Skip to content

Open nowPosted 10 hours ago

Security Engineer III

Meesho60 open roles

Where
Bangalore, Karnataka
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer IIIMeesho · Bangalore, Karnataka
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Meesho's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Meesho postings stay open a median of 2 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 10 hours ago

Meesho median: 2 days open

The posting

About the Team

The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. After all, when 5% of Indian households shop with us, it’s important to build resilient systems to manage millions of orders every day. We’ve done this – with zero downtime! 😎 Sounds impossible? Well, that’s the kind of Engineering muscle that has helped Meesho become the e-commerce giant it is today. We value speed over perfection, and see failures as opportunities to become better. We’ve taken steps to inculcate a strong ‘Founder’s Mindset’ across our engineering teams, making us grow and move fast. We place special emphasis on the continuous growth of each team member - and we do this with regular 1-1s and open communication. As a Security Engineer, you will be part of self-starters who thrive on teamwork and constructive feedback. We know how to party as hard as we work! If we aren’t building unparalleled tech solutions, you can find us debating the plot points of our favorite books and games – or even gossiping over chai. So, if a day filled with building impactful solutions with a fun team sounds appealing to you, join us.

About the Role

As a Security Engineer 3, you are a senior individual contributor who owns security outcomes end to end across one or more product areas. You operate with limited supervision, set the technical approach for your workstreams, and are a trusted second voice in design and architecture discussions. Beyond finding and fixing vulnerabilities, you drive security initiatives to closure across engineering teams, raise the bar on how we build securely, and mentor earlier-career engineers on the team. You will combine deep hands-on offensive and defensive skills with the judgment to prioritise what matters most for a platform operating at Meesho's scale.

What you will do

  • Security Architecture & Threat Modeling: Lead threat modeling and secure design reviews for complex, multi-service features, and partner with engineering to drive the resulting security requirements into production. Contribute security expertise to architecture discussions and help shape secure-by-default patterns that other teams adopt.
  • Application & Offensive Security: Own and conduct advanced security assessments (VAPT) across web platforms, APIs, and mobile applications (iOS & Android), including the business-logic, authentication, authorization, and multi-tenancy classes of issues that automated tooling misses. Plan and run red team and purple team exercises and translate findings into durable architectural fixes, not just point remediations.
  • Manual Code Review: Perform in-depth manual and automated source code reviews to identify security-critical bugs, and work with developers to eliminate whole classes of vulnerabilities at the framework or platform level.
  • DevSecOps & Automation: Own the integration, tuning, and scaling of security tooling (SAST, DAST, SCA, secret scanning, container scanning) in CI/CD. Design and build custom security tooling and automation that scales security across engineering teams, and contribute to supply-chain and pipeline-hardening initiatives.
  • Cloud Security: Drive security reviews and hardening of cloud-native workloads (AWS, Kubernetes/EKS, containers), covering identity and access, tenant isolation, network controls, and secrets management.
  • AI/LLM Security: Contribute to securing Meesho's AI-powered features and workflows, including threat modeling of LLM and RAG integrations, prompt-injection and data-leakage controls, tenant isolation for AI features, and secure patterns for AI in the SDLC.
  • Vulnerability & Bug Bounty Management: Own vulnerability lifecycle and remediation tracking for your areas, and help run the self-managed bug bounty program including triage, researcher engagement, and driving fixes to closure.
  • Security Metrics: Define and track security metrics (coverage, remediation SLAs, mean time to remediate) for your areas and use them to drive engineering behaviour and prioritisation.
  • Security Partnership & Mentorship: Act as a security subject matter expert for developers through secure-coding guidance, code reviews, and consultations. Mentor SE1 and SE2 engineers, review their work, and help level up the team's technical depth.
  • Security Culture & Compliance: Drive security culture initiatives (Security Champions, developer awareness, phishing simulations) and contribute to risk and compliance efforts such as ISO 27001 readiness, TPRM, and BCP/BIA.

What you will need

  • Proven ability to lead threat modeling sessions and drive findings into the SDLC across cross-functional teams.
  • Strong proficiency performing security assessments on web applications and APIs, with deep command of the OWASP Top 10 (Web and API) and complex authentication, authorization, session management, and business-logic vulnerabilities.
  • Hands-on manual source code review experience, with the ability to read and reason about code in languages such as Java, Node.js, Python, and React.
  • Demonstrated experience with DevSecOps, integrating and tuning security tooling in CI/CD pipelines, and building custom security automation.
  • Proficiency with cloud security on AWS or GCP, including their native security tooling, and working knowledge of Docker and Kubernetes security.
  • Strong analytical and problem-solving skills, with sound judgment on risk prioritisation at scale.
  • Excellent communication skills, with the ability to explain complex security issues to both technical and non-technical audiences and to influence engineering decisions without direct authority.
  • Ability to mentor and uplevel earlier-career security engineers.

Bonus Points

  • Relevant certifications such as OSCP, OSWE, GWAPT, or CKS.
  • Active participation in public or private bug bounty programs, published CVEs, or security research.
  • Experience speaking at meetups or conferences.
  • Exposure to AI/LLM security (prompt injection, RAG security, OWASP LLM Top 10) and software supply-chain security.
  • Exposure to India regulatory requirements such as the DPDP Act and CERT-In directions.

About us

Welcome to Meesho, where every story begins with a spark of inspiration and a dash of entrepreneurial spirit. We're not just a platform; we're your partner in turning dreams into realities.

Curious about life at Meesho? Explore our Glassdoor - our people have a lot to say and they've helped us become a loved workplace in India.

Our Mission

Democratising internet commerce for everyone — Meesho (Meri Shop) started with a single idea in mind: to be an e-commerce destination for Indian consumers and to enable small businesses to succeed online.

We provide our sellers with benefits such as zero commission and affordable shipping solutions in the market. Today, sellers nationwide are growing their businesses by tapping into Meesho’s large and diverse customer base, state-of-the-art tech infrastructure, and pan-India logistics network through trusted third-party partners.

Affordable, relatable merchandise that mirrors local markets has helped us connect with internet users and serve customers across urban, semi-urban, and rural India. Our unique business model and continuous innovation have established us as a part of India’s e-commerce ecosystem.

Culture and Total Rewards

Our focus is on cultivating a dynamic workplace characterized by high impact and performance excellence. We prioritize a people-centric culture, dedicated to hiring and developing exceptional talent.

Total rewards at Meesho comprise a comprehensive set of elements — monetary, non-monetary, tangible, and intangible. Our 9 guiding principles, or "Mantras," are the backbone of how we operate, influencing everything from recognition and evaluation to growth discussions. Daily rituals and processes like “Problem First Mindset,” “Listen or Die,” our Internal Mobility Program, Talent Reviews, and Continuous Performance Management embody these principles.

We offer competitive compensation — both cash and equity-based — tailored to job roles, individual experience, and skill, along with employee-centric benefits and a supportive work environment. Our holistic wellness program, MeeCare, includes benefits across physical, mental, financial, and social wellness. This includes extensive medical insurance for employees and their families, wellness initiatives like telehealth, wellness events, and fitness-related perks.

To support work-life balance, we offer generous leave policies, parental support, retirement benefits, and learning and development assistance. Through personalized recognition, gratitude for stretched work, and engaging activities, we promote employee delight at the workplace. Additional benefits such as salary advance support, relocation assistance, and flexible benefit plans further enrich the Meesho experience.

At Meesho, we are committed to creating an inclusive and accessible workplace where every individual can thrive. In compliance with the Rights of Persons with Disabilities Act, 2016, we uphold the following principles:

  • Equal Opportunity: We ensure that employment opportunities are never denied on the grounds of disability if the candidate is otherwise competent to perform the job.
  • Accessible Workplace: Our facilities are designed to be fully accessible, with amenities and assistive devices provided to support differently abled individuals in their work.
  • Inclusive Hiring Process: We adopt a transparent and non-discriminatory selection process, including providing application forms in alternate formats and offering reasonable accommodations during interviews upon request.
  • Career Growth: We provide adequate training post-recruitment and pre-promotion, with training materials available in accessible formats to enable equal career progression.
  • Support & Confidentiality: A dedicated liaison officer/committee addresses concerns and grievances, while maintaining strict confidentiality of disability-related information.
  • Awareness & Inclusion: We conduct awareness programs to promote a culture of inclusivity across the organization.

Meesho welcomes applicants and employees of all abilities and is dedicated to fostering an environment where differently abled persons can achieve their full potential.

Know more about Meesho here : https://www.meesho.io/

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Meesho's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Meesho's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Meesho's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.