Senior Security Engineer

Nykaa · Gurgaon

  • Experience1–3 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Leveljunior
  • Posted16 Sept 2026

About Nykaa

Nykaa is hiring in Gurgaon in ecommerce retail. This role looks for around 1+ years of experience.

Skills

  • Application Security
  • Penetration Testing
  • OWASP
  • Secure SDLC
  • Threat Modeling
  • Vulnerability Management
  • Microservices Security
  • Cloud-Native Application Security
  • Software Supply Chain Security
  • SBOM
  • Dependency Security
  • Vulnerability Reachability Analysis
  • Java
  • JavaScript
  • Python
  • SAST
  • DAST
  • WAF
  • CI/CD Security
  • GitHub Security Controls
  • AWS
  • GCP

The role

An application security engineer at an e-commerce retail company secures web, mobile, API, microservices, and cloud-native applications through application security, penetration testing, and software supply chain security. Threat modeling and CI/CD security further protect software delivery and GenAI applications.

Full job description

We're looking for a Senior Security Engineer to strengthen the security of our application ecosystem. You'll work closely with engineering, devOps, and product teams to identify complex vulnerabilities, uncover business-logic flaws, and build security into the software development lifecycle.

Responsibilities:

Lead application and product security initiatives across web, mobile, APIs, microservices, and cloud-native applications.

Conduct advanced penetration testing across Web, Android/iOS, and API environments, going beyond automated or checklist-based testing.

Identify and validate complex logical, business-logic, and application vulnerabilities.

Drive software supply chain security, including SBOM management, third-party dependency security, and vulnerability reachability analysis.

Integrate security controls and guardrails into CI/CD pipelines using Jenkins/GitHub Actions.

Strengthen GitHub security posture, including secret scanning, branch protection, repository controls, and security configurations.

Perform threat modeling and security assessments during application design and development.

Work with SAST, DAST, WAF, and other application security tooling.

Secure GenAI/LLM-powered applications and assess risks such as prompt injection, data leakage, insecure tool use, and model/application abuse.

Partner with engineering and devOps teams to implement secure SDLC practices in AWS/GCP environments.

Perform security-focused code reviews and mentor developers on secure coding practices in Java, JavaScript, and Python.

Document vulnerabilities clearly and communicate technical risks and remediation plans to engineering and business stakeholders.

Requirements:

Strong hands-on experience in application security, product security, or penetration testing.

Expert-level experience in web, mobile (iOS/Android), and API security.

Strong understanding of OWASP, secure SDLC, threat modeling, and vulnerability management.

Experience with microservices and cloud-native application security.

Strong knowledge of software supply chain security, SBOMs, dependency security, and vulnerability reachability.

Ability to read, debug, and understand code in Java, JavaScript, and/or Python.

Hands-on experience with SAST, DAST, WAF, CI/CD security, and GitHub security controls.

Practical experience securing applications on AWS and/or GCP.

Understanding of GenAI/LLM application security is highly desirable.

Strong attacker mindset with the ability to discover vulnerabilities beyond standard security checklists.

Preferred Certifications: OSCP, OSEP, OSWE.

Ideal Profile: Someone who can think like an attacker, understand how the application works internally, reproduce vulnerabilities, assess real-world exploitability, and work with developers to fix the underlying security issue.