Lead InfoSec Engineer

Darwinbox · Bengaluru

  • Experience7–8 yrs
  • SalaryNot disclosed
  • Work modehybrid
  • Posted25 Sept 2026

About Darwinbox

Darwinbox is hiring in Bengaluru in technology software. This role looks for around 7+ years of experience.

Skills

  • Application Security
  • OWASP Top 10
  • OWASP API Security Top 10
  • CWE
  • secure coding
  • SAST
  • DAST
  • Software Composition Analysis
  • secrets scanning
  • web application security testing
  • API security testing
  • threat modelling
  • STRIDE
  • secure code review
  • CI/CD
  • Jenkins
  • GitHub Actions
  • Git
  • AWS
  • Azure
  • Google Cloud Platform
  • Docker
  • Kubernetes
  • Infrastructure as Code security
  • Black Duck
  • Coverity
  • Trivy
  • TruffleHog
  • OAuth 2.0
  • OpenID Connect
  • SAML
  • JSON Web Token
  • role-based access control
  • software supply-chain security
  • SBOM
  • dependency governance
  • secrets management

The role

An application security engineer at a video technology company assesses web applications, APIs and cloud-native applications through threat modelling, secure code review and OWASP practices, and strengthens DevSecOps with SAST, DAST and security automation.

Full job description

Company Overview

At Synamedia, we’re a global team of 800+ trailblazers across 17 countries, revolutionizing how the world is entertained and informed.

Synamedia helps many of the world’s leading operators and media companies create, deliver and monetise next-generation video experiences across mobile and big screen. Combining integrated platforms, cloud innovation and trusted operational expertise, Synamedia enables customers to grow audiences, increase engagement, and accelerate digital transformation.

Our solutions have been built over the last three decades and are trusted by giants like Astro, Sky, beIN Sports, Vodafone, OSN, Etisalat and many more.

Ready to grow with us and shape the future of media and entertainment solutions? Let’s do it together!

Job Description

About the Job

We are looking for an Application Security Engineer to strengthen the security of Synamedia products and the software development lifecycle. The role partners with engineering, architecture, DevOps, cloud and security teams to identify risks early, automate security controls, and help teams build secure products at scale. The ideal candidate combines hands-on AppSec skills with strong software engineering awareness and can translate security findings into practical remediation guidance.

Responsibilities

Perform security assessments of web applications, APIs, microservices and cloud-native applications.

Conduct threat modelling and security design reviews for new products, features and architectural changes.

Perform secure code reviews and identify vulnerabilities, insecure coding patterns and design weaknesses.

Implement and improve SAST, DAST, SCA, secrets scanning and related AppSec tooling.

Integrate automated security checks and risk-based quality gates into CI/CD pipelines.

Validate, triage and prioritize vulnerabilities based on exploitability, technical impact and business risk.

Work with engineering teams to provide actionable remediation guidance and track vulnerabilities through closure.

Assess authentication, authorization, session management, cryptography, data protection and input-validation controls.

Perform security testing of REST APIs and service interfaces, including authorization, injection, data exposure and business-logic issues.

Develop security automation and scripts to improve the scalability and effectiveness of the AppSec program.

Define secure coding guidance, security checklists and developer enablement material.

Contribute to application-security metrics, reporting and continuous improvement of the Secure SDLC.

Skills Required

7+ years of relevant experience in Application Security, Product Security, DevSecOps, penetration testing or secure software development.

Strong understanding of OWASP Top 10, OWASP API Security Top 10, CWE/common vulnerability classes and secure coding principles.

Hands-on experience with SAST, DAST, Software Composition Analysis (SCA), secrets scanning and web/API security testing tools such as Burp Suite or OWASP ZAP.

Experience conducting threat modelling using STRIDE or a comparable methodology.

Ability to review source code from a security perspective in one or more languages such as Java, C/C++, C#, Python, JavaScript/TypeScript or Go.

Understanding of CI/CD technologies such as Jenkins, GitHub Actions, along with Git-based development workflows.

Ability to clearly communicate vulnerability impact, exploit scenarios, remediation options and risk to engineering stakeholders.

Experience with AWS, Azure or GCP; Docker, Kubernetes and Infrastructure-as-Code security.

Experience with tools such as Black Duck, Coverity, Trivy, and TruffleHog

Familiarity with OAuth 2.0, OpenID Connect, SAML, JWT, RBAC and modern identity/security patterns.

Exposure to software supply-chain security, SBOM, dependency governance and secrets management.

Security certifications such as CSSLP, CISSP, CCSP are advantageous but not mandatory.

Good to Have – Synamedia Product & Video Domain

Experience or domain knowledge in video streaming, broadcast, OTT, Pay-TV or media technology environments.

Exposure to solutions similar to Synamedia Go, Synamedia Iris, Conditional Access, DRM and video/content security platforms.

Understanding of Conditional Access systems, DRM, entitlement management, content protection, anti-piracy and secure video delivery.

Familiarity with OTT/video technologies and protocols such as HLS, MPEG-DASH, CDNs, streaming APIs, video players and Server-Side Ad Insertion (SSAI).

Understanding of application-security risks in addressable advertising and video monetisation platforms, including APIs, audience/customer data, ad-tech integrations, identity controls and cloud services.

Exposure to securing cloud-native SaaS video platforms, microservices, APIs, containers and distributed systems.

Good to Have – AI & AI-Assisted Development

Familiarity with AI-assisted software development and the secure adoption of Generative AI tools in engineering workflows.

Understanding of risks in AI-generated code, including insecure patterns, vulnerable dependencies, secrets exposure, licensing concerns and insufficient validation.

Ability to help define secure-development practices for teams using AI coding assistants and GenAI development tools.

Experience assessing applications that integrate LLMs, AI agents or Generative AI capabilities is desirable.

Awareness of AI security risks such as prompt injection, sensitive-data disclosure, insecure output handling, excessive agency, model/API abuse and third-party AI supply-chain risk.

Ability to support threat modelling and security reviews for AI-enabled features and services.

Awareness of OWASP guidance for LLM / Generative AI application security.

Interest in using AI and automation to improve vulnerability triage, secure code review, threat modelling, remediation guidance and security testing.

Growth Opportunities

When welcoming new talent into the team, we are always looking for opportunities to bring in new ideas, those who ask challenging questions and have the curiosity to learn. These qualities are important to us as we nurture a culture of innovation, seize more opportunities to partner with our customers and make a difference as we transform the future of video. To further support your growth and that of our talent pool, Synamedia offers an exhaustive library of skill enhancement resources from AWS, SkillSoft and other partners to help you upskill while on the job. Be it data analytics that picks your brain or content creation, there’s something for every kind of mind.

Benefits and Perks

Flexible working arrangements.

Competitive pay hikes and bonus packages.

Skill enhancement and growth opportunities.

Equal opportunity employment.

Health and wellbeing programmes.

Collaborative work with a truly global team.

A Culture of Belonging

Synamedia is committed to promoting a diverse, inclusive and equal opportunity community - a place where we can all be ourselves and succeed. Our values connect us, and we love to win together. We work with a bias to action, we innovate and encourage curiosity to grow and evolve, as a team.

In our aim to foster a people-friendly environment, we offer a range of family friendly, inclusive employment policies, flexible working arrangements, engagement activities and services to support all our colleagues across our 20 office locations. Synamedia regularly organises community events that promote cohesion and diversity among colleagues. We are proud of our mental health wellbeing initiatives, our Pride month awareness campaign, our cancer awareness programme and much more.

More information

If this role sparks your interest, have any questions, or require any accommodations to be made to help you through your application, please reach out to our recruitment team, who would be happy to help.

Job Snapshot

Updated Date

25/09/2026

Job ID

Job_1034

Department

80081 Protective Security

Location

Bangalore, India

Employee Type

Employee

Employee Sub Type

Employee - Regular