Overview
Join the global Product Security team to test products like an attacker, identify real and exploitable risks across applications, infrastructure and AI-enabled features, and work with engineering and product teams to remediate them.
What you'll do
- Perform hands-on security testing across web applications, APIs, containers, AWS, Azure, GCP and AI-enabled features using manual techniques and security tooling.
- Validate real, exploitable risk rather than relying on raw scanner output.
- Prioritize findings by exploitability and business impact, track them through verified remediation and retest.
- Contribute to threat modeling, secure design reviews and architecture discussions early in the development lifecycle.
- Assess identity and access control weaknesses, authentication and authorization models, and modern application and cloud architectures for privilege escalation and misconfiguration risk.
- Test AI-enabled features and agentic workflows for prompt injection, tool misuse, excessive agency and other AI-specific failure modes.
- Frame probabilistic findings as reproducible, actionable reports.
- Partner with engineering and product teams to explain findings, review fixes and support secure design and development practices.
- Strengthen security across build pipelines, deployment processes and release practices.
- Document findings and recommendations clearly.
- Support triage of externally reported vulnerabilities alongside the team that owns coordinated disclosure.
- Research emerging attack techniques and AI-assisted testing tools, and apply them to improve testing coverage, consistency and speed while maintaining manual validation.
- Share knowledge across the team to improve testing, risk communication and secure product development.
What you'll need
- Bachelor's degree in Computer Science, Information Security or a related field; equivalent practical experience accepted in place of formal education.
- 3+ years of experience performing penetration testing or application security.
- Experience testing across web applications, APIs, containerized deployments and multi-cloud environments, including AWS, Azure, GCP and embedded or agentic AI applications.
- Demonstrable expertise with tools such as Burp Suite, OWASP ZAP, Postman, Git, and Python or similar scripting languages.
- Strong understanding of the OWASP Top 10, the OWASP Top 10 for LLM Applications, SANS and MITRE ATT&CK.
- Experience validating vulnerabilities through manual testing and distinguishing real, exploitable risk from raw scanner output.
- Familiarity with security risks in AI-enabled features, including prompt injection, tool misuse, excessive agency, memory poisoning and insecure model integrations, and how they chain into real attack scenarios.
- Ability to evaluate AI-generated content critically, verify technical accuracy, and use sound judgment before applying outputs to security testing, analysis or decision-making.
- Demonstrated ability to identify security testing activities that can be automated with AI and implement practical automation that improves coverage, consistency, speed or reporting quality while maintaining human validation of security decisions.
- Comfort configuring and tuning AI-assisted coding and testing tools such as GitHub Copilot and Claude Code, and staying current with emerging AI attack techniques and testing methodologies.
- No security certification is required.
Nice to have
- Experience with threat modeling and secure design reviews.
- Familiarity with cloud security concepts and common risks in modern application environments.
- Experience testing APIs, desktop applications, or legacy and mainframe systems, including IBM i and z.
- Relevant security certifications such as OSCP, PNPT, GPEN, GWAPT, CEH or CompTIA Security+.
- A background in software engineering.
Details
- Location: India.
- Travel is required: No.
Read the full description and apply on the company’s own careers page.