Product Security Engineer (Vulnerability Management) in India at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security Engineer (Vulnerability Management) based in India.
This role offers the opportunity to strengthen product security by identifying, managing, and reducing security risks across the software development lifecycle.
You will collaborate closely with engineering, product, and security teams to improve application resilience and protect digital solutions.
The position focuses on vulnerability management, secure coding practices, security automation, and proactive risk reduction.
You will contribute to building secure-by-design practices while supporting developers with actionable security guidance.
Working in a fast-paced technology environment, you will leverage modern security tools and cloud technologies to address evolving threats.
This opportunity is ideal for a security professional passionate about application protection, automation, and improving enterprise security maturity.
The Product Security Engineer will be responsible for identifying, analyzing, prioritizing, and driving remediation of security vulnerabilities across applications and systems. The role requires strong technical expertise, collaboration skills, and the ability to embed security practices throughout the development lifecycle.
- Triage, validate, prioritize, and manage security vulnerabilities identified through manual reviews, automated tools, bug bounty programs, and AI-powered security platforms.
- Participate in security on-call activities, supporting incident triage, security consultations, and code review requests.
- Collaborate with engineering and product teams to drive vulnerability remediation and ensure timely closure of security findings.
- Review source code, pull requests, and application designs to identify security weaknesses before production deployment.
- Analyze security findings generated by automated and AI-assisted tools, validate results, remove false positives, and improve remediation workflows.
- Partner with security architecture teams to enhance vulnerability detection, prioritization, and risk management processes.
- Support security incident investigations and perform root cause analysis when required.
- Develop security automation tools and workflows to improve application security coverage and operational efficiency.
- Administer and maintain vulnerability scanning platforms, including configuration of policies, schedules, and reporting.
- Track remediation progress, create security metrics, and support risk reduction initiatives.
- Develop secure coding guidelines, security documentation, and developer awareness resources.
- Promote secure-by-design and secure-by-default practices across the software development lifecycle.
The ideal candidate is an experienced application security professional with strong knowledge of vulnerability management, secure development practices, and cloud security. You should be comfortable working across technical teams, analyzing complex security issues, and communicating risk-based recommendations.
- 5–8 years of experience in Application Security, Product Security, or a related cybersecurity role.
- Strong understanding of Secure Software Development Lifecycle (SSDLC/SDLC) principles.
- Hands-on experience managing vulnerabilities from SAST, DAST, SCA, dependency scanning, penetration testing, and bug bounty programs.
- Experience performing source code reviews and identifying application security vulnerabilities.
- Strong knowledge of OWASP Top 10, API security, authentication and authorization, cryptography, secrets management, and secure coding practices.
- Experience with vulnerability management and security scanning tools such as Tenable, SAST, DAST, SCA, Infrastructure-as-Code scanning, and secrets detection platforms.
- Experience working with AWS Cloud environments and cloud-native architectures.
- Ability to assess security findings, eliminate false positives, and provide practical remediation recommendations.
- Knowledge of DevSecOps practices and CI/CD security integration.
- Experience building security automation solutions and custom security tooling is a plus.
- Familiarity with AI-assisted development workflows, AI security platforms, or LLM security concepts is beneficial.
- Strong analytical, problem-solving, and prioritization skills.
- Excellent communication, documentation, and stakeholder management abilities.
- Ability to collaborate effectively with engineering, DevOps, and product teams in a fast-paced environment.
- Full-time remote work opportunity based in India.
- Opportunity to work on impactful product security initiatives.
- Exposure to modern application security tools, cloud technologies, and AI-powered security solutions.
- Opportunity to collaborate with experienced engineering and security professionals.
- Professional growth through challenging cybersecurity projects.
- Dynamic environment focused on innovation, continuous learning, and security excellence.
- Opportunity to influence secure development practices across teams.