Staff Product Security Engineer

5 - 10 years

10 - 15 Lacs

Posted:1 week ago| Platform: Foundit logo

Apply

Work Mode

Remote

Job Type

Full Time

Job Description

About The Team

  • The Tide Security Engineering team is made up of three core areas: Product Security, Threat Detection & Response, and Identity.
  • Product Security (this role!) consists of application and cloud security experts. Their mission is to protect the products we build, covering everything from secure design reviews to threat modelling and penetration testing, ensuring security is embedded from the ground up.
  • Threat Detection & Response focuses on protecting the company by building a robust detection and automation platform. We're proactive in our defence, constantly hacking ourselves to improve our security posture and staying ahead of emerging threats. Our goal is to make Tide resilient against the ever-evolving threat landscape.
  • Identity is responsible for managing Tide's staff identity platform, ensuring that access to systems and infrastructure is secure, seamless, and aligned with modern security practices. The team uses strategies like zero trust, multi-factor authentication, and granular role-based access controls to safeguard our internal operations.
  • While each area has its own focus, collaboration is key - it's why we share the same Slack channel and hold our standups together as one cohesive team, ensuring alignment and seamless communication across all security functions.

About The Role

  • First and foremost you will be passionate about security and resilient software development processes. You will enjoy hunting for vulnerabilities in our web and mobile applications and working with our engineering teams to remediate them strategically. You will be comfortable explaining security issues and concerns to product owners, engineers, VPs and executives and love the feeling you get when this results in them releasing a more resilient product. You will be a keen follower of all things Infosec and constantly be on the lookout for ways to apply new industry trends, tools and automations to your day-to-day role.

As a Senior Product Security Engineer You'll

  • Regularly dive deep into mobile, web app technologies in order to understand feature development and proactively hunt for vulnerabilities
  • Be proficient in securing cloud-native applications, ensuring that security best practices are applied consistently across our cloud environment
  • Be proficient in threat modelling and guide developers in secure design principles to prevent vulnerabilities from being introduced in the first place
  • Help remediate vulnerabilities through strategic initiatives, writing patches, or creating understandable and actionable vulnerability tickets.
  • Be the subject matter expert across a wide range of security areas, particularly in Application Security.
  • Make security invisible when possible, believing that gatekeeping and blocking product teams should be avoided in favour of enabling secure development.
  • Mentor and coach junior engineers, sharing your knowledge to help raise the security bar across the organisation
  • Leverage automation and security tools to seamlessly integrate security into our CI/CD pipelines, ensuring vulnerabilities are caught early without disrupting development.

What We Are Looking For

  • You have a breadth and depth of knowledge across AppSec; you're expected to understand topics like why private keys should be stored in the Secure Enclave, the differences between URL Schemes and Universal Links, what presigned URLs are in the context of S3 and the safest storage mechanisms for modern browsers.
  • You know Burp Suite (or your favourite attack proxy) inside and out; bonus points if you've written or contributed to an extension that enhances its functionality.
  • You have excellent spoken and written communication skills to articulate vulnerabilities clearly and persuasively, advocating for their remediation even when faced with competing production pressures.
  • As a passionate senior security engineer, you have a blog, public speaking engagements, bug bounty profile, or a Git repository showcasing your work.
  • You're comfortable writing proof-of-concept (POC) scripts to demonstrate your findings and their potential impact, as needed.
  • You have hands-on experience with securing cloud-native applications, ensuring that best practices are consistently applied.

What You'll Get In Return

  • Competitive salary
  • Self & Family Health Insurance
  • Term & Life Insurance
  • OPD Benefits
  • Mental wellbeing through Plumm
  • Learning & Development Budget
  • WFH Setup allowance
  • 15 days of Privilege leaves
  • 12 days of Casual leaves
  • 12 days of Sick leaves
  • 3 paid days off for volunteering or L&D activities
  • Stock Options

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You