Security Engineer IV

Meesho · Bengaluru

  • Experience6–10 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelsenior
  • Posted16 Sept 2026

About Meesho

Meesho is hiring in Bengaluru in ecommerce retail. This role looks for around 6+ years of experience.

Skills

  • Threat Modelling
  • Secure Software Development Lifecycle
  • DevSecOps
  • Vulnerability Assessment and Penetration Testing
  • Manual Source Code Review
  • Cloud Security
  • SAST
  • CI/CD
  • Java
  • React
  • Node.js
  • Python
  • Git
  • Jenkins
  • Artifactory
  • AWS
  • GCP
  • Web Application Firewall

The role

An application security engineer at an e-commerce marketplace conducts threat modelling, secures the software development lifecycle, and performs vulnerability assessments and penetration testing across web applications and APIs. The role also applies DevSecOps, source code reviews, and cloud security to protect production systems.

Full job description

As a Security Engineer 4 your role is integral in ensuring the security of our products throughout their development lifecycle. You will be involved from the very beginning, participating in threat modelling and design reviews to identify potential risks early. You'll also integrate and manage SAST tools within our CI/CD pipeline, ensuring continuous security testing as code evolves. Additionally, you'll lead and conduct vulnerability assessments and penetration testing (VAPT) to proactively uncover and address security vulnerabilities before they reach production.

Responsibilities:

Lead and manage all aspects of the Secure Software Development Lifecycle (SDLC).

Implement and manage security tools within the CI/CD pipeline (DevSecOps).

Conduct and oversee VAPT for web applications, APIs, iOS, and Android apps.

Perform threat modelling, design, and architecture reviews to identify potential risks.

Execute manual source code reviews and enhance security in production environments.

Manage and optimise a self-managed bug bounty program.

Provide security architectural guidance to Engineering and IT teams.

Manage issues identified from penetration tests and bug bounty programs.

Lead security training and awareness campaigns across the organisation.

Manage Web Application Firewalls (WAF) to ensure robust protection.

Engage in the Security Champions program to integrate security practices within teams.

Assist in creating and maintaining Security Risk Models for both new and existing systems.

Requirements:

7+ years of experience in product security, with a focus on application security and Dev SecOps.

Proven experience in leading architectural changes or cross-team efforts to mitigate security vulnerabilities.

Proficiency in programming languages such as Java, React, Node.js, and Python.

Hands-on experience with manual source code reviews and securing production code.

Expertise in deploying and managing security tools in CI/CD pipelines.

Experience with Git, Jenkins, Artifactory, or other similar technologies.

Strong background in securing the software development lifecycle, including eliminating classes of vulnerabilities.

Proficiency with cloud platforms like AWS or GCP, including their security tools.

Experience with Docker and containerization technologies is highly desirable.

Additional experience in infrastructure security, particularly in GCP, Docker, and containerization, is a bonus.