Security Engineer

Victoria’s Secret & Co. · Bengaluru

  • Experience3–5 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted24 Sept 2026

About Victoria’s Secret & Co.

Victoria’s Secret & Co. is hiring in Bengaluru in ecommerce retail. This role looks for around 3+ years of experience.

Skills

  • Application security testing
  • Dynamic Application Security Testing
  • Static Application Security Testing
  • API security testing
  • Penetration testing
  • AI/ML security
  • Agentic AI security
  • OWASP Top Ten
  • Secure code review
  • Go
  • Java
  • React
  • Swift
  • Python

The role

A penetration tester at a specialty retail company assesses web, mobile, API, and AI systems for vulnerabilities, applying OWASP Top Ten and application security testing to drive remediation. Expertise in AI/ML security and secure code review supports assessment of agentic systems and underlying infrastructure.

Full job description

Why You Belong Here

At Victoria’s Secret & Co, you’ll join a world-leading specialty retail brand recognized globally for innovation and excellence in lingerie and fashion. You’ll work alongside industry leaders to set the standard for what a retail brand can achieve, placing customers at the center of everything we do to create products and experiences that bring them joy.

We believe everyone deserves a place where they truly belong. We celebrate individuality and know that your passion, experience, and unique perspective strengthen our team and business. Here, you’ll be empowered to perform, grow, and engage through unmatched opportunities to develop your skills, gain real-world experience, and learn from the best in the business.

Description

Security Engineer works within global information security function and will be responsible for application security assessment and Pentest that includes Dynamic Application Security testing (Web/Mobile), Pentest for AI Models, Agentic AI systems and AI protocols like MCP, ACP, UCP and manual application Pentest. Candidate will be responsible for ensuring the security and integrity of applications and underlying infrastructures.

Perform Application Security Testing – Dynamic Web/Mobile Application Security Testing, Static Application Security Testing and API Security Testing

Perform Application Security Assessment and Pentest for AI models, frameworks, protocols, interfaces, and data pipelines (e.g., prompt injection, model inversion, jailbreaking).

Evaluate AI systems against OWASP LLM/Gen AI/Agentic AI Top 10 vulnerabilities

Review vulnerability reports from automated security testing tools and remove false positives

Identify potential threats and perform automated and manual tests as needed

Assess vulnerabilities and classify them based on the impact assessment

Collaborate with Dev team and drive remediation - tracking vulnerabilities and remediation progress

Participate in daily standups and provide project updates

Good understanding of AI development frameworks and automation

Business Strategy

Possess deep functional knowledge & work as subject matter expert as needed

Expertise to coach & demonstrate know how as needed

Change Management

Change agent with strong credibility and influence team

Relationship Management

Work closely with the respective stakeholders. Collaborate and build strong relationship with functional teams to ensure required support for vulnerability remediation and enhancement of processes.

Excellent collaboration skills and the ability to influence team members

Qualifications

Education & Skill

Bachelor’s degree in Information Technology/Information Security or equivalent experience in technology

Security Certifications Preferred Such As

oCertified Ethical Hacker (CEH)

oCertified AI/ML Pentester

oCertified Agentic AI Pentester

Work Expérience

3-5 years of experience in application security testingExperience in application security testing – DAST, API, AI/ML/Agentic AI, AI ProtocolsGood understanding of OWASP Top 10 (Web/mobile/API/LLM/GenAI/Agentic AI) vulnerabilities and secure code review guidelinesKnowledge of one language, preferably Go/JAVA/React/Swift/PythonStrong verbal and written communication skillsAbility to communicate technical issues to non-technical audiences