Gurgaon · Mid Level
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
HIGH
Lenskart is actively reviewing profiles and moving candidates through the pipeline right now.
First 72 hours
Window passed - posted 259d agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
We are looking for a Product Security Engineer with 3 to 5 years of hands-on experience in identifying, assessing, and mitigating security risks across our products and platforms. The ideal candidate will work closely with engineering, DevOps, and product teams to integrate security throughout the software development lifecycle (SDLC) and ensure the security of our applications and infrastructure.
Key Responsibilities
Conduct application security assessments, threat modeling, and code reviews for products and services.
Perform static (SAST), dynamic (DAST), and software composition (SCA) analysis using modern tools.
Collaborate with development teams to embed security controls in CI/CD pipelines.
Review and enhance security architecture for web, mobile, and API-based applications.
Work with DevOps teams to strengthen cloud security posture (AWS/GCP/Azure).
Investigate and respond to product security incidents and vulnerability reports.
Support bug bounty triage and coordinate fixes with engineering teams.
Document and enforce secure coding practices and security guidelines.
Participate in design and architecture reviews to ensure security-by-design principles.
3 to 5 years of experience in Application Security or Product Security roles.
Strong knowledge of OWASP Top 10 Web, Mobile, API Security Top 10, and secure development practices.
Experience in Infrastructure security ( External and Internal)
Hands-on experience with tools like Burp Suite, ZAP, Check Marx, SonarQube, Veracode, GitLab Security, etc.
Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and integrating security scans.
Knowledge of cloud security (AWS, Azure, GCP) and exposure to IAM, KMS, and network controls.
Scripting knowledge (Python, Bash, or PowerShell) for automating security tasks.
Understanding of container and Kubernetes security concepts.
Good to Have
Experience with threat modeling (STRIDE, PASTA, etc.).
Familiarity with infrastructure as code (Terraform, CloudFormation) security validation.
Exposure to DevSecOps practices and security orchestration.
Certifications such as CEH, OSCP, CSSLP, or AWS Security Specialty are a plus.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
More Security Engineer roles in Gurgaon
See allKeep browsing