Talent.com
This job offer is not available in your country.
Application Security Engineer

Application Security Engineer

ZeptoBengaluru, Karnataka, India
30+ days ago
Job description

Job Description : Product Security Engineer

Team : Cybersecurity

Location : Bangalore, India

About Zepto

Zepto is revolutionizing e-commerce in India. As the country's fastest-growing quick-commerce company, we deliver groceries and essentials in 10 minutes flat. This speed is not just a promise; it's the result of a complex, high-throughput technology and operations backbone that operates at an unprecedented scale.

Our environment is defined by rapid innovation, immense scale, and the challenge of solving complex problems that have never been solved before. We are building the future of commerce, and we need brilliant minds to help us build it securely.

About the Team & The Role

The Cybersecurity team at Zepto is a core part of the engineering organization. Our mission is to secure our products, platforms, and customers by embedding security into the DNA of everything we build. We aren't just a compliance function or a team that finds vulnerabilities; we are builders and problem-solvers who create foundational security solutions that allow Zepto to scale safely.

We are looking for a Product Security Engineer who thinks like an engineer first and a security expert second. This is not a traditional pentesting role. You will not just be breaking things—you will be building the tools, systems, and processes to prevent them from breaking in the first place. You will be a trusted security partner to our product and engineering teams, shaping the future of our architecture and enabling developers to ship secure code at lightning speed.

What You’ll Do (Responsibilities)

As a Product Security Engineer, you will :

  • Design & Architect : Act as a security subject matter expert for engineering and product teams. Conduct in-depth architecture reviews, threat modeling, and design reviews for new features and services.
  • Automate Everything : Build and implement automated security solutions within our CI / CD pipelines (DevSecOps). You will be responsible for our SAST, DAST, SCA, and secret scanning infrastructure, focusing on reducing noise and providing actionable, high-fidelity alerts to developers.
  • Build Security Tooling : Identify gaps in our security posture and build custom tools and platforms to solve them. Whether it’s a framework for secure service-to-service communication or a platform for managing secrets, you will own the solution from concept to production.
  • Secure Code & Dependencies : Perform deep-dive manual and automated code reviews to identify complex security flaws. Drive our Software Composition Analysis (SCA) and secret management strategies, ensuring best practices are followed across the organization.
  • Lead Security Initiatives : Own and drive large-scale security initiatives across the company, such as implementing a new authentication service, rolling out a web application firewall, or hardening our cloud infrastructure.
  • Share Knowledge & Innovate : Mentor engineers on secure coding practices, write technical blog posts about the novel problems you're solving, present your work at conferences, and contribute back to the open-source community.

What We’re Looking For (Qualifications)

  • Engineering Mindset : A strong passion for solving complex problems with code. You are proficient in at least one programming language (e.g., Python, Go, Java, JavaScript) and are comfortable building security focused tools.
  • Deep Security Expertise : A solid understanding of application security (AppSec) fundamentals. You know the OWASP Top 10 like the back of your hand but, more importantly, you understand the underlying vulnerabilities and how to mitigate them at scale.
  • Hands-On Experience : Proven experience in areas like threat modeling, secure code review, and security automation. While you can perform a VAPT, you are more interested in automating the discovery and prevention of those vulnerabilities.
  • DevSecOps Acumen : Experience integrating security tools into CI / CD pipelines and a strong belief in shifting security left.
  • Excellent Communicator : You can clearly articulate complex security risks to both technical and non-technical audiences and can influence engineering teams without direct authority.
  • Ownership & Drive : A proactive and self-driven attitude. You don't wait for tasks; you identify problems and take ownership of the solutions.
  • Why Join Us?

  • Unparalleled Impact : Zepto is growing at an explosive rate. The solutions you build will have a direct and immediate impact on the security of millions of users and will be critical to the company's success.
  • Solve for Scale : The challenges we face are unique. You won't be applying off-the-shelf solutions; you will be building for a scale and speed that few companies can match.
  • Culture of Engineering : We are a tech-first company that values deep technical expertise. You will be surrounded by a world-class team of engineers to learn from and collaborate with.
  • Greenfield Opportunities : Our security function is young and growing. You will have the opportunity to build things from the ground up and shape the future of our security posture.
  • Growth & Learning : We encourage our team to be thought leaders. You'll have the support to write blogs, speak at events, and contribute to open-source projects that elevate both your and Zepto's reputation in the security community.
  • If you are an engineer who is passionate about security and wants to build resilient, scalable systems in a hyper-growth environment, we would love to hear from you.

    Create a job alert for this search

    Application Engineer • Bengaluru, Karnataka, India

    Related jobs
    Security Engineer I (Application Security)

    Security Engineer I (Application Security)

    coinswitchINDIA
    PeepalCo is a house for brands serving India with tailored wealth-tech products, Making Money Equal for All.Founded by Ashish Singhal, Govind Soni, and Vimal Sagar Tiwari, PeepalCos products includ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Application Security Engineer - Vulnerability Management

    Senior Application Security Engineer - Vulnerability Management

    Hire AlphaBangalore
    We are seeking a Senior Application Security Engineer with 67+ years of experience in application security, secure code review, and vulnerability management. The ideal candidate should have deep exp...Show moreLast updated: 8 days ago
    • Promoted
    Application Security Lead

    Application Security Lead

    Oak TitaniumBangalore, IN
    Job Title : Application Security Lead .We are a rapidly growing cybersecurity firm delivering advanced security solutions to enterprises across the Middle East, Europe, and the United States.Our mis...Show moreLast updated: 18 days ago
    Senior Lead Application Security Engineer

    Senior Lead Application Security Engineer

    BAKER HUGHESINDIA
    Lead Application Security Engineer.Would you like to innovate with the latest energy technology?.Do you enjoy being part of a successful team?. Join our Digital Technology team.We operate at the hea...Show moreLast updated: 30+ days ago
    Application Engineer

    Application Engineer

    ConcentrixBengaluru, Karnataka, India
    Total Years of experience : 5-10Yrs.An Application Engineer, good C++ & Linux Application development skillsets what we are looking for but perhaps even more important here is a experience in the pa...Show moreLast updated: 13 days ago
    Application Security Architect (AWS)

    Application Security Architect (AWS)

    ObjectwaysBengaluru, Karnataka, India
    Application Security Architect (AWS).Bangalore (Hybrid - 3days WFO).We are seeking an experienced and highly skilled Application Security Architect with deep expertise in AWS.The ideal candidate wi...Show moreLast updated: 13 days ago
    Senior Application Security Engineer I

    Senior Application Security Engineer I

    RSA SecurityBangalore, , IN
    Outseer Fraud Manager is an advanced, omnichannel fraud detection hub that provides risk-based, multi-factor authentication for organizations seeking to protect their consumers from fraud across di...Show moreLast updated: 17 days ago
    Application Security Engineer

    Application Security Engineer

    ZeptoBengaluru, Karnataka, India
    Job Description : Product Security Engineer.Zepto is revolutionizing e-commerce in India.As the country's fastest-growing quick-commerce company, we deliver groceries and essentials in 10 minutes fl...Show moreLast updated: 13 days ago
    Application Security Engineer

    Application Security Engineer

    Flexera Software India LLPBangalore
    Flexera saves customers billions of dollars in wasted technology spend.A pioneer in Hybrid ITAM and FinOps, Flexera provides award-winning, data-oriented SaaS solutions for technology value optimiz...Show moreLast updated: 18 days ago
    • Promoted
    Application Security Testing Engineer

    Application Security Testing Engineer

    Human HorizonBangalore
    Position : Application Security Testing Engineer Experience : 6 - 11 years Job Description : <...Show moreLast updated: 30+ days ago
    Security Engineer, Application Security

    Security Engineer, Application Security

    ADCI - KarnatakaBengaluru, Karnataka, IND
    In Amazon Stores, we ship some of the widest arrays of technology found at any company.Innovative digital healthcare to no-checkout retail, we push the boundaries of technology in every direction u...Show moreLast updated: 30+ days ago
    Application Security Engineer

    Application Security Engineer

    Arctic WolfBengaluru, IND
    Position Overview and Objective.The Application Security Engineer role is responsible for the implementation of.Arctic Wolf software systems, applications, code,. This role will work within our Info...Show moreLast updated: 1 day ago
    Application Security Engineer IV

    Application Security Engineer IV

    Condé NastMARKSQUARE, Bengaluru, IN
    Condé Nast is a global media company, home to iconic brands including Vogue, The New Yorker, GQ, Glamour, AD, Vanity Fair and Wired, among many others. The company's award-winning content reaches 84...Show moreLast updated: 2 days ago
    Application Security Lead Engineer

    Application Security Lead Engineer

    Anicalls (Pty) LtdBengaluru, India
    Create and manage bug bounty programs.Evangelize software security best practices.Perform threat modeling, architecture design reviews, and detection capabilities. Develop and implement security too...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    TELUS DigitalBangalore, IN
    We are a Digital Customer Experience organization, with a comprehensive coverage of IT Services from Traditional Services to Next Gen Digital Services. At TELUS Digital, we focus on lean, agile, hum...Show moreLast updated: 2 days ago
    Senior Application Security Engineer I

    Senior Application Security Engineer I

    RSA CareerBangalore, Karnataka, India
    Outseer Fraud Manageris an advanced omnichannel fraud detection hub that provides riskbased multifactor authentication for organizations seeking to protect their consumers from fraud across digital...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Application Security Engineer

    Lead Application Security Engineer

    Condé Nast Technology LabBengaluru, Karnataka, India
    Condé Nast is a global media company, home to iconic brands including Vogue, The New Yorker, GQ, Glamour, AD, Vanity Fair and Wired, among many others. The company's award-winning content reaches 84...Show moreLast updated: 2 days ago
    Application Security Engineer II

    Application Security Engineer II

    Zeta Services Inc.Bangalore
    It was founded by and Ramki Gaddipati in 2015.Our flagship processing platform - Zeta Tachyon - is the industry’s first modern, cloud-native, and fully API-enabled stack that brings together issuan...Show moreLast updated: 18 days ago
    Application security

    Application security

    NR Consulting - IndiaBangalore, Karnataka
    Vulnerability Assessment : Conduct regular vulnerability assessments to identify security weaknesses.Risk Evaluation : Evaluate the severity of vulnerabilities and prioritize remediation efforts base...Show moreLast updated: 30+ days ago
    Senior Application Security Specialist

    Senior Application Security Specialist

    [24]7.aiBengaluru, Karnataka, India
    Role : Senior Security Specialist.Summary of essential job functions.The overall responsibility of the team is to provide assurance to the management on the Information Security, Compliance and Risk...Show moreLast updated: 13 days ago