability to influence developers and non-security stakeholders.
  • A passion for mentoring and building developer-first security culture. Nice to Have (Preferred Qualifications)
  • Knowledge of cloud-native application security (Kubernetes, serverless, containers).
  • Certifications such as OSWE, OSCP, GWAPT, CSSLP, or GIAC AppSec certs.
  • Experience with bug bounty programs or contributing to open-source security projects
  • WHAT'S IN IT FOR YOU

    At Zinnia, you collaborate with smart, creative professionals who are dedicated to delivering cutting-edge technologies, deeper data insights, and enhanced services to transform how insurance is done. Visit our website at www.zinnia.com for more information. Apply by completing the online application on the careers section of our website. We are an Equal Opportunity employer committed to a diverse workforce. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability

    Skills Required

    DAST, Saml, Go, Typescript, Javascript, product security , Application Security, SAST, Python, Java, Oauth2, Jwt, Penetration Testing, SCA, Burp Suite, Owasp Top 10, Checkmarx

    Create a job alert for this search

    Senior Security Engineer • Noida, India

    Related jobs
    • Promoted
    Security Engineer

    Security Engineer

    InfogainDelhi, India
    Title : Security Engineer (6+ Years).Job Description : Use CrowdStrike reports to evaluate all security vulnerabilities on both Windows and Linux systems. Analyze the requirements to remediate the sec...Show moreLast updated: 14 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.aiGhaziabad, IN
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Threat Detection Engineer

    Sr Threat Detection Engineer

    Insight GlobalMeerut, IN
    Exact compensation may vary based on several factors, including skills, experience, and education.We are seeking a highly experienced Senior Detection Engineer to lead the development and optimizat...Show moreLast updated: 13 days ago
    • Promoted
    Contractor Security Engineer Level 3 – GRC Tech Solutions

    Contractor Security Engineer Level 3 – GRC Tech Solutions

    Mindlancemeerut, uttar pradesh, in
    Remote Role | Contractor Security Engineer Level 3 – GRC Tech Solutions.This position focuses on enabling process clarity, automation, and efficiency while creating insights that empower our busine...Show moreLast updated: 14 days ago
    • Promoted
    Senior Engineer II- Security [T500-21025]

    Senior Engineer II- Security [T500-21025]

    lululemonDelhi, India
    Setting the bar in technical fabrics and functional design, we create transformational products and experiences that support people in moving, growing, connecting, and being well.We owe our success...Show moreLast updated: 11 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Arcananoida, delhi, in
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show moreLast updated: 30+ days ago
    • Promoted
    Director Product – Building and Managing Security Products - Cyber Security Startup - Salary INR 75 L

    Director Product – Building and Managing Security Products - Cyber Security Startup - Salary INR 75 L

    CareerXperts Consultinggurgaon, haryana, in
    We are seeking a hands-on product leader to drive the strategy, design, and operational delivery of AI-driven threat investigation and response content at platform scale. This role is ideal for a fo...Show moreLast updated: 1 day ago
    • Promoted
    Product Security Engineer II

    Product Security Engineer II

    FICODelhi, India
    FICO (NYSE : FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential!.As a ...Show moreLast updated: 28 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    TAC SecurityDelhi, India
    As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies.Leveraging y...Show moreLast updated: 28 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Next Digital RecruitmentNoida, Republic Of India, IN
    Job Title : Cyber Security Engineer L1,L2,L3 and Team Leads.Design, deploy, and manage security architectures focusing on SSE, SASE, and Identity Management solutions. Operate and maintain security t...Show moreLast updated: 1 day ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    ConfidentialGurugram, Gurgaon / Gurugram, India
    You are an experienced, hands-on Application Security Engineer who's passionate about building secure products, automating security workflows, and influencing development teams to embed security in...Show moreLast updated: 4 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    CBTSfaridabad, haryana, in
    Senior level roles as IT Security Architect, IT Security Engineer, IT Security Auditor, Cyber-Security Analyst, Cyber-Intelligence Analyst. Certifications, Accreditations, Licenses.One or more of th...Show moreLast updated: 13 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    AtomicworkDelhi, India
    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwo...Show moreLast updated: 28 days ago
    • Promoted
    Product Security Engineer (I5)

    Product Security Engineer (I5)

    ConfidentialDelhi, Mumbai, Kolkata
    You will engage with the best and brightest engineers and architects as they build our future application and service capabilities, while ensuring our current generation solutions continue to deliv...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    ConfidentialDelhi NCR, Delhi
    Skilled Senior Security Engineer with expertise in LISA Assessment, application security, B2B / B2C commerce platforms, and vulnerability management. Known for strong analytical thinking, problem-solv...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Product Security Engineer [T500-20534]

    Senior Product Security Engineer [T500-20534]

    REA Cyber Citygurugram, India
    In 1995, in a garage in Melbourne, Australia, REA Group was born from a simple question : “Can we change the way the world experiences property?”. Fast forward 30 years, REA Group is a market leader ...Show moreLast updated: 14 hours ago
    • Promoted
    Zinnia - Senior Security Engineer - OWASP

    Zinnia - Senior Security Engineer - OWASP

    ZinniaNoida
    Who We Are : Zinnia is the leading technology platform for accelerating life and annuities growth.With innovative enterprise solutions and data insights, Zinnia simplifies the...Show moreLast updated: 21 days ago
    • Promoted
    Senior Lead Product Security Engineer

    Senior Lead Product Security Engineer

    ConfidentialGurgaon / Gurugram
    As a Senior Lead Product Security Engineer, you will be responsible for : .Building and executing engineering processes for early detection of design flaws, vulnerabilities, weaknesses, missing secur...Show moreLast updated: 30+ days ago