
Product Security Engineer - Testing
- Bangalore, Karnataka
- Permanent
- Full-time
- Conduct security assessments, including threat modeling, design reviews, and vulnerability scans for applications built on Java, React, Kubernetes, MongoDB, Elasticsearch, and Kafka.
- Perform penetration testing and vulnerability assessments on APIs, web applications, and mobile apps, addressing OWASP Top 10 and other common risks
- Ensure compliance with security standards such as OWASP, NIST, ISO 27001, SOC 2, PCI-DSS, and GDPR by implementing and validating controls.
- Assist in developing secure coding guidelines and provide security training to developers.
- Stay informed on emerging threats, including those related to AI/ML features in Sprinklr AI+, and recommend proactive mitigation strategies.
- Performing Pen Testing on web and mobile applications.
- Proficiency in threat modeling, vulnerability management, and secure design principles.
- Strong understanding of web, API, and mobile app security, including OWASP Top 10 vulnerabilities.
- Experience with Sprinklr’s tech stack: Java, JavaScript/React, Kubernetes, and cloud platforms (AWS, Azure, GCP).
- Familiarity with DevSecOps practices and tools like Burp Suite, OWASP ZAP, or similar for security testing.
- Ability to communicate security risks effectively to technical and non-technical stakeholders.
- Strong problem-solving skills and a proactive approach to identifying risks.
- Certifications such as CISSP, CEH, OSCP, or cloud-specific security certifications (e.g., AWS Certified Security - Specialty).
- Experience with microservices, Kafka, or distributed SaaS applications.
- Knowledge of AI/ML security practices, aligning with Sprinklr’s AI-driven features.
- Familiarity with compliance frameworks like SOC 2 or GDPR.