Application Security II

Nykaa · Gurgaon

  • Experience4–6 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelmid
  • Posted16 Sept 2026

About Nykaa

Nykaa is hiring in Gurgaon in ecommerce retail. This role looks for around 4+ years of experience.

Skills

  • Application Security
  • Product Security
  • Penetration Testing
  • Web Security
  • Mobile Security
  • API Security
  • OWASP
  • Secure SDLC
  • Threat Modeling
  • Microservices Security
  • Software Supply Chain Security
  • SBOM
  • Vulnerability Reachability
  • SAST
  • DAST
  • WAF
  • CI/CD Security
  • GitHub Security
  • AWS
  • GCP
  • Java
  • JavaScript
  • Python

The role

An application security engineer at an ecommerce retail company secures web, mobile, API, and microservices products through application security, penetration testing, and GenAI security, while applying DevSecOps and cloud security practices.

Full job description

We are looking for a Senior Security Engineer to identify, investigate, and mitigate complex security vulnerabilities across our application ecosystem. This role is ideal for a security professional with a strong attacker mindset, deep expertise in Application/Product Security and Penetration Testing, and the ability to work closely with Engineering and DevOps teams to secure modern microservices, cloud-native applications, and GenAI solutions.

The candidate will have responsibilities across the following functions:

Application and Product Security:

Perform advanced security assessments across Web, Mobile (Android/iOS), APIs, and Microservices.

Conduct penetration testing to uncover logical, business-logic, and deep application vulnerabilities beyond standard checklists.

Identify, triage, reproduce, and validate complex security vulnerabilities.

Perform security-focused code reviews and support secure SDLC initiatives.

Software Supply Chain and DevSecOps:

Drive Software Supply Chain Security, including SBOM management and third-party dependency security.

Analyse and validate vulnerability reachability to determine whether vulnerable code paths are actually exploitable within the product.

Integrate security guardrails into CI/CD pipelines using Jenkins and GitHub Actions.

Strengthen GitHub security posture through secret scanning, branch protection, repository security controls, and related practices.

Work closely with Development and DevOps teams to embed security throughout the SDLC.

Cloud and Security Architecture:

Conduct Threat Modeling during application and feature design.

Assess security architecture of cloud-native and microservice-based applications.

Apply secure SDLC principles across AWS/GCP environments.

Work with security tools and technologies including SAST, DAST, and WAF.

GenAI Security:

Assess and secure GenAI/LLM-powered applications.

Understand and mitigate emerging LLM security risks such as prompt injection, data leakage, insecure tool/function usage, and application-level AI threats.

Partner with engineering teams to build security controls into AI-enabled products.

Collaboration and Security Advocacy:

Communicate vulnerabilities, business impact, and remediation strategies clearly to technical and non-technical stakeholders.

Define security requirements and contribute to cyber risk assessments.

Mentor developers and junior security engineers on secure coding practices.

Requirements:

Hands-on experience in Application Security, Product Security, Penetration Testing, or Vulnerability Research.

Strong expertise in Web, Mobile (iOS/Android), and API Security.

Strong understanding of OWASP, secure SDLC, threat modelling, vulnerability management, and application security.

Experience securing microservices and cloud-native applications.

Knowledge of Software Supply Chain Security, SBOM, third-party dependencies, and vulnerability reachability.

Hands-on experience with SAST, DAST, WAF, CI/CD security, and GitHub security controls.

Strong ability to read, understand, debug, and review code in Java, JavaScript, and/or Python.

Practical experience with AWS and/or GCP security.

Strong understanding of modern GenAI/LLM security threats is a plus.

Strong analytical and problem-solving skills with an attacker mindset.

Preferred Certifications: OSCP, OSEP, OSWE.

Ideal Candidate:

A seasoned security professional who can think like an attacker, understand application internals, reproduce vulnerabilities, assess exploitability, and work with engineering teams to fix security issues at their root.

Keywords: Application Security, Product Security, VAPT, Penetration Testing, Vulnerability Research, Web Security, API Security, Mobile Security, OWASP, Threat Modelling, DevSecOps, Software Supply Chain Security, SBOM, Vulnerability Reachability, SAST, DAST, WAF, CI/CD Security, GitHub Security, AWS, GCP, Microservices Security, GenAI Security, LLM Security, Secure SDLC, OSCP, OSEP, OSWE.