Security Engineer III
Meesho
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
3,188 open security roles across 416 companies are on ApplySarthi right now, most of them in Bengaluru (119), Hyderabad (24), Pune (22).
- Security Engineer (Fractional)Jobgether
- Cloud Security Engineer - Remote within UKImmersivelabs
- Director, Sales - Data & AI Securityveeamsoftware
- Security Consultant-Infrastructure SecurityIBM
- Senior Software Engineer, Security Services and Observability, Amazon Web ServicesAmazon Web Services
What security roles keep asking for: AWS (30%), Python (27%), SIEM (14%), CI/CD (14%), Azure (13%), GCP (13%), IAM (13%) — counted across their open postings here.
Security Engineer jobs in Bengaluru · Security Engineer jobs in India · Remote Security Engineer jobs · AWS jobs · Android jobs · CI/CD jobs · Docker jobs
Meesho has 61 open roles listed here.
- Lead Copybengaluru
- Senior Copywriterbengaluru
- Associate - Operationsbengaluru
- Senior Product Managerbengaluru
- Deputy Manager - Logistics Intelligencebengaluru
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for security roles keep coming back to AWS, Python, SIEM, CI/CD. Practise those questions before you sit with Meesho.
Questions you are likely to be asked
- Why do you want to join Meesho?
- What is your experience with LLMs? Tell me one thing you learned the hard way.
- Walk me through how code gets from a commit to production where you work.
- Tell me about an outage you handled. What did you learn from it?
- How do you decide what to monitor, and what should wake someone up at night?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Security Engineer III at Meesho interview free →About the Team The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. After all, when 5% of Indian households shop with us, it’s important to build resilient systems to manage millions of orders every day. We’ve done this – with zero downtime! 😎 Sounds impossible? Well, that’s the kind of Engineering muscle that has helped Meesho become the e-commerce giant it is today. We value speed over perfection, and see failures as opportunities to become better. We’ve taken steps to inculcate a strong ‘Founder’s Mindset’ across our engineering teams, making us grow and move fast. We place special emphasis on the continuous growth of each team member - and we do this with regular 1-1s and open communication. As a Security Engineer, you will be part of self-starters who thrive on teamwork and constructive feedback. We know how to party as hard as we work! If we aren’t building unparalleled tech solutions, you can find us debating the plot points of our favorite books and games – or even gossiping over chai. So, if a day filled with building impactful solutions with a fun team sounds appealing to you, join us. About the Role As a Security Engineer 4, your role is integral in ensuring the security of our products throughout their development lifecycle. You will be involved from the very beginning, participating in threat modeling and design reviews to identify potential risks early. You'll also integrate and manage SAST tools within our CI/CD pipeline, ensuring continuous security testing as code evolves. Additionally, you'll lead and conduct vulnerability assessments and penetration testing (VAPT) to proactively uncover and address security vulnerabilities before they reach production. What you will do: Security Architecture & Threat Modeling: Lead threat modeling and secure design reviews for complex, multi-service features, and partner with engineering to drive the resulting security requirements into production. Contribute security expertise to architecture discussions and help shape secure-by-default patterns that other teams adopt. Application & Offensive Security: Own and conduct advanced security assessments (VAPT) across web platforms, APIs, and mobile applications (iOS & Android), including the business-logic, authentication, authorization, and multi-tenancy classes of issues that automated tooling misses. Plan and run red team and purple team exercises and translate findings into durable architectural fixes, not just point remediations. Manual Code Review: Perform in-depth manual and automated source code reviews to identify security-critical bugs, and work with developers to eliminate whole classes of vulnerabilities at the framework or platform level. DevSecOps & Automation: Own the integration, tuning, and scaling of security tooling (SAST, DAST, SCA, secret scanning, container scanning) in CI/CD. Design and build custom security tooling and automation that scales security across engineering teams, and contribute to supply-chain and pipeline-hardening initiatives. Cloud Security: Drive security reviews and hardening of cloud-native workloads (AWS, Kubernetes/EKS, containers), covering identity and access, tenant isolation, network controls, and secrets management. AI/LLM Security: Contribute to securing Meesho's AI-powered features and workflows, including threat modeling of LLM and RAG integrations, prompt-injection and data-leakage controls, tenant isolation for AI features, and secure patterns for AI in the SDLC. Vulnerability & Bug Bounty Management: Own vulnerability lifecycle and remediation tracking for your areas, and help run the self-managed bug bounty program including triage, researcher engagement, and driving fixes to closure. Security Metrics: Define and track security metrics (coverage, remediation SLAs, mean time to remediate) for your areas and use them to drive engineering behaviour and prioritisation. Security Partnership & Mentorship: Act as a security subject matter expert for developers through secure-coding guidance, code reviews, and consultations. Mentor SE1 and SE2 engineers, review their work, and help level up the team's technical depth. Security Culture & Compliance: Drive security culture initiatives (Security Champions, developer awareness, phishing simulations) and contribute to risk and compliance efforts such as ISO 27001 readiness, TPRM, and BCP/BIA. What you will need: Experience: 5-7 years of hands-on experience in product security or application security, with a demonstrated track record of owning security workstreams end to end. Education: A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is preferred. Core Technical Depth: Proven ability to lead threat modeling sessions and drive findings into the SDLC across cross-functional teams. Strong proficiency performing security assessments on web applications and APIs, with deep command of the OWASP Top 10 (Web and API) and complex authentication, authorization, session management, and business-logic vulnerabilities. Hands-on manual source code review experience, with the ability to read and reason about code in languages such as Java, Node.js, Python, and React. Demonstrated experience with DevSecOps, integrating and tuning security tooling in CI/CD pipelines, and building custom security automation. Proficiency with cloud security on AWS or GCP, including their native security tooling, and working knowledge of Docker and Kubernetes security. Offensive Security: Demonstrated experience planning and executing red team or purple team exercises, and translating real-world attack paths into concrete defensive improvements. Mobile Security: Working knowledge of mobile application security assessments for Android and iOS, familiarity with the OWASP MASVS framework and mobile-specific vulnerabilities (insecure webview, insecure deeplink, insecure data storage, flawed cryptography), and exposure to tools such as Frida, Objection, Drozer, and MobSF. General Skills & Acumen: Strong analytical and problem-solving skills, with sound judgment on risk prioritisation at scale. Excellent communication skills, with the ability to explain complex security issues to both technical and non-technical audiences and to influence engineering decisions without direct authority. Ability to mentor and uplevel earlier-career security engineers. Bonus Points: Relevant certifications such as OSCP, OSWE, GWAPT, or CKS. Active participation in public or private bug bounty programs, published CVEs, or security research. Experience speaking at meetups or conferences. Exposure to AI/LLM security (prompt injection, RAG security, OWASP LLM Top 10) and software supply-chain security. Exposure to India regulatory requirements such as the DPDP Act and CERT-In directions.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- AM/ Manager - Risk & Decision ScienceMeesho · bengaluru
- Assistant Manager - Business FinanceMeesho · bengaluru
- Assistant Manager - Performance MarketingMeesho · bengaluru
- Assistant Manager Finance – Logistics IntelligenceMeesho · bengaluru
- Associate Compliance ManagerMeesho · bengaluru
- Associate Director - Business FinanceMeesho · bengaluru
- Associate Director - Commerce PlatformMeesho · bengaluru
- Cluster Head ( Security & Investigation)Meesho · jaipur
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on lever · posted 2026-10-07. ApplySarthi collects openings and links to application pages; the role is advertised by Meesho, not by us.