S

Engineer 1 - Product Security

slice · Bengaluru, Karnataka, India

Banking · 1,001-5,000 employees

2 d ago
Junior (0-2 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The engineer will embed security throughout the software development lifecycle by performing vulnerability assessments, penetration testing, and threat modeling. They will also collaborate with engineering teams to provide secure coding guidance and implement automated security testing practices.

What they look for

Application Security Penetration Testing Vulnerability Assessment Threat Modeling Mobile Security API Security DevSecOps Python Bash Burp Suite OWASP Top 10 Secure Coding Linux Networking SAST DAST

Requirements

Candidates must have 1-2 years of experience in application or product security with hands-on knowledge of web, API, and mobile security testing. Proficiency in security tools like Burp Suite and scripting languages such as Python or Bash is required.

Benefits

Competitive salaries Medical insurance Flexible working hours Tailored vacation and leave policies Learning and upskilling opportunities

Full description

About the role:

As a Cyber Security Engineer at slice, you will play a key role in strengthening our Application and Product Security program by embedding security throughout the Software Development Lifecycle (SDLC). You will work closely with engineering, product, and infrastructure teams to identify security risks early, conduct security assessments, and help build secure, scalable products that meet industry standards and compliance requirements. This role is ideal for someone passionate about offensive security, secure design, mobile and API security, and DevSecOps.

What you will do:

Application Security

  • Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, Android, and iOS applications.
  • Conduct Secure Design Reviews and identify potential security risks during the design phase.
  • Perform Threat Modeling sessions for new applications, services, and major feature releases.
  • Validate security controls and perform security re-testing after vulnerabilities are remediated.
  • Prepare detailed security assessment reports with clear remediation guidance and risk prioritization.

Mobile & API Security

  • Perform static and dynamic security analysis of Android and iOS applications.
  • Assess REST APIs and microservices for authentication, authorization, business logic, and data exposure vulnerabilities.
  • Identify vulnerabilities such as:

Broken Authentication Broken Authorization (BOLA/IDOR) Injection attacks Sensitive Data Exposure Business Logic flaws Security Misconfiguration Rate-limit bypass SSRF, XXE, CSRF, XSS, and related web security issues

  • Provide secure coding recommendations and remediation guidance.
  • Contribute to the implementation and improvement of SAST, DAST, SCA, Secret Scanning, and Infrastructure-as-Code (IaC) security practices.
  • Evaluate new technologies and architectures from a security perspective and recommend appropriate security controls.
  • Develop scripts and automation to improve security testing and vulnerability management workflows.
  • Contribute to internal security tools and automation initiatives.
  • Assist in improving security processes, standards, and documentation.

Collaboration & Compliance

  • Partner with developers, architects, product managers, and infrastructure teams to drive secure-by-design principles.
  • Provide technical security guidance during feature development and product releases.
  • Ensure applications and infrastructure comply with internal security requirements and applicable industry standards.

What you will need:

  • 1–2 years of experience in Application Security, Product Security, or Cyber Security.
  • Strong understanding of web application, API, Android, and iOS security concepts.
  • Hands-on experience performing penetration testing of web applications, APIs, and mobile applications.
  • Hands-on experience in identifying and assessing network security vulnerabilities and security misconfigurations.

Good understanding of:

  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP Mobile Application Security (MASVS/MSTG)
  • Knowledge of authentication and authorization mechanisms including OAuth2, JWT, OIDC, and session management.
  • Good understanding of Secure Software Development Lifecycle (SSDLC) and secure coding practices.
  • Familiarity with common security vulnerabilities and exploitation techniques.
  • Experience writing technical security reports and communicating remediation recommendations.
  • Strong analytical, problem-solving, and communication skills.
  • Experience with Linux systems and networking fundamentals.
  • Experience with scripting using Python, Bash, or similar languages for automation.

Tools & Technologies Experience with one or more of the following tools is preferred:

  • Burp Suite
  • MobSF
  • Frida
  • Objection
  • Postman
  • Nmap
  • Subfinder
  • Amass

Good to Have

  • Familiarity with AWS security concepts.
  • Experience with SAST, DAST, SCA, Secret Scanning, and IaC Security.
  • Experience with cloud-native application security.
  • Participation in Bug Bounty programs or responsible disclosure programs.
  • Contributions to open-source security projects.
  • Familiarity with AI-assisted security testing and automation.

Preferred Certifications

  • eJPT
  • eWPT
  • eMAPT
  • PNPT
  • OSCP (Good to Have)

What We Look For

  • Passion for offensive security and continuous learning.
  • Strong ownership and accountability.
  • Curiosity to understand how systems work and how they can be secured.
  • Ability to communicate effectively with engineering and business stakeholders.
  • A collaborative mindset and willingness to improve security processes across the organization.

Life at slice:

Life so good, you’d think we’re kidding:

  • Competitive salaries. Period.
  • An extensive medical insurance that looks out for our employees & their dependents. We’ll love you and take care of you, our promise.
  • Flexible working hours. Just don’t call us at 3AM, we like our sleep schedule.
  • Tailored vacation & leave policies so that you enjoy every important moment in your life.
  • A reward system that celebrates hard work and milestones throughout the year. Expect a gift coming your way anytime you kill it here.
  • Learning and upskilling opportunities. Seriously, not kidding.
  • Good food, games, and a cool office to make you feel like home. An environment so good, you’ll forget the term “colleagues can’t be your friends”.

We believe in equality. Period.

At slice, we are committed to building a diverse and talented workforce. We never discriminate on the basis of race, sex, religion, colour, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, medical condition, disability, or any other class or characteristic protected by the applicable law.

We consider all qualified job-seekers with criminal histories in a manner consistent with the applicable law. Additionally, we are committed to providing reasonable accommodations to qualified individuals with physical or mental disabilities in order to participate in the job application or interview process, perform essential job functions, and receive other benefits and privileges of employment.

Come join our crew!

About slice:

slice

A new bank for a new India

slice’s purpose is to make the world better at using money and time, with a major focus on building the best consumer experience for your money. We’ve all felt how slow, confusing, and complicated banking can be. So, we’re reimagining it. We’re building every product from scratch to be fast, transparent, and feel good, because we believe that the best products transcend demographics, like how great music touches most of us.

Our cornerstone products and services: slice savings account, slice UPI credit card, slice UPI, and slice business are designed to be simple, rewarding, and completely in your control. At slice, you’ll get to build things you’d use yourself and shape the future of banking in India. We tailor our working experience with the belief that the present moment is the only real thing in life. And we have harmony in the present the most when we feel happy and successful together.

We’re backed by some of the world’s leading investors, including Tiger Global, Insight Partners, Advent International, Blume Ventures, and Gunosy Capital.