Security Engineer - Product/Application Security
Chennai, India
Applications have closed
Poshmark is a leading social marketplace for new and secondhand style for women, men, kids, pets, home, and more. By combining the human connection of physical shopping with the scale, ease, and selection benefits of ecommerce, Poshmark makes buying and selling simple, social, and sustainable.
Security team at Poshmark is responsible for securing our application platform, cloud infrastructure, and IT systems to protect Poshmark and its 80 million Community members. As an Application Security Engineer, you will collaborate with other security and engineering teams on identifying vulnerabilities in our application while improving visibility and implementing application security best practices throughout SDLC.
Responsibilities
-
Participate in product requirement and technical design discussions to influence requirements and designs
-
Create application security and secure coding standards and educate developers
-
Integrate, enhance and implement devsecops tooling SAST, IAST, SCA and others as required to shift left security
-
Bake security into every stage of the software development lifecycle for Backend/Mobile/Web applications
-
Develop custom tools and automations that enable DevSecOps and SecOps
-
Manage and run penetration testing
-
Manage bug bounty programs
-
Mitigate identified vulnerabilities by providing and/or implementing technical solutions
6-Month Accomplishments
-
Bring in the security processes and culture for the product verticals
-
Perform penetration testing of applications and networks
-
Mature the security gating in SDLC
-
Define security requirements for development and testing
-
Triage and provide remediation solutions for critical vulnerabilities
12+ Month Accomplishments
-
Solid understanding of Poshmark
-
Able to provide tailored solutions relevant to Poshmark
-
Build partnerships with Engineering, other security verticals to drive security across products
-
Contribute to the overall application security and other security programs
-
Provide solutions and design recommendations and prioritize the security backlog
Requirements
-
2+ years of professional hands-on experience in application security
-
Strong foundation of security architecture, protocols, vulnerabilities, and countermeasures
-
Strong understanding of secure coding standards and security risks (e.g. OWASP, SANS and others).
-
Familiarity with cryptography primitives and fundamentals (e.g. SSL/TLS, PKI)
-
Demonstrated experience in programming languages (e.g. JRuby, Java, Kotlin, Swift, and/or JavaScript) and development tools (e.g. Gradle, Jenkins)
-
Experience with AWS or cloud environments and ability to recommend designs for
-
Strong attention to detail and accountability under minimal supervision
-
Strong growth mindset
-
Great communication skills
About Us
Poshmark is a leading social marketplace for new and secondhand style for women, men, kids, pets, home, and more. By combining the human connection of physical shopping with the scale, ease, and selection benefits of e-commerce, Poshmark makes buying and selling simple, social, and sustainable. Its community of more than 80 million registered users across the U.S., Canada, Australia, and India, is driving the future of commerce while promoting more sustainable consumption. For more information, please visit www.poshmark.com, and for company news and announcements, please visit investors.poshmark.com. You can also find Poshmark on Instagram, Facebook, Twitter, Pinterest, and YouTube.
Why Poshmark?
At Poshmark, we’re constantly challenging the status quo and are looking for innovative and passionate people to help shape the future of Poshmark. We’re disrupting the industry by combining social connections with e-commerce through data-driven solutions and the latest technology to optimize our platform. We’re nothing without our amazing team who deliver an unparalleled social shopping experience to the millions of people we connect each day.
We built Poshmark around four core values: 1) focus on people to create empowered communities that drive success; 2) together we grow to support each other to strive for our dreams; 3) lead with love to foster genuine connections built upon a foundation of respect; and 4) embrace your weirdness to accept and empower one another on their own unique journey. We’re invested in our team and community, working together to build an entirely new way to shop. That way, when we win, we all win together. Come help us build the most connected shopping experience ever. We will set you up with comprehensive global and in-country benefits to support you and your family needs.
Poshmark is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
View Poshmark's Job Applicant Privacy Policy here.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security AWS Cloud Cryptography DevSecOps E-commerce Ecommerce IAST Java JavaScript Kotlin OWASP Pentesting PKI Privacy SANS SAST SDLC SecOps TLS Vulnerabilities
Perks/benefits: Career development
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Product Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Senior Information Security Analyst jobs
- Open Cyber Security Specialist jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Cybersecurity Specialist jobs
- Open Senior Security Architect jobs
- Open Sr. Security Engineer jobs
- Open IT Security Engineer jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Application security-related jobs
- Open Agile-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open Malware-related jobs
- Open DevOps-related jobs
- Open Security Clearance-related jobs
- Open IDS-related jobs
- Open EDR-related jobs
- Open Forensics-related jobs
- Open CEH-related jobs
- Open Kubernetes-related jobs