Senior Application Security Engineer

3 Months ago • All levels • Cyber Security

Job Summary

Job Description

Senior Application Security Engineer with deep expertise in AppSec, proficient in Burp Suite, threat modelling and secure design principles. Experience in securing cloud-native applications and strong communication skills to articulate vulnerabilities. Passionate about security with a proven track record.
Must have:
  • AppSec Expertise
  • Burp Suite
  • Threat Modelling
  • Cloud Security
Good to have:
  • Security Automation
  • Penetration Testing
  • Vulnerability Management
  • Secure Coding Practices
Perks:
  • Competitive Salary
  • Health Insurance

Job Details

Job Title: – Senior Application Security Engineer 
Location: – Hyderabad/Bengaluru/Delhi NCR

About Tide

At Tide, we are building a finance platform designed to save small businesses time and money. We provide our members with business accounts and related banking services, but also a comprehensive set of connected administrative solutions from invoicing to accounting.
Launched in 2017, Tide is now used by over 1 million small businesses across the world and is available to UK, Indian and German SMEs. Headquartered in central London, with offices in Sofia, Hyderabad, Delhi, Berlin and Belgrade, Tide employs over 1,800 employees.  
Tide is rapidly growing, expanding into new markets and always looking for passionate and driven people. Join us in our mission to empower small businesses and help them save time and money.   

About the Team :

The Tide Security Engineering team is made up of three core areas: Product Security, Threat Detection & Response, and Identity.

Product Security (this role!) consists of application and cloud security experts. Their mission is to protect the products we build, covering everything from secure design reviews to threat modelling and penetration testing, ensuring security is embedded from the ground up.

Threat Detection & Response focuses on protecting the company by building a robust detection and automation platform. We’re proactive in our defence, constantly hacking ourselves to improve our security posture and staying ahead of emerging threats. Our goal is to make Tide resilient against the ever-evolving threat landscape.

Identity is responsible for managing Tide's staff identity platform, ensuring that access to systems and infrastructure is secure, seamless, and aligned with modern security practices. The team uses strategies like zero trust, multi-factor authentication, and granular role-based access controls to safeguard our internal operations.

While each area has its own focus, collaboration is key - it's why we share the same Slack channel and hold our standups together as one cohesive team, ensuring alignment and seamless communication across all security functions.

About the Role : 
First and foremost you will be passionate about security and resilient software development processes. You will enjoy hunting for vulnerabilities in our web and mobile applications and working with our engineering teams to remediate them strategically. You will be comfortable explaining security issues and concerns to product owners, engineers, VPs and executives and love the feeling you get when this results in them releasing a more resilient product. You will be a keen follower of all things Infosec and constantly be on the lookout for ways to apply new industry trends, tools and automations to your day-to-day role.

As a Senior Product Security Engineer you’ll:

  • Regularly dive deep into mobile, web app technologies in order to understand feature development and proactively hunt for vulnerabilities
  • Be proficient in securing cloud-native applications, ensuring that security best practices are applied consistently across our cloud environment
  • Be proficient in threat modelling and guide developers in secure design principles to prevent vulnerabilities from being introduced in the first place
  • Help remediate vulnerabilities through strategic initiatives, writing patches, or creating understandable and actionable vulnerability tickets.
  • Be the subject matter expert across a wide range of security areas, particularly in Application Security.
  • Make security invisible when possible, believing that gatekeeping and blocking product teams should be avoided in favour of enabling secure development.
  • Mentor and coach junior engineers, sharing your knowledge to help raise the security bar across the organisation
  • Leverage automation and security tools to seamlessly integrate security into our CI/CD pipelines, ensuring vulnerabilities are caught early without disrupting development.

What we are looking for : 

  • You have a breadth and depth of knowledge across AppSec; you’re expected to understand topics like why private keys should be stored in the Secure Enclave, the differences between URL Schemes and Universal Links, what presigned URLs are in the context of S3 and the safest storage mechanisms for modern browsers.
  • You know Burp Suite (or your favourite attack proxy) inside and out; bonus points if you’ve written or contributed to an extension that enhances its functionality.
  • You have excellent spoken and written communication skills to articulate vulnerabilities clearly and persuasively, advocating for their remediation even when faced with competing production pressures.
  • As a passionate senior security engineer, you have a blog, public speaking engagements, bug bounty profile, or a Git repository showcasing your work.
  • You’re comfortable writing proof-of-concept (POC) scripts to demonstrate your findings and their potential impact, as needed.
  • You have hands-on experience with securing cloud-native applications, ensuring that best practices are consistently applied.

What you’ll get in return: 

  • Competitive salary
  • Self & Family Health Insurance
  • Term & Life Insurance
  • OPD Benefits
  • Mental wellbeing through Plumm
  • Learning & Development Budget
  • WFH Setup allowance
  • 15 days of Privilege leaves
  • 12 days of Casual leaves
  • 12 days of Sick leaves
  • 3 paid days off for volunteering or L&D activities
  • Stock Options

Tidean Ways of Working 

At Tide, we champion a flexible workplace model that supports both in-person and remote work to cater to the specific needs of our different teams. 

While remote work is supported, we believe in the power of face-to-face interactions to foster team spirit and collaboration. Our offices are designed as hubs for innovation and team-building, where we encourage regular in-person gatherings to foster a strong sense of community. 

Tide is a place for everyone

At Tide, we believe that we can only succeed if we let our differences enrich our culture. Our Tideans come from a variety of backgrounds and experience levels. We consider everyone irrespective of their ethnicity, religion, sexual orientation, gender identity, family or parental status, national origin, veteran, neurodiversity or differently-abled status. We celebrate diversity in our workforce as a cornerstone of our success. Our commitment to a broad spectrum of ideas and backgrounds is what enables us to build products that resonate with our members’ diverse needs and lives. 

We are One Team and foster a transparent and inclusive environment, where everyone’s voice is heard.

Similar Jobs

Ness Digital - Lead Java Full-stack Engineer

Ness Digital

Timișoara, Timiș, Romania (Remote)
4 Weeks ago
N-iX - Middle Java Engineer (With AWS)

N-iX

Ukraine (Remote)
2 Weeks ago
PwC - IN_Associate_Azure Cloud Data Engineer_OneCloud _Advisory _Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Paytm - DevOps- Principal Engineer

Paytm

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Paytm - Senior QA Engineer - Mobile Apps/SDET

Paytm

Noida, Uttar Pradesh, India (On-Site)
3 Months ago
Axinous - Program Management Intern-SkillBridge (FedRAMP)

Axinous

Mobile, Alabama, United States (Remote)
3 Months ago
Palo Alto Networks - Prisma Cloud Solutions Architect - Healthcare

Palo Alto Networks

Phoenix, Arizona, United States (Remote)
2 Months ago
Palo Alto Networks - Solutions Consultant - CA State Government

Palo Alto Networks

Sacramento, California, United States (On-Site)
2 Months ago
Axinous - Snr Customer Success Manager, Germany

Axinous

Germany (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

PwC - ETIC, Cloud Infrastructure - Senior Associate

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
3 Months ago
Axinous - Staff Software Development Engineer (Backend)

Axinous

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Assystems - Développeur Junior - H/F

Assystems

Lyon, Auvergne-Rhône-Alpes, France (Hybrid)
3 Months ago
Keywords Studios (Player Support) - Solutions Architect

Keywords Studios (Player Support)

Montreal, Quebec, Canada (Remote)
2 Months ago
Hawk Eye Innovations - Frontend Test Automation Engineer

Hawk Eye Innovations

Budapest, Hungary (On-Site)
3 Weeks ago
Rockstar Games - Lead Product Manager, Security

Rockstar Games

San Diego, California, United States (On-Site)
1 Month ago
Assystems - Senior Software Engineer

Assystems

Gurugram, Haryana, India (On-Site)
3 Months ago
Luxoft - Senior ETL Developer

Luxoft

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
2 Months ago
InMobiInMobi - SDE III - Devops

InMobiInMobi

Bengaluru, Karnataka, India (On-Site)
4 Months ago
NextGen Healthcare India - Data Engineer with AI

NextGen Healthcare India

Bengaluru, Karnataka, India (Remote)
5 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

ION - Smalltalk Developer - 708

ION

India (On-Site)
3 Months ago
Kwalee - Product Analyst

Kwalee

Bengaluru, Karnataka, India (On-Site)
1 Week ago
Laespace Design Studio - Furniture Designer

Laespace Design Studio

Hyderabad, Telangana, India (On-Site)
4 Months ago
DeepSight AI Labs   - Intern/Computer Vision Engineer

DeepSight AI Labs

Gurugram, Haryana, India (On-Site)
8 Months ago
Minteworld - Technical Recruiter

Minteworld

Bengaluru, Karnataka, India (Remote)
4 Months ago
Assystems - Draughts Person / Designer - Solar (Electrical)

Assystems

Gurugram, Haryana, India (On-Site)
3 Months ago
Revvity - Software Test Engineer

Revvity

Thane, Maharashtra, India (Hybrid)
8 Months ago
Intel Corporation - Research Scientist

Intel Corporation

Bengaluru, Karnataka, India (On-Site)
2 Months ago
5th Ocean Studios 🔜 IGDC - 2D Generalist

5th Ocean Studios 🔜 IGDC

Hyderabad, Telangana, India (On-Site)
4 Months ago
Accor - Talent and Culture Manager

Accor

Maharashtra, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Playtech - Network Security Engineer

Playtech

Sofia, Sofia City Province, Bulgaria (On-Site)
2 Months ago
Redhorse Corp - Information System Security Officer (ISSO)

Redhorse Corp

Fort Belvoir, Virginia, United States (On-Site)
2 Months ago
Trend Micro - (Sr.) Cloud Developer (Vision One)

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
Netflix - Manager, Content Security Vendor Program

Netflix

Los Angeles, California, United States (On-Site)
3 Months ago
Google - Staff Software Engineer, Security/Privacy, Google Cloud Security and Privacy

Google

San Francisco, California, United States (On-Site)
3 Months ago
Reversing Labs - Application Security Architect

Reversing Labs

Zagreb, Croatia (Hybrid)
2 Months ago
USE Insider - Security Engineer - Red Team

USE Insider

Türkiye (Remote)
3 Months ago
PwC - CD&E-Quality Assurance SOC Analyst-Senior Associate-Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Nintendo - Security Engineer

Nintendo

Redmond, Washington, United States (Hybrid)
2 Months ago
Zuora - Senior Security Engineer

Zuora

Bengaluru, Karnataka, India (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded