Talent.com
Product Security Engineer -III (Application Security)

Product Security Engineer -III (Application Security)

ConfidentialIndia
19 hours ago
Job description

What You'll Do

Avalara is seeking a Security Engineer to join our Application Security team. In this role you will be tasked with designing, implementing and deploying security engineering tooling for our code scanning and web scanning pipelines. You will help us scale the traditional application security mode of code auditing into automated pipelines to find security vulnerabilities such as XSS, SSRF, RCE, CSRF and SQLi across Avalara's code base. You will leverage your software skills and security knowledge to help uplift the security posture of our products and services. You will report into the Senior Manager of Application Security.

What Your Responsibilities Will Be

  • Design, build and deploy microservice-based automation leveraging manually discovered findings to scale automated scanning and vulnerability discovery efforts
  • Identify tooling gaps in static and dynamic scanning technologies and build out tooling to correct coverage and findings accuracy.
  • Provide security guidance and consultancy to engineering service owners to remediate known vulnerabilities. Build company-wide remediation burndowns plans.
  • Perform threat modelling, design, and code reviews on an as-needed basis to assess software security and service posture, to lead future product roadmaps and requirements.

What You'll Need To Be Successful

  • B.S. in Computer Science, Computer or Electrical Engineering, Mathematics or a related field.
  • Programming skills in at least one of Java, Go, Python, .NET.
  • Minimum of 5 years work in application security, with hands-on experience in SCA, SAST, DAST and related code scanning technologies.
  • Experience identifying, evaluation, and remediating application vulnerabilities including the OWASP Top-10 and / or CWE Top-25.
  • Experience with CI / CD build pipelines and AWS / GCP cloud provider IaC provisioning technologies.
  • Avalara is an AI-first Company

    AI is embedded in our workflows, decision-making, and products. Success here requires embracing AI as an essential capability.

  • You'll bring experience using AI and AI-related technologies, ready to thrive here.
  • You'll apply AI every day to business challenges - improving efficiency, contributing solutions, and driving results for your team, our company, and our customers.
  • You'll grow with AI by staying curious about new trends and best practices, and by sharing what you learn so others can benefit too.
  • How We'll Take Care Of You

    Total Rewards

    In addition to a great compensation package, paid time off, and paid parental leave, many Avalara employees are eligible for bonuses.

    Health & Wellness

    Benefits vary by location but generally include private medical, life, and disability insurance.

    Inclusive culture and diversity

    Avalara strongly supports diversity, equity, and inclusion, and is committed to integrating them into our business practices and our organizational culture. We also have a total of 8 employee-run resource groups, each with senior leadership and exec sponsorship.

    What You Need To Know About Avalara

    We're defining the relationship between tax and tech.

    We've already built an industry-leading cloud compliance platform, processing over 54 billion customer API calls and over 6.6 million tax returns a year. Our growth is real - we're a billion dollar business - and we're not slowing down until we've achieved our mission - to be part of every transaction in the world.

    We're bright, innovative, and disruptive, like the orange we love to wear. It captures our quirky spirit and optimistic mindset. It shows off the culture we've designed, that empowers our people to win. We've been different from day one. Join us, and your career will be too.

    We're An Equal Opportunity Employer

    Supporting diversity and inclusion is a cornerstone of our company — we don't want people to fit into our culture, but to enrich it. All qualified candidates will receive consideration for employment without regard to race, color, creed, religion, age, gender, national orientation, disability, sexual orientation, US Veteran status, or any other factor protected by law. If you require any reasonable adjustments during the recruitment process, please let us know.

    Skills Required

    DAST, Java, SCA, Gcp, .NET, SAST, Go, Python, Aws

    Create a job alert for this search

    Application Security Engineer • India

    Related jobs
    • Promoted
    Senior Product Security Engineer T500-20534

    Senior Product Security Engineer T500-20534

    REA Cyber CityRepublic Of India, IN
    In 1995, in a garage in Melbourne, Australia, REA Group was born from a simple question : “Can we change the way the world experiences property?”. Fast forward 30 years, REA Group is a market leader ...Show moreLast updated: 18 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    ConfidentialIndia
    At Twilio, we're shaping the future of communications, all from the comfort of our homes.We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers wo...Show moreLast updated: 22 days ago
    • Promoted
    ChargePoint - Staff Product Security Architect - Threat Modeling

    ChargePoint - Staff Product Security Architect - Threat Modeling

    ChargePointIndia
    Reports To : Senior Manager, Information Security.What You Will Be Doing : ChargePoint is looking for a Staff, Product Security Architect who will help develop our pr...Show moreLast updated: 30+ days ago
    • Promoted
    Strategy - Senior Application Security Engineer

    Strategy - Senior Application Security Engineer

    StrategyNagpur
    Job Description : Join Strategy's IT Security group as a Senior Application Security Engineer and play a crucial role in safeguarding Strategy's software application...Show moreLast updated: 2 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    ConfidentialIndia
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 22 days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    FoodsmartIndia, India
    Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians.Our platform is designed to foster healthier food choices, drive lasting behavior c...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.aiIndia, India
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    ITPeopleNetworkRepublic Of India, IN
    We are looking for a motivated.The role involves supporting the setup, integration, and daily operations of application security scanning within CI / CD pipelines. You will work closely with developme...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    Check Point SoftwareRepublic Of India, IN
    As the world’s leading vendor of Cyber Security, facing the most sophisticated threats and attacks, we’ve assembled a global team of the most driven, creative and innovative people.At Check Point, ...Show moreLast updated: 17 days ago
    • Promoted
    Software Security Architect – Qt & Chromium Platforms

    Software Security Architect – Qt & Chromium Platforms

    ConfidentialIndia
    We are looking for an experienced Software Security Architect with strong hands-on development skills to lead, guide and actively contribute to the remediation of security issues in Qt and Chromium...Show moreLast updated: 22 days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    ConfidentialNagpur
    Join Strategy s IT Security group as an Application Security Engineer and play a crucial role in safeguarding Strategy s software applications while using modern security and AI tooling.In this pos...Show moreLast updated: 30+ days ago
    • Promoted
    DevSecOps / AppSecOps Staff Engineer

    DevSecOps / AppSecOps Staff Engineer

    First American (India)nagpur, maharashtra, in
    Our people-first culture empowers bold thinkers and passionate technologists to solve real-world challenges through scalable architecture and innovative design. If you're driven by impact, thrive in...Show moreLast updated: 30+ days ago
    • Promoted
    Embedded Security Engineer

    Embedded Security Engineer

    ConfidentialIndia
    Lead and support product and information security for (IoT) products, apps, and cloud services.Security Architecture, product, Embedded Systems, IOT, app, and cloud security for complex systems,.Ex...Show moreLast updated: 22 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    ArcanaIndia, India
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show moreLast updated: 30+ days ago
    • Promoted
    Security (DevSecOps)and QA (Automation)

    Security (DevSecOps)and QA (Automation)

    PioVation GmbHIndia, India
    If you care about European-grade safety, quality, and compliance, read on.Senior Security Engineer (DevSecOps).Application & cloud security (threat modeling, secure SDLC).Kubernetes security (netwo...Show moreLast updated: 18 days ago
    • Promoted
    Security Engineer

    Security Engineer

    ConfidentialIndia
    MWIDM is a WMBE Certified global staffing firm serving Fortune 2000 clients with customized and scalable workforce solutions. Our approach integrates account management into our delivery process to ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    SpheraIndia, India
    Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability.Our mission is to create...Show moreLast updated: 8 days ago
    • Promoted
    • New!
    Lead Security Engineer

    Lead Security Engineer

    PINKVILLARepublic Of India, IN
    Pinkvilla is seeking a dynamic Information Security professional, who will contribute to strengthening our security posture by working closely with cross-functional teams, monitoring threats, secur...Show moreLast updated: 22 hours ago