Role Overview
We are seeking a proactive and technically curious Security Engineer I to join our product security team. In this role, you will be on the front lines of defending our products, focusing heavily on Vulnerability Assessment and Penetration Testing (VAPT) across our web applications, mobile apps (iOS/Android), and backend APIs. A major component involves writing automation to streamline repetitive testing and operational tasks.
Responsibilities
- Conduct routine VAPT on web applications, REST/GraphQL APIs, and mobile applications (iOS and Android).
- Design, write, and maintain custom scripts and automation tools primarily in Python, Go, or Bash.
- Review alerts from SAST/DAST scanners, filter false positives, and manually validate vulnerabilities.
- Collaborate with engineering teams to provide remediation guidance based on the OWASP Top 10.
- Integrate and tune open-source and commercial security testing tools within deployment pipelines.
- Draft penetration testing reports detailing attack vectors and Proofs of Concept (PoCs).
Requirements
- 0–2 years of experience in application security, penetration testing, or software engineering.
- Hands-on understanding of OWASP Top 10 (Web and Mobile) and manual exploitation (XSS, SQLi, IDOR).
- Strong proficiency in Python, Go, Ruby, or Bash for automation.
- Familiarity with tools such as Burp Suite, OWASPZAP, Postman, Nmap, or MobSF.
- Solid understanding of HTTP/HTTPS, TCP/IP, DNS, and API architectures.
Skills
- Vulnerability Assessment and Penetration Testing (VAPT)
- Python
- OWASP Top 10
- Burp Suite
- API Security