Security Engineer
Victoria’s Secret & Co. · Bengaluru
- Experience3–5 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted24 Sept 2026
About Victoria’s Secret & Co.
Victoria’s Secret & Co. is hiring in Bengaluru in ecommerce retail. This role looks for around 3+ years of experience.
Skills
- Application security testing
- Dynamic Application Security Testing
- Static Application Security Testing
- API security testing
- Penetration testing
- AI/ML security
- Agentic AI security
- OWASP Top Ten
- Secure code review
- Go
- Java
- React
- Swift
- Python
The role
A penetration tester at a specialty retail company assesses web, mobile, API, and AI systems for vulnerabilities, applying OWASP Top Ten and application security testing to drive remediation. Expertise in AI/ML security and secure code review supports assessment of agentic systems and underlying infrastructure.
Full job description
Why You Belong Here
At Victoria’s Secret & Co, you’ll join a world-leading specialty retail brand recognized globally for innovation and excellence in lingerie and fashion. You’ll work alongside industry leaders to set the standard for what a retail brand can achieve, placing customers at the center of everything we do to create products and experiences that bring them joy.
We believe everyone deserves a place where they truly belong. We celebrate individuality and know that your passion, experience, and unique perspective strengthen our team and business. Here, you’ll be empowered to perform, grow, and engage through unmatched opportunities to develop your skills, gain real-world experience, and learn from the best in the business.
Description
Security Engineer works within global information security function and will be responsible for application security assessment and Pentest that includes Dynamic Application Security testing (Web/Mobile), Pentest for AI Models, Agentic AI systems and AI protocols like MCP, ACP, UCP and manual application Pentest. Candidate will be responsible for ensuring the security and integrity of applications and underlying infrastructures.
Perform Application Security Testing – Dynamic Web/Mobile Application Security Testing, Static Application Security Testing and API Security Testing
Perform Application Security Assessment and Pentest for AI models, frameworks, protocols, interfaces, and data pipelines (e.g., prompt injection, model inversion, jailbreaking).
Evaluate AI systems against OWASP LLM/Gen AI/Agentic AI Top 10 vulnerabilities
Review vulnerability reports from automated security testing tools and remove false positives
Identify potential threats and perform automated and manual tests as needed
Assess vulnerabilities and classify them based on the impact assessment
Collaborate with Dev team and drive remediation - tracking vulnerabilities and remediation progress
Participate in daily standups and provide project updates
Good understanding of AI development frameworks and automation
Business Strategy
Possess deep functional knowledge & work as subject matter expert as needed
Expertise to coach & demonstrate know how as needed
Change Management
Change agent with strong credibility and influence team
Relationship Management
Work closely with the respective stakeholders. Collaborate and build strong relationship with functional teams to ensure required support for vulnerability remediation and enhancement of processes.
Excellent collaboration skills and the ability to influence team members
Qualifications
Education & Skill
Bachelor’s degree in Information Technology/Information Security or equivalent experience in technology
Security Certifications Preferred Such As
oCertified Ethical Hacker (CEH)
oCertified AI/ML Pentester
oCertified Agentic AI Pentester
Work Expérience
3-5 years of experience in application security testingExperience in application security testing – DAST, API, AI/ML/Agentic AI, AI ProtocolsGood understanding of OWASP Top 10 (Web/mobile/API/LLM/GenAI/Agentic AI) vulnerabilities and secure code review guidelinesKnowledge of one language, preferably Go/JAVA/React/Swift/PythonStrong verbal and written communication skillsAbility to communicate technical issues to non-technical audiences