About this role
About the Role Security Engineer II to drive end-to-end product security across web apps, APIs, cloud systems, and firmware layers. Focus on vulnerability detection, SDLC integration, and building scalable security automation using modern tools including AI-driven technologies. Collaborate with engineering teams to ensure secure design, development, and deployment and strengthen firmware-level security as part of a holistic product security approach. What You'll Do
- Web & API Security Testing: Perform manual & automated testing aligned with OWASP Top 10 (including API security).
- Code & Release Security Reviews: Continuously review code changes/releases and validate vulnerability fixes.
- Security Tooling & CI/CD Integration: Implement and manage SAST, DAST, and automated security scans in pipelines.
- API Discovery & Inventory Management: Discover, track, and maintain API inventory (including shadow APIs) with risk classification.
- Advanced API Testing: Perform API fuzzing, abuse-case testing, and identify business logic vulnerabilities.
- Cloud Security Management: Secure cloud environments using CSPM, CWPP, CIEM, and CNAPP; remediate misconfigurations and identity risks.
- Threat Modeling & Secure Design: Conduct STRIDE-based threat modeling and recommend secure architecture improvements.
- Security Automation & Optimization: Build automated security pipelines, enforce security gates, and enhance detection using AI and continuous tuning.
- Security Audit & Compliance Support: Provide technical evidence and documentation for internal and external security audits (e.g., SOC2, ISO 27001, PCI-DSS) to ensure continuous regulatory compliance and security assurance.