Principal Product Security Engineer |India

💰 ₹18,000 - ₹28,800 (Est.) 📍 Bengaluru

Job Description

You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.

You love to solve puzzles, and are a great team player.

This role is remote.

What you’ll do:

The primary emphasis of this role will be code, both reading and writing it (securely) and chatting about it with developers.

During a typical week, you may spend some time:
• Tracking down the line of code responsible for a bug discovered via our bug bounty program (http://hackerone.com/vimeo) and then educating developers and providing them with recommendations on how to best fix the issue
• Auditing a legacy backend controller and providing recommendations to developers on how to best refactor the code to eliminate existing authorization bugs and reduce the likelihood of future ones
• Paring with an engineering team to design the architecture for a new microservice and ensuring that the design adheres to industry best practices (e.g. OWASP ASVS 4.0, CIS benchmarks, etc.)
• Coding up a prototype for a new permissions middleware
• Flagging to leadership a recurring systemic security issues in our codebase and providing highly actionable recommendations to address the root cause in a thorough, maintainable manner
• Hopping on a call or two with Development, Product Management teams to discuss security-related issues
• Engaging with one or more product development teams and guide them through a threat model and data flow analysis.
• Providing technical advice in response to occasional questions from developers and other members of the security team

Depending on your preferences and the current needs of the team, you may potentially also participate in the following activities (although, this will likely be secondary to the activities described above):
• Penetration testing — either hunt for security issues on our production or staged applications during an open-box internal pen test, or help coordinate an engagement with an external firm
• Writing code for internal automated security tools — write some code, usually in Python, Bash, or Go, to support any of our team's various initiatives. Often we strive to facilitate a culture of “paved roads” for our developers, such that it is easy for any developer to incorporate security into their designs and implementations
• Threat modeling — consider how malicious attackers may compromise our systems, and advise developers and product managers on what defenses are needed
• Code reviews — discover weakness in our source code before it reaches production
• Bug bounty program — help triage new incoming reports on a daily basis, plus launch creative initiatives to increase researcher engagement on our programs
• Web Application Firewall and Rate Limiting — expand coverage and tune new rules while coordinating with developers, support team members, and the site reliability team
• Remediation — enable and encourage developers to correctly fix recently discovered security issues in a timely manner, ultimately reducing our Mean Time To Remediate
• Secure Software Development Lifecycle — configure automated tooling (eg. static and dynamic code analysis, IAST) in our SDLC to detect security issues in our source code before it reaches production
• Developer Education, Security Culture — create fun ways to spread technical security awareness throughout the engineering department
• Incident response — lead or assist in running the various phases of an incident response, including initial detection, triage, containment, recovery, root cause analysis, retrospective, etc.
• Collaboration with the infrastructure security team — pair with members of the infrastructure security team on various projects to secure our cloud instances and employee workstations
• Collaboration with the compliance and privacy team — help ensure that our company complies with industry best practices and standards
• Process improvements — help strengthen our own internal processes and procedures

Skills and knowledge you should possess:
• Required: 5+ years of prior experience in either software development, devops, or site reliability engineering with hands-on coding experience.
• Preferred: prior experience in Application Security
• 7+ total years of relevant experience in Engineering, Application Security, or a similar technical field.
• Strong knowledge of modern web, mobile, and network security
• Strong programming skills with at least one of the following languages, and the ability to read all of them: Python, Go, PHP, Javascript, and Ruby
• Expertise with application pen testing, using tools like Burp or Zap
• Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.
• Confident with shell scripting
• Confident with common SDLC components, like git, Jira, Jenkins, etc
• Confident ability to communicate technical security concepts to developers
• At least an upper-intermediate level of English

Bonus points (nice skills to have, but not needed):
• Link to a Github repo with security tools/scripts you’ve developed or help maintain
• Full-stack web development experience creating RESTful applications (in any language) is a big plus
• Open source vulnerability research or blog posts is a big plus
• Experience with system security hardening guidelines and SDLC principles

About Us

💡 Quick Summary

Seeking a career-building opportunity? The Principal Product Security Engineer |India position is now open for candidates interested in the Fresher Jobs sector. This role in Bengaluru offers a professional environment and growth potential.

Requirement Snapshot: Candidates should possess basic communication skills, a proactive attitude, and the ability to work in a team. Experience in Fresher Jobs is a plus.

Sponsored

Job Details

Company Name: Vimeo, Inc.

Frequently Asked Questions

Click the Apply Now button on this page, login or register for free on CallCenterJob.co.in, fill in your name, mobile number, city, and experience, then submit your application. The recruiter will contact you directly.
The expected salary for Principal Product Security Engineer |India in Bengaluru is ₹18,000 - ₹28,800 (Est.) per month. Actual compensation may vary based on experience and negotiation.
No, Principal Product Security Engineer |India is an on-site position based in Bengaluru . Candidates must be able to commute or relocate to this location.
Basic communication skills, a proactive attitude, and the ability to work in a team are required for Principal Product Security Engineer |India. Previous experience in Fresher Jobs is a plus. Freshers may also apply depending on the employer's requirements.
Yes, CallCenterJob.co.in is completely free for job seekers. Never pay money to apply for any job. If anyone asks for payment to process your application, report it immediately using the "Report this Job" button.

Similar Openings

  • Assistant Manager | Retail

    Job Summary The individual is expected to manage the daily operations of our Brijwasi Sweets store. Responsibilities and Duties Responsible for the smooth functioning of the store Assist walk in customers with their purchases & Up sell products E...

    Full Time / Part Time

    Salary Estimated: 25K to 32K

    Mumbai, Maharashtra

    August 4, 2026


    Apply Now

  • Digital Marketing Executive | Trainee

    Undergraduates - B Com , BBA , B.Tech Work experience of 6 months or Certification in Digital Marketing -Must have Benefits Letter for experience as Digital Marketing Trainee Build a sustainable career in digital marketing Guarantee to get absorbed f...

    Full Time / Part Time

    Salary Estimated: 21K to 31K

    Noida, Uttar Pradesh

    August 4, 2026


    Apply Now

  • SAVE Fresher Graduate Under Graduate Call Center Bpo Ites Voice

    Apply on TimesJobs Fresher Graduate Under Graduate Call Center Bpo Ites Voice W White Horse Manpower Consultancy P Ltd Bengaluru, Karnataka Apply on TimesJobs 18 hours agoFull–time · Candidate should possess excellent oral and written communication s...

    Full Time / Part Time

    Salary Estimated: 22K to 25K

    Jaipur, Rajasthan

    August 4, 2026


    Apply Now

  • Documents Verification Fresher Apply Now

    Overseeing the customer service process. • Resolving customer complaints brought to your attention. • Handling customer concerns and complaints in a timely manner. • Establishing a positive rapport with all clients and customers via phone. Requiremen...

    Full Time / Part Time

    Salary Estimated: 25K to 32K

    New Delhi, Delhi

    August 4, 2026


    Apply Now

  • Hr Recruiter (Fresher)

    We are looking for a motivated and result-oriented Recruiter to join our HR team. The ideal candidate will be responsible for managing the end-to-end recruitment cycle — from sourcing and screening candidates to coordinating interviews and ensuring a...

    Full Time / Part Time

    Salary Estimated: 19K to 22K

    Mumbai, Maharashtra

    August 4, 2026


    Apply Now

  • Telecaller Back Office Computer Operator Telesales BDE

    Job description • Hiring Admission Counselor who to good at, • Follow-ups with Existing inquiry and generate new Leads • Counsel them about the courses available. • Maintaining good relations with clients professionally • Excellent logical skills to ...

    Full Time / Part Time

    Salary Estimated: 24K to 31K

    Ahmedabad, Gujarat

    August 4, 2026


    Apply Now