About the Role
We are looking for a passionate Product & Cloud Security Engineer to join our Information Security team. The ideal candidate will play a key role in strengthening the organizations product security posturedriving secure design implementation and governance across our product and cloud environments.
This role combines hands-on security expertise with process-oriented governance ensuring that our applications and cloud workloads meet both internal security standards and external compliance requirements.
Key Responsibilities
- Partner with product and engineering teams to review designs identify risks and recommend secure architecture patterns and mitigations.
- Contribute to defining implementing and continuously improving the Secure SDLC frameworkembedding security checkpoints tools and metrics throughout development pipelines.
- Support identification triage and remediation of vulnerabilities across applications and cloud environments. Work with engineering teams to ensure timely closure of findings.
- Help operationalize and optimize SAST DAST and SCA tooling to integrate seamlessly within CI/CD pipelines.
- Assist in implementing and reviewing security controls IAM configurations and compliance guardrails for workloads deployed in Azure and GCP.
- Support ongoing adherence to PCI-DSS ISO 27001 and other relevant frameworks by mapping controls maintaining evidence and supporting audits.
- Understand key privacy regulations (e.g. GDPR CCPA) and how they translate into security control requirements for product and infrastructure design.
Required Skills & Experience
- Strong understanding of application and product security principles.
- Hands-on experience with vulnerability management and application security testing tools (e.g. Wiz Qualys SonarQube Checkmarx Burp OWASP ZAP Black Duck etc.).
- Good knowledge of cloud security controls and best practices for Azure and GCP.
- Familiarity with secure development practices DevSecOps and integrating security within CI/CD pipelines.
- Exposure to compliance frameworks such as PCI-DSS ISO 27001 and SOC 2.
- Strong collaboration skills ability to work with developers product owners and compliance teams.
- Excellent written and verbal communication skills.
Preferred / Nice-to-Have
- Understanding of privacy frameworks and data protection principles.
- Relevant certifications (e.g. CCSP AZ-500 GCP Security Engineer CSSLP CISSP CEH) are a plus.
- Experience with threat modeling or secure design reviews.
Qualifications :
BE/BTECH in Information Technology Computer Science or a related field.
Remote Work :
No
Employment Type :
Full-time
About the RoleWe are looking for a passionate Product & Cloud Security Engineer to join our Information Security team. The ideal candidate will play a key role in strengthening the organizations product security posturedriving secure design implementation and governance across our product and cloud ...
About the Role
We are looking for a passionate Product & Cloud Security Engineer to join our Information Security team. The ideal candidate will play a key role in strengthening the organizations product security posturedriving secure design implementation and governance across our product and cloud environments.
This role combines hands-on security expertise with process-oriented governance ensuring that our applications and cloud workloads meet both internal security standards and external compliance requirements.
Key Responsibilities
- Partner with product and engineering teams to review designs identify risks and recommend secure architecture patterns and mitigations.
- Contribute to defining implementing and continuously improving the Secure SDLC frameworkembedding security checkpoints tools and metrics throughout development pipelines.
- Support identification triage and remediation of vulnerabilities across applications and cloud environments. Work with engineering teams to ensure timely closure of findings.
- Help operationalize and optimize SAST DAST and SCA tooling to integrate seamlessly within CI/CD pipelines.
- Assist in implementing and reviewing security controls IAM configurations and compliance guardrails for workloads deployed in Azure and GCP.
- Support ongoing adherence to PCI-DSS ISO 27001 and other relevant frameworks by mapping controls maintaining evidence and supporting audits.
- Understand key privacy regulations (e.g. GDPR CCPA) and how they translate into security control requirements for product and infrastructure design.
Required Skills & Experience
- Strong understanding of application and product security principles.
- Hands-on experience with vulnerability management and application security testing tools (e.g. Wiz Qualys SonarQube Checkmarx Burp OWASP ZAP Black Duck etc.).
- Good knowledge of cloud security controls and best practices for Azure and GCP.
- Familiarity with secure development practices DevSecOps and integrating security within CI/CD pipelines.
- Exposure to compliance frameworks such as PCI-DSS ISO 27001 and SOC 2.
- Strong collaboration skills ability to work with developers product owners and compliance teams.
- Excellent written and verbal communication skills.
Preferred / Nice-to-Have
- Understanding of privacy frameworks and data protection principles.
- Relevant certifications (e.g. CCSP AZ-500 GCP Security Engineer CSSLP CISSP CEH) are a plus.
- Experience with threat modeling or secure design reviews.
Qualifications :
BE/BTECH in Information Technology Computer Science or a related field.
Remote Work :
No
Employment Type :
Full-time
View more
View less