Meesho is India’s fastest growing internet commerce company. We want to make eCommerce accessible to all. Our vision is to enable 100 million small businesses in India, including individual entrepren…
📋 Job Overview
The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. After all, when 5% of Indian households shop with us, it’s important to build resilient systems to manage millions of orders every day. We’ve done this – with zero downtime! 😎 Sounds impossible? Well, that’s the kind of Engineering muscle that has helped Meesho become the e-commerce giant it is today. We value speed over perfection, and see failures as opportunities to become better. We’ve taken steps to inculcate a strong ‘Founder’s Mindset’ across our engineering teams, making us grow and move fast. We place special emphasis on the continuous growth of each team member - and we do this with regular 1-1s and open communication. As a Security Engineer, you will be part of self-starters who thrive on teamwork and constructive feedback. We know how to party as hard as we work! If we aren’t building unparalleled tech solutions, you can find us debating the plot points of our favorite books and games – or even gossiping over chai. So, if a day filled with building impactful solutions with a fun team sounds appealing to you, join us.
🏢 About Meesho
Meesho is an e-commerce giant that has built resilient systems to manage millions of orders every day with zero downtime. The company values speed, continuous growth, and teamwork, and has a strong ‘Founder’s Mindset’ across its engineering teams.
🎯 The Role
As a Security Engineer 3, you are a senior individual contributor who owns security outcomes end to end across one or more product areas. You operate with limited supervision, set the technical approach for your workstreams, and are a trusted second voice in design and architecture discussions. Beyond finding and fixing vulnerabilities, you drive security initiatives to closure across engineering teams, raise the bar on how we build securely, and mentor earlier-career engineers on the team. You will combine deep hands-on offensive and defensive skills with the judgment to prioritise what matters most for a platform operating at Meesho's scale.
✅ Key Responsibilities
Security Architecture & Threat Modeling: Lead threat modeling and secure design reviews for complex, multi-service features, and partner with engineering to drive the resulting security requirements into production. Contribute security expertise to architecture discussions and help shape secure-by-default patterns that other teams adopt.
Application & Offensive Security: Own and conduct advanced security assessments (VAPT) across web platforms, APIs, and mobile applications (iOS & Android), including the business-logic, authentication, authorization, and multi-tenancy classes of issues that automated tooling misses. Plan and run red team and purple team exercises and translate findings into durable architectural fixes, not just point remediations.
Manual Code Review: Perform in-depth manual and automated source code reviews to identify security-critical bugs, and work with developers to eliminate whole classes of vulnerabilities at the framework or platform level.
DevSecOps & Automation: Own the integration, tuning, and scaling of security tooling (SAST, DAST, SCA, secret scanning, container scanning) in CI/CD. Design and build custom security tooling and automation that scales security across engineering teams, and contribute to supply-chain and pipeline-hardening initiatives.
Cloud Security: Drive security reviews and hardening of cloud-native workloads (AWS, Kubernetes/EKS, containers), covering identity and access, tenant isolation, network controls, and secrets management.
AI/LLM Security: Contribute to securing Meesho's AI-powered features and workflows, including threat modeling of LLM and RAG integrations, prompt-injection and data-leakage controls, tenant isolation for AI features, and secure patterns for AI in the SDLC.
Vulnerability & Bug Bounty Management: Own vulnerability lifecycle and remediation tracking for your areas, and help run the self-managed bug bounty program including triage, researcher engagement, and driving fixes to closure.
Security Metrics: Define and track security metrics (coverage, remediation SLAs, mean time to remediate) for your areas and use them to drive engineering behaviour and prioritisation.
Security Partnership & Mentorship: Act as a security subject matter expert for developers through secure-coding guidance, code reviews, and consultations. Mentor SE1 and SE2 engineers, review their work, and help level up the team's technical depth.
Security Culture & Compliance: Drive security culture initiatives (Security Champions, developer awareness, phishing simulations) and contribute to risk and compliance efforts such as ISO 27001 readiness, TPRM, and BCP/BIA.
📌 Required Qualifications
Experience: 5-7 years of hands-on experience in product security or application security, with a demonstrated track record of owning security workstreams end to end.
Education: A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is preferred.
Core Technical Depth:
Proven ability to lead threat modeling sessions and drive findings into the SDLC across cross-functional teams.
Strong proficiency performing security assessments on web applications and APIs, with deep command of the OWASP Top 10 (Web and API) and complex authentication, authorization, session management, and business-logic vulnerabilities.
Hands-on manual source code review experience, with the ability to read and reason about code in languages such as Java, Node.js, Python, and React.
⭐ Desirable Experience
No specific desirable experience mentioned.
🎁 Benefits
Competitive
🛂 Visa & Eligibility
No specific visa or eligibility information mentioned.