Application & Product Security Lead

Bengaluru, Karnataka, India | Security | Full-time

Apply

MoEngage is an insights-led customer engagement platform trusted by 1,350+ global consumer brands, including McAfee, Flipkart, Domino’s, Nestle, Deutsche Telekom, and OYO. MoEngage combines data from multiple sources to help brands gain a 360-degree view of their customers.  

MoEngage Analytics arms marketers and product owners with insights into customer behavior. Brands can leverage MoEngage Personalize to orchestrate journeys and build 1:1 conversations across the website, mobile, email, social, and messaging channels. MoEngage Inform, the transactional messaging infrastructure, helps unify promotional and transactional communication to a single platform for better insights and lower costs. MoEngage’s AI Suite helps marketers develop winning copies and creatives, optimize campaigns and channels that boost engagement, and help with faster execution.

For over a decade, consumer brands in 60+ countries have been using MoEngage to power digital experiences for over a billion monthly customers. With offices in 15 countries, MoEngage is backed by Goldman Sachs Asset Management, B Capital, Steadview Capital, Multiples Private Equity, Eight Roads, F-Prime Capital, Matrix Partners, Ventureast, and Helion Ventures.

MoEngage was named a Contender in The Forrester Wave™: Real-Time Interaction Management, Q1 2024 report, and Strong Performer in The Forrester Wave™ 2023 report. MoEngage was also featured as a Leader in the IDC MarketScape: Worldwide Omni-Channel Marketing Platforms for B2C Enterprises 2023.

Key Skills: Product Security, Application Security Testing, Secure SDLC, Secure code review, Application Security, Threat Modeling, OWASP Top10 , Years of Experience: 5-8 years
Does this sound like you?

You enjoy solving challenging technical problems.

  • You have an experience that shows breadth and depth of security knowledge. You

    are strong in multiple domains of software security.

  • You know how to work as a partner with product teams and give them the advantage

    of your security experience.

  • You recognize, adopt, use, and recommend best practices in security engineering.

  • You work ceaselessly to improve your knowledge of the security threat landscape and

    of technologies that enable new forms of attack and defense.

  • You are an effective communicator who engages well with technical and

    non-technical audiences alike.

    Skills that you would need:

  • Ability to implement and drive information and data security initiatives for MoEngage SaaS Application.

  • Understanding of security by design principles and architecture level security concepts and ability to promote secure design principles and a security-focused outlook across a large organization.

  • Exposure to multiple security engineering disciplines such as application security, secure software development, cryptography, network security, system security, and security policy.

  • Deep knowledge of common software vulnerabilities, such as OWASP Top 10 and CWE/SANS Top 25

  • The desire to solve security challenges at scale, and work on securing the next generation of applications powering the most sophisticated customer engagement platform ever built.

  • Experience in providing practical solutions that enable product and architecture teams to meet business goals while controlling security risk.

  • Ability to solve problems at their root and step back to understand the broader context.

  • Deep understanding of the interplay between attack and defense. Familiarity with current network security and application security tools and how to apply them.

  • Good understanding of information security policies, practices, and standards.

As a Security Lead, you will:

  • Drive various application security initiatives to perform end-to-end security reviews to ensure critical information is appropriately protected. Identify security vulnerabilities and risks, and develop mitigation plans.

  • Provide security architecture and design consultations to product teams, to help them build applications that are secure from the start.

  • Promote secure design principles and a security-focused outlook across a large organization.

  • Evaluate and recommend new and emerging security technologies for use inside and outside the security organization.

  • Produce creative and inventive solutions for large problems. Participate in projects that develop new intellectual property.

  • Be an advocate for customer trust.

  • Perform regular VA/PT for web, API and SDK

  • Identify process gaps in our application security pentesting and vulnerability

    Management.

  • Own and implement recommendations and fixes.

    Requirements:

  • Bachelor's degree in computer science, computer engineering.

  • 5 to 8 years of experience in the application security domain.

  • Detailed technical knowledge and conceptual understanding of Application Security

    Concepts, tools and practices.

  • Exposure of medium to advanced level of hands on implementation of SAST, SCA

    tools

  • Good to have experience in Secure Code Assessment, Dynamic Assessment,

    Software Composition Analysis and risk identification.

  • Good to have experience in security vulnerability assessments and remediation

    techniques.

  • Thorough understanding of OWASP Top 10, their attack & defense mechanisms

    (XSS, SQLi, CSP, CORS, SSRF)

  • Understanding of different AuthN/AuthZ frameworks ( oAuth, SAML)

  • Should be familiar with common tools (Postman, Burpsuite, etc )