Meesho logo

Security Engineer III

Meesho · Posted Oct 7

Online marketplace, social commerce, and value-retail services

Bangalore, KarnatakaFull-timeOnsiteSenior Level5–7 years₹40.0L–₹65.0L yearly100+ applicants
E-CommerceRetailMarketplaceSocial CommerceLogisticsPublic Company
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

The security team at Meesho protects an e-commerce platform used by a large share of Indian households, building resilient systems to handle millions of orders daily with zero downtime. The function spans product and application security, cloud-native workloads, DevSecOps tooling, and emerging AI/LLM security. This Security Engineer III role owns threat modeling and secure design reviews, leads VAPT and red team exercises across web, API, and mobile surfaces, integrates SAST/DAST/SCA tooling into CI/CD, and mentors junior security engineers.

What you will do

  • Security Architecture & Threat Modeling: Lead threat modeling and secure design reviews for complex, multi-service features, and partner with engineering to drive the resulting security requirements into production. Contribute security expertise to architecture discussions and help shape secure-by-default patterns that other teams adopt.
  • Application & Offensive Security: Own and conduct advanced security assessments (VAPT) across web platforms, APIs, and mobile applications (iOS & Android), including the business-logic, authentication, authorization, and multi-tenancy classes of issues that automated tooling misses. Plan and run red team and purple team exercises and translate findings into durable architectural fixes, not just point remediations.
  • Manual Code Review: Perform in-depth manual and automated source code reviews to identify security-critical bugs, and work with developers to eliminate whole classes of vulnerabilities at the framework or platform level.
  • DevSecOps & Automation: Own the integration, tuning, and scaling of security tooling (SAST, DAST, SCA, secret scanning, container scanning) in CI/CD. Design and build custom security tooling and automation that scales security across engineering teams, and contribute to supply-chain and pipeline-hardening initiatives.
  • Cloud Security: Drive security reviews and hardening of cloud-native workloads (AWS, Kubernetes/EKS, containers), covering identity and access, tenant isolation, network controls, and secrets management.
  • AI/LLM Security: Contribute to securing Meesho's AI-powered features and workflows, including threat modeling of LLM and RAG integrations, prompt-injection and data-leakage controls, tenant isolation for AI features, and secure patterns for AI in the SDLC.
  • Vulnerability & Bug Bounty Management: Own vulnerability lifecycle and remediation tracking for your areas, and help run the self-managed bug bounty program including triage, researcher engagement, and driving fixes to closure.
  • Security Metrics: Define and track security metrics (coverage, remediation SLAs, mean time to remediate) for your areas and use them to drive engineering behaviour and prioritisation.
  • Security Partnership & Mentorship: Act as a security subject matter expert for developers through secure-coding guidance, code reviews, and consultations. Mentor SE1 and SE2 engineers, review their work, and help level up the team's technical depth.
  • Security Culture & Compliance: Drive security culture initiatives (Security Champions, developer awareness, phishing simulations) and contribute to risk and compliance efforts such as ISO 27001 readiness, TPRM, and BCP/BIA.

Skills used in this role

JavaNode.jsPythonReactSASTDASTSCADockerKubernetesEKSAWSGCPCI/CDOWASP Top 10OWASP MASVSFridaObjectionDrozerMobSFVAPTPenetration TestingThreat ModelingRed Teaming

What the employer is looking for

  • Experience: 5-7 years of hands-on experience in product security or application security, with a demonstrated track record of owning security workstreams end to end.
  • Education: A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is preferred.
  • Proven ability to lead threat modeling sessions and drive findings into the SDLC across cross-functional teams.
  • Strong proficiency performing security assessments on web applications and APIs, with deep command of the OWASP Top 10 (Web and API) and complex authentication, authorization, session management, and business-logic vulnerabilities.
  • Hands-on manual source code review experience, with the ability to read and reason about code in languages such as Java, Node.js, Python, and React.
  • Demonstrated experience with DevSecOps, integrating and tuning security tooling in CI/CD pipelines, and building custom security automation.
  • Proficiency with cloud security on AWS or GCP, including their native security tooling, and working knowledge of Docker and Kubernetes security.
  • Offensive Security: Demonstrated experience planning and executing red team or purple team exercises, and translating real-world attack paths into concrete defensive improvements.
  • Mobile Security: Working knowledge of mobile application security assessments for Android and iOS, familiarity with the OWASP MASVS framework and mobile-specific vulnerabilities (insecure webview, insecure deeplink, insecure data storage, flawed cryptography), and exposure to tools such as Frida, Objection, Drozer, and MobSF.
  • Strong analytical and problem-solving skills, with sound judgment on risk prioritisation at scale.
  • Excellent communication skills, with the ability to explain complex security issues to both technical and non-technical audiences and to influence engineering decisions without direct authority.
  • Ability to mentor and uplevel earlier-career security engineers.

Preferred qualifications

  • Relevant certifications such as OSCP, OSWE, GWAPT, or CKS.
  • Active participation in public or private bug bounty programs, published CVEs, or security research.
  • Experience speaking at meetups or conferences.
  • Exposure to AI/LLM security (prompt injection, RAG security, OWASP LLM Top 10) and software supply-chain security.
  • Exposure to India regulatory requirements such as the DPDP Act and CERT-In directions.

Benefits and support

  • Competitive compensation — both cash and equity-based — tailored to job roles, individual experience, and skill
  • Holistic wellness program, MeeCare, including benefits across physical, mental, financial, and social wellness
  • Extensive medical insurance for employees and their families
  • Wellness initiatives like telehealth, wellness events, and fitness-related perks
  • Generous leave policies
  • Parental support
  • Retirement benefits
  • Learning and development assistance
  • Salary advance support
  • Relocation assistance

About Meesho

Meesho is an Indian e-commerce platform that enables small businesses, individuals, and manufacturers to sell products online across various categories like fashion, home, and beauty. Operating a zero-commission marketplace model, the company focuses on serving value-conscious consumers primarily in tier-2, tier-3, and rural regions. It has scaled significantly to connect millions of buyers with local suppliers and independent sellers.

Industry
E-Commerce
Company size
1001-5000 employees
Founded
December 2015
Location
Bengaluru, Karnataka, India
Funding stage
Public Company

Funding

Public Company · $1.36B raised

Tiger Global ManagementPeak XV PartnersSoftBank Vision FundMetaWestBridge CapitalY CombinatorElevation Capital
  • 2016-05-05Angel$350K
  • 2017-10-01Series A$3.1M
  • 2018-06-01Series B$11.5M
  • 2018-11-01Series C$50M
  • 2019-06-01Corporate Round$25M
  • 2019-08-01Series D$125M
  • 2021-04-01Series E$300M
  • 2021-09-01Series F$570M
  • 2023-09-11Secondary Market$52.5M
  • 2024-05-11Venture Round$275M
  • 2025-01-27Series FUndisclosed

Leadership

VA
Vidit Aatrey

Founder & Chief Executive Officer

SB
Sanjeev Barnwal

Co-founder & Chief Technology Officer

DB
Dhiresh Bansal

Chief Financial Officer

DM
Debdoot Mukherjee

Chief Data Scientist, Head of AI and Demand Engineering