Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Senior Product Security Engineer @ Toast

Home > IT Security

 Senior Product Security Engineer

Job Description

  • Identify, triage, and provide remediation guidance for application vulnerabilities.
  • Select, implement, design, or build tools to thwart attacks of all shapes and sizes.
  • Improve developer tooling and adoption to build a more robust SSDLC.
  • Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious. decisions when building new software.
  • Support and expand the Security Champions program, providing edge security guidance and training.
  • Assist incident response teams with application security expertise and tools.
  • Think like an attacker to identify weaknesses in application architecture.
In addition:
  • Support Cloud and Network Infrastructure Engineerings implementation of edge security solutions.
  • Influence the implementation and rule maintenance of our WAF strategy and other edge security solutions.
  • Advise on WAF rules and policies to protect against common and emerging threats.
  • Conduct regular assessments of our edge security posture and recommend improvements.
  • Provide expertise on Content Delivery Networks (CDNs) and their security features.
Do you have the right
ingredients*
(Requirements)
  • 5+ years of experience in application security
  • Strong knowledge of common web application vulnerabilities and edge-based attack vectors.
  • Proficiency in analyzing web traffic patterns and identifying anomalies.
  • Knowledge of compliance standards relevant to the financial industry (e.g., PCI DSS, SOC 2).
  • Excellent problem-solving skills and ability to think creatively about edge security challenges.
  • Strong communication skills, with the ability to explain complex edge security concepts to both technical and non-technical audiences.
  • Strong understanding of cloud application architecture and common weaknesses.
Special Sauce(Nonessential Skills/Nice to Haves)
Experience with:
  • Understanding of WAF configuration, tuning, and optimization.
  • Popular WAF solutions (e.g., AWS WAF, Cloudflare, Akamai, ModSecurity).
  • Familiarity with CDN technologies and their security features.
  • Cloud and container security technologies and SSDLC tooling (e.g. SAST/DAST/SCA)
  • Infrastructure-as-code (IaC) technologies like Terraform to manage cloud security services
  • Securing financial technologies

Job Classification

Industry: Software Product
Functional Area / Department: IT & Information Security
Role Category: IT Security
Role: Application Security Engineer
Employement Type: Full time

Contact Details:

Company: Toast
Location(s): Bengaluru

+ View Contactajax loader


Keyskills:   PCI DSS remediation cloud security Web technologies SOC Finance Security services Infrastructure Application security application architecture

 Fraud Alert to job seekers!

₹ Not Disclosed

Similar positions

Technical Consultant-Security Intel & Operations Consulting Svcs

  • IBM
  • 3 - 5 years
  • Bengaluru
  • 6 hours ago
₹ Not Disclosed

Technical Consultant-Application Security

  • IBM
  • 3 - 5 years
  • Pune
  • 8 hours ago
₹ Not Disclosed

Senior Cybersecurity Specialist

  • Orange Business
  • 4 - 9 years
  • Noida, Gurugram
  • 2 days ago
₹ Not Disclosed

Senior Systems Administrator

  • Ness
  • 3 - 7 years
  • Hyderabad
  • 20 days ago
₹ Not Disclosed

Toast

Toast empowers restaurants of all sizes to build great teams, increase revenue, improve operations, and delight guests. We pair our deep understanding of the restaurant industry with powerful cloud based software and restaurant-grade hardware to deliver an intuitive, all-in-one platform, across poin...