Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Security Engineer IV @ Meesho

Home > Software Development

 Security Engineer IV

Job Description

About the Team

The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. After all, when 5% of Indian households shop with us, its important to build resilient systems to manage millions of orders every day. Weve done this with zero downtime! ?? Sounds impossible? Well, thats the kind of Engineering muscle that has helped Meesho become the e-commerce giant it is today. We value speed over perfection, and see failures as opportunities to become better. Weve taken steps to inculcate a strong Founders Mindset across our engineering teams, making us grow and move fast. We place special emphasis on the continuous growth of each team member - and we do this with regular 1-1s and open communication. As a Security Engineer, you will be part of self-starters who thrive on teamwork and constructive feedback. We know how to party as hard as we work! If we arent building unparalleled tech solutions, you can find us debating the plot points of our favorite books and games or even gossiping over chai. So, if a day filled with building impactful solutions with a fun team sounds appealing to you, join us.

About the Role

As a Security Engineer 4, your role is integral in ensuring the security of our products throughout their development lifecycle. You will be involved from the very beginning, participating in threat modeling and design reviews to identify potential risks early. You'll also integrate and manage SAST tools within our CI/CD pipeline, ensuring continuous security testing as code evolves. Additionally, you'll lead and conduct vulnerability assessments and penetration testing (VAPT) to proactively uncover and address security vulnerabilities before they reach production.
What you will do
  • Lead and manage all aspects of the Secure Software Development Lifecycle (SDLC).
  • Implement and manage security tools within the CI/CD pipeline (DevSecOps).
  • Conduct and oversee VAPT for web applications, APIs, iOS, and Android apps.
  • Perform threat modeling, design, and architecture reviews to identify potential risks.
  • Execute manual source code reviews and enhance security in production environments.
  • Manage and optimize a self-managed bug bounty program.
  • Provide security architectural guidance to Engineering and IT teams.
  • Manage issues identified from penetration tests and bug bounty programs.
  • Lead security training and awareness campaigns across the organization.
  • Manage Web Application Firewalls (WAF) to ensure robust protection.
  • Engage in the Security Champions program to integrate security practices within teams.
  • Assist in creating and maintaining Security Risk Models for both new and existing systems.
What you will need
  • 7+ years of experience in product security, with a focus on application security and Dev SecOps.
  • Proven experience in leading architectural changes or cross-team efforts to mitigate security vulnerabilities.
  • Proficiency in programming languages such as Java, React, Node.js, and Python.
  • Hands-on experience with manual source code reviews and securing production code.
  • Expertise in deploying and managing security tools in CI/CD pipelines.
  • Experience with Git, Jenkins, Artifactory, or other similar technologies.
  • Strong background in securing the software development lifecycle, including eliminating classes of vulnerabilities.
  • Proficiency with cloud platforms like AWS or GCP, including their security tools.
  • Experience with Docker and containerization technologies is highly desirable.
  • Additional experience in infrastructure security, particularly in GCP, Docker, and containerization, is a bonus.

Job Classification

Industry: BPM / BPO
Functional Area / Department: Engineering - Software & QA
Role Category: Software Development
Role: Search Engineer
Employement Type: Full time

Contact Details:

Company: Meesho
Location(s): Bengaluru

+ View Contactajax loader


Keyskills:   Security Engineering Jenkins Java Git GCP CI/CD Node.js Artifactory React AWS Python

 Fraud Alert to job seekers!

₹ Not Disclosed

Similar positions

SFMC Lead Engineer

  • Wipro
  • 5 - 10 years
  • Bengaluru
  • 13 hours ago
₹ Not Disclosed

Governance Data Engineer

  • Ness
  • 4 - 7 years
  • Bengaluru
  • 18 hours ago
₹ Not Disclosed

Senior Lead Cybersecurity Architect

  • JPMorgan Chase Bank
  • 5 - 10 years
  • Kolkata
  • 1 day ago
₹ Not Disclosed

Software Engineer II Full Stack

  • NCR Corporation
  • 3 - 8 years
  • Hyderabad
  • 1 day ago
₹ Not Disclosed

Meesho

Meesho Meesho is building a disruptive social distribution channel via social sellers selling on WhatsApp, Facebook and other social channels. Meesho has so far enabled 10,00,000+ social sellers across 500+ towns to start and grow their online business, with tools around sourcing, logistics and ...