Security Engineer - 3 (Appsec)
Nykaa · Gurgaon
- Experience8–12 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted2 Sept 2026
About Nykaa
Nykaa is hiring in Gurgaon in ecommerce retail. This role looks for around 8+ years of experience.
Skills
- penetration testing
- web application security
- mobile application security
- API security
- OWASP Top 10 Mobile
- OWASP API Security
- secure coding practices
- SAST
- DAST
- mobile security testing
- authentication
- authorization
- encryption
- session management
- cloud-native architectures
- microservices architectures
- CI/CD
- DevSecOps
- threat modeling
- security architecture
- code review
The role
An application security engineer at an ecommerce product company performs penetration testing, threat modeling, and DevSecOps across web, mobile, and API environments, applying OWASP standards and secure coding practices.
Full job description
Responsibilities:
Perform web and mobile application security assessments, vulnerability analysis, and penetration testing.
Identify, validate, and remediate vulnerabilities across APIs, web applications, Android, and iOS platforms.
Drive implementation of secure SDLC practices across engineering teams.
Conduct code reviews, threat modeling, and security architecture assessments.
Collaborate with developers to remediate security issues and improve application security posture.
Perform security testing for APIs, authentication flows, session management, and business logic vulnerabilities.
Integrate security tools and automation into CI/CD pipelines.
Develop and maintain security standards, policies, and best practices for application security.
Conduct root cause analysis for security incidents and recommend preventive measures.
Stay updated on emerging threats, OWASP standards, and evolving attack vectors.
Requirements:
8+ years of experience in Application Security / Product Security.
Strong expertise in Web and Mobile Application Security.
Hands-on experience with penetration testing for web, API, Android, and iOS applications.
Deep understanding of OWASP Top 10 Mobile, OWASP API Security, and secure coding practices.
Experience with SAST, DAST, and mobile security testing tools.
Strong knowledge of authentication, authorization, encryption, and session management.
Familiarity with cloud-native and microservices-based architectures.
Experience integrating security into CI/CD pipelines and DevSecOps workflows.
Strong analytical, debugging, and communication skills.