Senior Security Engineer III
Nykaa · Gurgaon
- Experience6–10 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelsenior
- Posted16 Sept 2026
About Nykaa
Nykaa is hiring in Gurgaon in ecommerce retail. This role looks for around 6+ years of experience.
Skills
- Software Bill of Materials (SBOM)
- Jenkins
- GitHub Actions
- Vulnerability Reachability Analysis
- GitHub Security
- Penetration Testing
- SAST
- DAST
- Web Application Firewall (WAF)
- Threat Modeling
- Secure SDLC
- Cloud Security
- Application Security
The role
A security engineer at an e-commerce retail company secures application ecosystems through application security, software supply chain security, and penetration testing. The work includes threat modeling and DevSecOps practices across microservices, APIs, mobile applications, cloud environments, and GenAI systems.
Full job description
We are looking for a Senior Security Engineer who can think like an attacker and help secure our application ecosystem against modern threats. You will work closely with engineering, development, and DevOps teams to identify and mitigate complex vulnerabilities across microservices, APIs, web/mobile applications, cloud environments, and GenAI implementations.
Responsibilities:
Lead software supply chain security initiatives, including SBOM management and third-party dependency security.
Integrate security controls and guardrails into CI/CD pipelines using Jenkins and GitHub Actions.
Perform vulnerability reachability analysis by reproducing and validating open-source/third-party vulnerabilities.
Strengthen GitHub security posture, including secret scanning, branch protection, and repository security controls.
Conduct advanced web, mobile (Android/iOS), and API penetration testing.
Identify complex logical and business-logic vulnerabilities beyond checklist-based security testing.
Perform security assessments across microservices and cloud-native architectures.
Work with SAST, DAST, WAF, and other application security tools.
Conduct threat modeling during the application/design phase.
Apply Secure SDLC practices across cloud environments.
Help secure GenAI/LLM-based applications and address emerging issues.