Security Engineer-2

Cashfree Payments
India
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 3+ yearsEducation: bachelorsSkills: ["Interpersonal skills","Communication","Problem-solving"]

Identify and validate security vulnerabilities across Cashfree products through research, exploitation demonstrations, and secure design reviews. Partner with developers to scope assessments, define workarounds/mitigations, and embed secure coding practices across sprint cycles and the DevOps pipeline. Lead threat-modeling enablement, run workshops and security tech-talks, and develop training content for developers and QA while automating security testing to improve assessment productivity.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cashfree Payments
Cashfree Payments
6 hours ago

Security Engineer-2

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Identify and validate security vulnerabilities across Cashfree products through research, exploitation demonstrations, and secure design reviews. Partner with developers to scope assessments, define workarounds/mitigations, and embed secure coding practices across sprint cycles and the DevOps pipeline. Lead threat-modeling enablement, run workshops and security tech-talks, and develop training content for developers and QA while automating security testing to improve assessment productivity.
Location: India
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Examine products for vulnerabilities, demonstrate exploitability and risks, and stay ahead of emerging threats through independent research.
  • •Collaborate with development teams on threat modeling and secure design reviews, and ensure mitigation workarounds are implemented per policy.
  • •Prioritize critical security defects during sprints and identify/mitigate issues in the sprint execution cycle.
  • •Integrate and automate SAST in the DevOps pipeline, and build secure coding principles across the development community.
  • •Create and deliver developer/QA security training content and run workshops/security tech-talks to disseminate security knowledge.

Key Requirements

  • •3+ years of relevant engineering or security assessment experience in application security.
  • •Strong knowledge of vulnerability classes including cross-site scripting, SQL injection, CSRF, cryptographic weaknesses, and code injection.
  • •Experience with threat modeling and vulnerability/risk classification, including pre-assessment architectural and API analysis for white-box/grey-box assessments.
  • •Familiarity with S-SDLC/CICD and QA processes in an in-house engineering organization.
  • •Good programming/scripting knowledge (Java, Ruby, Python) and ability to apply offensive and defensive thinking for security assessments and pen-testing tasks.
Experience:3+ yearsApplication securitySecurity assessments
Education:Bachelor's in Computer Science, Electrical, or Computer Engineering
Skills:Interpersonal skillsCommunicationProblem-solving
Tech Stack:JavaRubyPythonGoNode.jsSASTDevOpsCloudService meshesMicro-servicesJVM

Company Brief

Cashfree Payments
Provides payment gateway and payouts infrastructure for businesses, enabling online payments, vendor disbursements, and recurring collections. Serves merchants with APIs, checkout tools, banking integrations, and payment processing across cards, UPI, net banking, and wallets.
Industry: Payments
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Bengaluru, India
Founded: 2015
WebsiteLinkedIn