SECTION I · THE BRIEF
Brief #68838Updated 22 SEP 2026BENGALURUAshbySOFTWARE COMPANIES
Employbl Company Profile

Senior Product Security Engineer

Arrive delivers last-mile mobility solutions to navigation systems, voice platforms, websites, mobile apps and in-car dashboards, including the company's ParkWhiz and BestParking consumer brands

Location
Bengaluru
Company size
100–500
Posted
Today
Via
Ashby
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Senior Product Security Engineer

Arrive· BengaluruView company profile


Job title
Senior Product Security Engineer
Job location
Bengaluru
Job description

We’ve signed up to an ambitious journey. Join us!

As Arrive, we guide customers and communities towards brighter futures and more livable cities, it isn’t a challenge just anyone could take on. Luckily, we have something to help us make it happen. Our people and our values. We Arrive Curious, Focused and Together. Just as our entire brand is inspired by the North Star, the shining light leading travelers to their destinations since time began, our values guide us. They help us be at our best. For our customers. For the cities and communities we serve. For ourselves. As a global team, we are transforming urban mobility. Let’s grow better, together.

We are seeking a Product Security Engineer to strengthen the security posture of our applications and cloud-native platforms. This role focuses on proactive application security testing, vulnerability management, secure SDLC integration, and collaboration with engineering teams. You will independently conduct security assessments across web applications, APIs, and cloud environments, while supporting secure development practices and contributing to improving overall product security maturity.

Key Responsibilities: Application & API Security

● Conduct manual and automated penetration testing of web applications and APIs.

● Identify and validate vulnerabilities aligned with OWASP Top 10 and API Security Top 10.

● Perform threat modeling for new features and services.

● Conduct secure code reviews (static analysis) and recommend remediation.

● Validate findings from SAST, DAST, and dependency scanning tools.

● Provide remediation guidance and conduct fix verification testing.

● Participate in design reviews and architecture discussions from a security perspective. Cloud & Infrastructure Security

● Assess AWS/Azure/GCP configurations for common misconfigurations.

● Review IAM policies, storage access controls, and container security posture.

● Validate findings from CSPM/CNAPP tools.

● Support cloud-native application security assessments. Vulnerability Management

● Prioritize vulnerabilities using CVSS and business impact context.

● Track remediation SLAs and support risk acceptance decisions.

● Provide actionable recommendations to development teams. Security Testing & Automation

● Develop scripts and tooling (Python/Bash) to automate testing workflows.

● Improve security testing playbooks and documentation.

● Contribute to enhancing detection and monitoring coverage. Collaboration & Reporting

● Prepare high-quality technical reports with clear risk articulation.

● Translate technical findings into business-impact language.

● Work cross-functionally with DevOps, Cloud, and Engineering teams.

Required Skills:

● 6–9 years of experience in Application Security, Product Security, or Offensive Security.

Hands-on experience conducting web and API penetration testing.

● Strong understanding of OWASP Top 10 and common attack vectors.

● Experience using tools such as Burp Suite, OWASP ZAP, Nmap, Snyk, Checkmarks, etc.

● Experience working with cloud platforms (AWS/Azure/GCP).

● Familiarity with container security and modern DevOps environments.

● Experience reviewing code for security issues.

● Strong understanding of HTTP, authentication mechanisms, and networking fundamentals.

● Basic scripting experience (Python, Bash, or similar).

Preferred Experience:

● Experience in SaaS, fintech, or product-based organizations.

● Exposure to Kubernetes and container security testing.

● Familiarity with bug bounty or responsible disclosure programs.

● Experience implementing DevSecOps practices.

● Certifications such as CEH, Security+, eJPT, OSCP (nice to have).

About Arrive

Arrive, including brands like EasyPark, Flowbird, RingGo, ParkMobile and Parkopedia, is a leading global mobility platform. Present in over 90 countries and 20,000 cities, the company helps people and decision-makers make smarter decisions about urban mobility and ease the experience of travel worldwide. Arrive delivers a unique combination of the core ingredients to make cities more livable: from smart payments and optimized car parks to data-driven traffic reduction and support for reinvestment in public transport and green space. It’s about more than function, it’s about saving time and simplifying the experience of travel for everyone. Travel is more than a journey, it’s how you Arrive.

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Arrive headquarters

Chicago, IL

Company size

100500 employees

Founded

2006

Total raised

$70,255,648

View company profile ↗

Funding rounds