Meesho
About this role
This is product security at Meesho, and the scope is the whole secure development lifecycle rather
than one slice of it. You sit in from the start, running threat modelling and design reviews to catch
risk early, then wire SAST tooling into the CI/CD pipeline so testing continues as code changes. You
also lead vulnerability assessment and penetration testing across web applications, APIs and both iOS
and Android apps, do manual source code review, and run a self managed bug bounty programme. There is
a WAF to operate and a Security Champions programme to keep the wider engineering org engaged. The
stack around it is Git, Jenkins and Artifactory with Docker and containers. Apply if you are an
application security engineer who wants breadth: offensive testing, tooling and architecture guidance
in one seat.
than one slice of it. You sit in from the start, running threat modelling and design reviews to catch
risk early, then wire SAST tooling into the CI/CD pipeline so testing continues as code changes. You
also lead vulnerability assessment and penetration testing across web applications, APIs and both iOS
and Android apps, do manual source code review, and run a self managed bug bounty programme. There is
a WAF to operate and a Security Champions programme to keep the wider engineering org engaged. The
stack around it is Git, Jenkins and Artifactory with Docker and containers. Apply if you are an
application security engineer who wants breadth: offensive testing, tooling and architecture guidance
in one seat.
Who this is for
Requirements. 7+ years of experience in product security with a focus on application security and
DevSecOps. Proven experience leading architectural changes or cross team efforts to mitigate security
vulnerabilities. Hands-on experience with manual source code reviews and securing production code.
Experience with Git, Jenkins, Artifactory or similar. Experience with Docker and containerisation is
highly desirable.
What you would do. Lead and manage all aspects of the Secure Software Development Lifecycle. Implement
and manage security tools within the CI/CD pipeline (DevSecOps). Conduct and oversee VAPT for web
applications, APIs, iOS and Android apps. Perform threat modelling, design and architecture reviews.
Execute manual source code reviews and improve security in production. Manage and optimise a self
managed bug bounty programme. Provide security architectural guidance to engineering and IT teams.
Manage issues found through penetration tests and the bug bounty. Lead security training and
awareness across the organisation. Manage Web Application Firewalls. Take part in the Security
Champions programme. Help create and maintain security risk models for new and existing systems.
Location and terms. Bangalore, marked on-site, Full Time Employee, on the Infrastructure team inside
Tech.
Who this is for. An AppSec engineer with seven or more years who wants to own the programme rather
than execute a piece of it. Note the mix: this is not a pure pentest role and it is not a pure tooling
role, it is both plus architecture review and internal advocacy. If you want to spend all day testing,
the training, awareness and Security Champions responsibilities will not suit. The "lead and manage"
language here is about the security programme and its findings, not about managing engineers.
DevSecOps. Proven experience leading architectural changes or cross team efforts to mitigate security
vulnerabilities. Hands-on experience with manual source code reviews and securing production code.
Experience with Git, Jenkins, Artifactory or similar. Experience with Docker and containerisation is
highly desirable.
What you would do. Lead and manage all aspects of the Secure Software Development Lifecycle. Implement
and manage security tools within the CI/CD pipeline (DevSecOps). Conduct and oversee VAPT for web
applications, APIs, iOS and Android apps. Perform threat modelling, design and architecture reviews.
Execute manual source code reviews and improve security in production. Manage and optimise a self
managed bug bounty programme. Provide security architectural guidance to engineering and IT teams.
Manage issues found through penetration tests and the bug bounty. Lead security training and
awareness across the organisation. Manage Web Application Firewalls. Take part in the Security
Champions programme. Help create and maintain security risk models for new and existing systems.
Location and terms. Bangalore, marked on-site, Full Time Employee, on the Infrastructure team inside
Tech.
Who this is for. An AppSec engineer with seven or more years who wants to own the programme rather
than execute a piece of it. Note the mix: this is not a pure pentest role and it is not a pure tooling
role, it is both plus architecture review and internal advocacy. If you want to spend all day testing,
the training, awareness and Security Champions responsibilities will not suit. The "lead and manage"
language here is about the security programme and its findings, not about managing engineers.
Apply on company site
Opens jobs.lever.co, the employer's own application page. Applying is always free.