
Security Engineer III
Meesho · Posted Oct 7
Online marketplace, social commerce, and value-retail services
Get a personal compatibility score
Add a resume for personal matches
About the role
The security team at Meesho protects an e-commerce platform used by a large share of Indian households, building resilient systems to handle millions of orders daily with zero downtime. The function spans product and application security, cloud-native workloads, DevSecOps tooling, and emerging AI/LLM security. This Security Engineer III role owns threat modeling and secure design reviews, leads VAPT and red team exercises across web, API, and mobile surfaces, integrates SAST/DAST/SCA tooling into CI/CD, and mentors junior security engineers.
What you will do
- Security Architecture & Threat Modeling: Lead threat modeling and secure design reviews for complex, multi-service features, and partner with engineering to drive the resulting security requirements into production. Contribute security expertise to architecture discussions and help shape secure-by-default patterns that other teams adopt.
- Application & Offensive Security: Own and conduct advanced security assessments (VAPT) across web platforms, APIs, and mobile applications (iOS & Android), including the business-logic, authentication, authorization, and multi-tenancy classes of issues that automated tooling misses. Plan and run red team and purple team exercises and translate findings into durable architectural fixes, not just point remediations.
- Manual Code Review: Perform in-depth manual and automated source code reviews to identify security-critical bugs, and work with developers to eliminate whole classes of vulnerabilities at the framework or platform level.
- DevSecOps & Automation: Own the integration, tuning, and scaling of security tooling (SAST, DAST, SCA, secret scanning, container scanning) in CI/CD. Design and build custom security tooling and automation that scales security across engineering teams, and contribute to supply-chain and pipeline-hardening initiatives.
- Cloud Security: Drive security reviews and hardening of cloud-native workloads (AWS, Kubernetes/EKS, containers), covering identity and access, tenant isolation, network controls, and secrets management.
- AI/LLM Security: Contribute to securing Meesho's AI-powered features and workflows, including threat modeling of LLM and RAG integrations, prompt-injection and data-leakage controls, tenant isolation for AI features, and secure patterns for AI in the SDLC.
- Vulnerability & Bug Bounty Management: Own vulnerability lifecycle and remediation tracking for your areas, and help run the self-managed bug bounty program including triage, researcher engagement, and driving fixes to closure.
- Security Metrics: Define and track security metrics (coverage, remediation SLAs, mean time to remediate) for your areas and use them to drive engineering behaviour and prioritisation.
- Security Partnership & Mentorship: Act as a security subject matter expert for developers through secure-coding guidance, code reviews, and consultations. Mentor SE1 and SE2 engineers, review their work, and help level up the team's technical depth.
- Security Culture & Compliance: Drive security culture initiatives (Security Champions, developer awareness, phishing simulations) and contribute to risk and compliance efforts such as ISO 27001 readiness, TPRM, and BCP/BIA.
Skills used in this role
What the employer is looking for
- Experience: 5-7 years of hands-on experience in product security or application security, with a demonstrated track record of owning security workstreams end to end.
- Education: A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is preferred.
- Proven ability to lead threat modeling sessions and drive findings into the SDLC across cross-functional teams.
- Strong proficiency performing security assessments on web applications and APIs, with deep command of the OWASP Top 10 (Web and API) and complex authentication, authorization, session management, and business-logic vulnerabilities.
- Hands-on manual source code review experience, with the ability to read and reason about code in languages such as Java, Node.js, Python, and React.
- Demonstrated experience with DevSecOps, integrating and tuning security tooling in CI/CD pipelines, and building custom security automation.
- Proficiency with cloud security on AWS or GCP, including their native security tooling, and working knowledge of Docker and Kubernetes security.
- Offensive Security: Demonstrated experience planning and executing red team or purple team exercises, and translating real-world attack paths into concrete defensive improvements.
- Mobile Security: Working knowledge of mobile application security assessments for Android and iOS, familiarity with the OWASP MASVS framework and mobile-specific vulnerabilities (insecure webview, insecure deeplink, insecure data storage, flawed cryptography), and exposure to tools such as Frida, Objection, Drozer, and MobSF.
- Strong analytical and problem-solving skills, with sound judgment on risk prioritisation at scale.
- Excellent communication skills, with the ability to explain complex security issues to both technical and non-technical audiences and to influence engineering decisions without direct authority.
- Ability to mentor and uplevel earlier-career security engineers.
Preferred qualifications
- Relevant certifications such as OSCP, OSWE, GWAPT, or CKS.
- Active participation in public or private bug bounty programs, published CVEs, or security research.
- Experience speaking at meetups or conferences.
- Exposure to AI/LLM security (prompt injection, RAG security, OWASP LLM Top 10) and software supply-chain security.
- Exposure to India regulatory requirements such as the DPDP Act and CERT-In directions.
Benefits and support
- Competitive compensation — both cash and equity-based — tailored to job roles, individual experience, and skill
- Holistic wellness program, MeeCare, including benefits across physical, mental, financial, and social wellness
- Extensive medical insurance for employees and their families
- Wellness initiatives like telehealth, wellness events, and fitness-related perks
- Generous leave policies
- Parental support
- Retirement benefits
- Learning and development assistance
- Salary advance support
- Relocation assistance
About Meesho
Meesho is an Indian e-commerce platform that enables small businesses, individuals, and manufacturers to sell products online across various categories like fashion, home, and beauty. Operating a zero-commission marketplace model, the company focuses on serving value-conscious consumers primarily in tier-2, tier-3, and rural regions. It has scaled significantly to connect millions of buyers with local suppliers and independent sellers.
- Industry
- E-Commerce
- Company size
- 1001-5000 employees
- Founded
- December 2015
- Location
- Bengaluru, Karnataka, India
- Funding stage
- Public Company
Funding
Public Company · $1.36B raised
- 2016-05-05Angel$350K
- 2017-10-01Series A$3.1M
- 2018-06-01Series B$11.5M
- 2018-11-01Series C$50M
- 2019-06-01Corporate Round$25M
- 2019-08-01Series D$125M
- 2021-04-01Series E$300M
- 2021-09-01Series F$570M
- 2023-09-11Secondary Market$52.5M
- 2024-05-11Venture Round$275M
- 2025-01-27Series FUndisclosed
Leadership
Founder & Chief Executive Officer
Co-founder & Chief Technology Officer
Chief Financial Officer
Chief Data Scientist, Head of AI and Demand Engineering
Recent coverage
Free Press Journal
Meesho Content Commerce NMV Grows 152% YoY, Powered By Homemakers And Young Graduates2026-10-06
Business Standard
Meesho share price surges 10% in two days on heavy volume after content commerce update2026-10-06
Bloomberg
India E-Commerce Firm Meesho Starts Taking Orders for $603 Million India IPO2025-12-04