Role Summary:
As an Application Security Engineer at JioStar, you will play a critical role in securing our applications, products, and user data across a large-scale, cloud-native streaming ecosystem. You will work closely with engineering, product, and security teams to embed security throughout the software development lifecycle, identify and remediate vulnerabilities, and drive secure-by-design practices across web, mobile, and backend applications.
This role requires strong expertise in application security, secure coding practices, security testing, and threat modeling, along with the ability to collaborate with engineering teams to build secure and resilient products at scale.
About Us:
Perched firmly at the nucleus of spellbinding content and innovative technology, JioStar is a leading global media & entertainment company that is reimagining the way audiences consume entertainment and sports. Its television network and streaming service together reach more than 750 million viewers every week, igniting the dreams and aspirations of hundreds of million people across geographies.
Key Responsibilities:
Drive application security across the software development lifecycle, from design and development to deployment and production
Conduct security assessments and identify vulnerabilities across web, mobile, APIs, backend services, and other application components
Perform and support application security testing, including SAST, DAST, SCA, API security testing, and penetration testing
Conduct threat modeling and security reviews for new features, products, and architectural changes, and provide actionable remediation recommendations
Partner with engineering and product teams to identify security risks and implement secure-by-design and secure-by-default practices
Review application architecture, design, and code to identify security weaknesses and recommend appropriate security controls
Help define and maintain secure coding standards, application security guidelines, and security best practices across engineering teams
Work with development teams to triage, prioritize, and remediate vulnerabilities based on severity, business impact, and exploitability
Integrate security tools and automated security checks into CI/CD pipelines to enable continuous security testing and shift-left security practices
Develop automation and tooling using Python, Shell, or similar languages to improve application security processes and scale security assessments
Assess third-party libraries, dependencies, APIs, and open-source components for security risks and vulnerabilities
Support security incident investigations by analysing application logs, attack patterns, vulnerabilities, and potential areas of compromise
Collaborate with engineering teams to address security risks related to authentication, authorization, session management, encryption, data protection, and API security
Contribute to security reviews for web and mobile applications, including identifying common vulnerabilities such as OWASP Top 10 and OWASP API Security risks
Help prepare security documentation, risk assessments, remediation reports, and evidence required for audits and compliance activities
Stay updated on emerging application security threats, attack techniques, vulnerabilities, and industry best practices, and translate them into actionable security improvements
Skills and attributes for success:
Hands-on experience in Application Security, Product Security, or Software Security Engineering
Strong understanding of web, mobile, API, and backend application security
Good understanding of OWASP Top 10, OWASP API Security Top 10, secure coding practices, and common application vulnerabilities
Experience with application security testing tools and methodologies, including SAST, DAST, SCA, API security testing, and penetration testing
Experience with threat modeling, security architecture reviews, and secure SDLC practices
Familiarity with common authentication and authorization mechanisms, encryption, API security, and data protection principles
Experience integrating security tools and controls into CI/CD and DevSecOps workflows
Strong scripting/programming skills in Python, Shell, Java, JavaScript, or similar languages
Experience with vulnerability management, security risk assessment, and remediation tracking
Strong analytical, troubleshooting, problem-solving, and communication skills
Ability to work closely with engineering and product teams and influence secure development practices across the organization
Preferred Education and Experience:
Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field; a Master’s degree is a plus
3-6 years of experience in Application Security, Product Security, Security Engineering, or a related field
Experience securing consumer-facing web, mobile, API, or large-scale digital products is preferred
Experience working with fast-paced product engineering teams or media/OTT platforms is an added advantage
Relevant security certifications such as OSCP, CEH, CSSLP, or equivalent are a plus

