1,334,991open jobs
78,300companies
214,577added this week
Browse all
Salary
≈ $16k – $39k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Middle · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 7, 2026. First seen by Alion on Oct 7, 2026. Meesho scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Meesho is an Indian e-commerce company headquartered in Bengaluru and founded in 2015. The company operates an online marketplace that enables small businesses and individual entrepreneurs to sell products such as apparel, home goods, and electronics directly to consumers. Originally established as a social commerce platform facilitating sales through networks like WhatsApp and Facebook, it has evolved into a large-scale retail ecosystem serving millions of users across India.

About the Team

The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. After all, when 5% of Indian households shop with us, it’s important to build resilient systems to manage millions of orders every day. We’ve done this - with zero downtime! Sounds impossible? Well, that’s the kind of Engineering muscle that has helped Meesho become the e-commerce giant it is today. We value speed over perfection, and see failures as opportunities to become better. We’ve taken steps to inculcate a strong ‘Founder’s Mindset’ across our engineering teams, making us grow and move fast. We place special emphasis on the continuous growth of each team member - and we do this with regular 1-1s and open communication. As a Security Engineer, you will be part of self-starters who thrive on teamwork and constructive feedback. We know how to party as hard as we work! If we aren’t building unparalleled tech solutions, you can find us debating the plot points of our favorite books and games - or even gossiping over chai. So, if a day filled with building impactful solutions with a fun team sounds appealing to you, join us.

About the Role

As a Security Engineer 3, you are a senior individual contributor who owns security outcomes end to end across one or more product areas. You operate with limited supervision, set the technical approach for your workstreams, and are a trusted second voice in design and architecture discussions. Beyond finding and fixing vulnerabilities, you drive security initiatives to closure across engineering teams, raise the bar on how we build securely, and mentor earlier-career engineers on the team. You will combine deep hands-on offensive and defensive skills with the judgment to prioritise what matters most for a platform operating at Meesho's scale.

What you will do

  • Security Architecture & Threat Modeling: Lead threat modeling and secure design reviews for complex, multi-service features, and partner with engineering to drive the resulting security requirements into production. Contribute security expertise to architecture discussions and help shape secure-by-default patterns that other teams adopt.
  • Application & Offensive Security: Own and conduct advanced security assessments (VAPT) across web platforms, APIs, and mobile applications (iOS & Android), including the business-logic, authentication, authorization, and multi-tenancy classes of issues that automated tooling misses. Plan and run red team and purple team exercises and translate findings into durable architectural fixes, not just point remediations.
  • Manual Code Review: Perform in-depth manual and automated source code reviews to identify security-critical bugs, and work with developers to eliminate whole classes of vulnerabilities at the framework or platform level.
  • DevSecOps & Automation: Own the integration, tuning, and scaling of security tooling (SAST, DAST, SCA, secret scanning, container scanning) in CI/CD. Design and build custom security tooling and automation that scales security across engineering teams, and contribute to supply-chain and pipeline-hardening initiatives.
  • Cloud Security: Drive security reviews and hardening of cloud-native workloads (AWS, Kubernetes/EKS, containers), covering identity and access, tenant isolation, network controls, and secrets management.
  • AI/LLM Security: Contribute to securing Meesho's AI-powered features and workflows, including threat modeling of LLM and RAG integrations, prompt-injection and data-leakage controls, tenant isolation for AI features, and secure patterns for AI in the SDLC.
  • Vulnerability & Bug Bounty Management: Own vulnerability lifecycle and remediation tracking for your areas, and help run the self-managed bug bounty program including triage, researcher engagement, and driving fixes to closure.
  • Security Metrics: Define and track security metrics (coverage, remediation SLAs, mean time to remediate) for your areas and use them to drive engineering behaviour and prioritisation.
  • Security Partnership & Mentorship: Act as a security subject matter expert for developers through secure-coding guidance, code reviews, and consultations. Mentor SE1 and SE2 engineers, review their work, and help level up the team's technical depth.
  • Security Culture & Compliance: Drive security culture initiatives (Security Champions, developer awareness, phishing simulations) and contribute to risk and compliance efforts such as ISO 27001 readiness, TPRM, and BCP/BIA.

What you will need

    Experience: 5-7 years of hands-on experience in product security or application security, with a demonstrated track record of owning security workstreams end to end.

    Education: A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is preferred.

    Core Technical Depth:

  • Proven ability to lead threat modeling sessions and drive findings into the SDLC across cross-functional teams.

  • Strong proficiency performing security assessments on web applications and APIs, with deep command of the OWASP Top 10 (Web and API) and complex authentication, authorization, session management, and business-logic vulnerabilities.

  • Hands-on manual source code review experience, with the ability to read and reason about code in languages such as Java, Node.js, Python, and React.

  • Demonstrated experience with DevSecOps, integrating and tuning security tooling in CI/CD pipelines, and building custom security automation.

  • Proficiency with cloud security on AWS or GCP, including their native security tooling, and working knowledge of Docker and Kubernetes security.

  • Offensive Security: Demonstrated experience planning and executing red team or purple team exercises, and translating real-world attack paths into concrete defensive improvements.

    Mobile Security: Working knowledge of mobile application security assessments for Android and iOS, familiarity with the OWASP MASVS framework and mobile-specific vulnerabilities (insecure webview, insecure deeplink, insecure data storage, flawed cryptography), and exposure to tools such as Frida, Objection, Drozer, and MobSF.

    General Skills & Acumen:

  • Strong analytical and problem-solving skills, with sound judgment on risk prioritisation at scale.

  • Excellent communication skills, with the ability to explain complex security issues to both technical and non-technical audiences and to influence engineering decisions without direct authority.

  • Ability to mentor and uplevel earlier-career security engineers.

Bonus Points

  • Relevant certifications such as OSCP, OSWE, GWAPT, or CKS.

  • Active participation in public or private bug bounty programs, published CVEs, or security research.

  • Experience speaking at meetups or conferences.

  • Exposure to AI/LLM security (prompt injection, RAG security, OWASP LLM Top 10) and software supply-chain security.

  • Exposure to India regulatory requirements such as the DPDP Act and CERT-In directions.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,334,991 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Bengaluru
≈ $15k – $34k per year (Estimated) • In office • Full-Time • 3+ years exp • Pune
Python
DevOps
Rest API
SLI/SLO/SLA
BGP
OSPF
Cybersecurity
Zscaler
Apply
≈ $13k – $35k per year (Estimated) • In office • 1+ year exp • Bachelor's Degree • Gurgaon
Python
PowerShell
Cybersecurity
Threat Modeling
Apply
≈ $13k – $35k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
DevOps
GCP
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
DNS
Cybersecurity
ISO 27001
OWASP Top 10
PCI DSS
OWASP SAMM
PKI
OWASP
Apply
≈ $15k – $33k per year (Estimated) • Remote (India) • Full-Time • 3+ years exp • Bachelor's Degree • Pune
Python
PowerShell
AI/ML
Function Calling
AI Agents
LLM
RAG
Copilot Studio
DevOps
Azure
IAM
Cybersecurity
Zero Trust
Least Privilege
Microsoft Entra ID
Active Directory
Management
ITSM
Apply
≈ $14k – $33k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Gurgaon
DevOps
Azure
AWS
Linux
Windows
Unix
Cybersecurity
ISO 27001
PCI DSS
GDPR
HIPAA
PKI
SIEM
Apply
In office • Contractor • Singapore
JavaScript
Java
SQL
Node JS
Java
Maven
Spring Boot
DevOps
Rest API
Azure
CI/CD
AWS
Management
Agile
Apply
$58k – $100k per year (gross) • In office • Full-Time • Vilnius
Python
PowerShell
Bash
DevOps
Terraform
Ansible
GCP
Zabbix
VMWare
Azure
CI/CD
AWS
Kubernetes
Grafana
Configuration Management
Proxmox VE
Hyper-V
Linux
Windows
DNS
Cybersecurity
SIEM
Management
ITIL
ITSM
Apply
≈ $17k – $43k per year (Estimated) • In office • Full-Time • 5+ years exp • Master's Degree • Pune
Python
Java
Kotlin
SQL
Java
Maven
DevOps
GCP
OpenShift
Jenkins
Docker
Kubernetes
TeamCity
Unix
Management
Agile
Scrum
QA
Cucumber
Apply
≈ $20k – $49k per year (Estimated) • In office • Full-Time • Master's Degree • Pune
JavaScript
Java
TypeScript
SQL
Java
Spring Framework
Spring Boot
Spring Security
Spring Cloud
Hazelcast
Apache Tomcat
Databases
MySQL
PostgreSQL
Redis
Oracle
Memcached
Frontend
Angular
DevOps
Rest API
Terraform
GCP
CI/CD
Jenkins
Docker
Kubernetes
Google GKE
Apache HTTP Server
Management
Confluence
SharePoint
Agile
Scrum
Apply
≈ $23k – $57k per year (Estimated) • In office • Full-Time • 18+ years exp • Pune
Python
Java
SQL
Python
Flask
FastAPI
Databases
PostgreSQL
Redis
Snowflake
Neo4j
Databricks
Pinecone
Google BigQuery
BigQuery
AI/ML
Copilot
LangGraph
Weights & Biases
LangChain
Spark
Claude Code
Jupyter Notebook
MLFlow
Vertex AI
Scikit-learn
AI Agents
TensorFlow
PyTorch
Gemini
Google ADK
Hugging Face
LLM Guardrails
Machine Learning
DevOps
GCP
Kubernetes
Google GKE
AIOps
GitHub
Analytics
Looker
Apply
≈ $26k – $61k per year (Estimated) • In office • Full-Time • 10+ years exp • Bengaluru
Python
JavaScript
Java
Node JS
AI/ML
AI Agents
Hallucination
Red Teaming
LLM Guardrails
NIST AI RMF
DevOps
GCP
AWS
Docker
Self-Healing
Cybersecurity
Zero Trust
Threat Modeling
Apply
Security Engineer IV 2 years ago
≈ $20k – $43k per year (Estimated) • In office • Full-Time • 7+ years exp • Bengaluru
Python
JavaScript
Java
Node JS
Frontend
React.js
DevOps
GCP
CI/CD
Jenkins
Git
AWS
Docker
Cybersecurity
Threat Modeling
Apply
Senior Copywriter 3 days ago
≈ $20k – $56k per year (Estimated) • In office • 3+ years exp • Bengaluru
Apply
≈ $8.5k – $21k per year (Estimated) • In office • 1+ year exp • Bengaluru
Analytics
Microsoft Excel
Apply
Manager Partnership 7 days ago
≈ $8k – $23k per year (Estimated) • In office • Full-Time • 2+ years exp • Bengaluru
Apply
SRE Engineer 7 hours ago
≈ $19k – $41k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Python
DevOps
Terraform
Ansible
Azure
AWS
Kubernetes
HPC
Linux
Management
Agile
Apply
≈ $19k – $42k per year (Estimated) • In office • Full-Time • 5+ years exp • Master's Degree • Bengaluru
Python
C++
MATLAB
Robotics
Digital Twin
Apply
≈ $18k – $44k per year (Estimated) • In office • 4+ years exp • Bengaluru
Python
Go
JavaScript
Java
C++
Node JS
AI/ML
Model Context Protocol
AI Agents
Machine Learning
DevOps
Kubernetes
IAM
Apply
Data Engineer II 7 hours ago
≈ $15k – $35k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
Python
SQL
Databases
Databricks
Delta Lake
Google BigQuery
BigQuery
AI/ML
dbt
DevOps
CI/CD
Git
Management
Agile
Scrum
Apply
In office • Full-Time • Bengaluru
Management
Agile
Apply
See all jobs
This is one of many
1,334,991 more open roles from verified company boards, updated every day.