Title : Senior Product Security Security Engineer
The Role :
Razorpay is looking for a Senior Application Security Engineer with solid experience in AppSec fundamentals—secure code review, vulnerability discovery, API security, and practical pentesting skills. The ideal candidate should also be able to perform basic threat modeling for new features and understand the emerging risks from AI-driven attack patterns.
Roles / Responsibilities :
- Perform application-level pentests across web, mobile, and backend services.
- Identify, validate, and help remediate vulnerabilities including OWASP Top 10, API Top 10, and logic flaws.
- Conduct security assessments for identity flows, API endpoints, microservices, and internal tools.
- Review code (manual + assisted) to detect common AppSec issues.
Application Security & Pentesting
Perform application-level pentests across web, mobile, and backend services.Identify, validate, and help remediate vulnerabilities including OWASP Top 10, API Top 10, and logic flaws.Conduct security assessments for identity flows, API endpoints, microservices, and internal tools.Review code (manual + assisted) to detect common AppSec issues.Threat Modeling (Basic)
Perform threat modeling for new features :Identify data-flow risksSpot common misconfigurationsHighlight authentication / authorization concernsDocument potential abuse cases and propose simple, actionable mitigations.AI / LLM Security (Introductory)
Understand the basics of AI-driven attack vectors : prompt manipulation, data leakage, misuse of LLM-based features.Flag potential AppSec risks in AI-assisted workflows or model integrations.Support teams in implementing simple guardrails around AI / LLM usage.Secure SDLC & Developer Productivity
Integrate AppSec checks into CI / CD pipelines—SAST, SCA, secrets scanning, basic DAST.Support engineering teams with secure coding guidance and easy-to-consume AppSec patterns.Help create developer-friendly standards, checklists, and best practices.Tooling & Automation
Write small scripts or utilities (Python / JS / Go) for repetitive security checks.Contribute to improving internal AppSec automation and dashboards.Requirements :
A Bachelor's degree in Computer Science, Cybersecurity, or a related field.A minimum of 5-8 years of experience in application security.Hands-on experience with offensive security practices and product security vulnerability management.Practical pentesting experience with tools like Burp Suite, ZAP, Postman, and custom scripts.Basic working knowledge of threat modeling techniques (STRIDE-lite, DFD-based reasoning, or simple checklist-based models).Familiarity with AI / LLM security basics (prompt injection, data leakage paths, output validation).Programming / scripting experience (Python / JS / Go preferred).Experience with AppSec tools in CI / CD.Location : Bangalore