Company Description
Freshworks makes it fast and easy for businesses to delight their customers and employees. We do this by taking a fresh approach to building and delivering software that is affordable, quick to implement, and designed for the end user. Headquartered in San Mateo, California, Freshworks has a global team operating from 13 global locations to serve more than 65,000 companies -- from startups to public companies – that rely on Freshworks software-as-a-service to enable a better customer experience (CRM, CX) and employee experience (ITSM).
Freshworks’ cloud-based software suite includes Freshdesk (omni-channel customer support), Freshsales (sales automation), Freshmarketer (marketing automation), Freshservice (IT service desk), Freshchat (AI-powered bots), supported by Neo, our underlying platform of shared services.
Want more jobs like this?
Get Software Engineering jobs in Chennai, India delivered to your inbox every week.
Freshworks is featured in global national press including CNBC, Forbes, Fortune, Bloomberg and has been a BuiltIn Best Place to work in San Francisco and Denver for the last 3 years. Our customer ratings have earned Freshworks products TrustRadius Top Rated Software ratings and G2 Best of Awards for Best Feature Set, Best Value for the Price and Best Relationship.
Job DescriptionPurpose of the Role
In today’s world, any organisation or individual is constantly under the threat of cyber attack and this is proven through a steady uprise in security incidents and data breaches year after year.
We at Freshworks are committed to preventing such incidents and providing a secure operating environment for our customers to run their businesses.
Freshworks is looking for an enthusiastic and self-driven staff security engineer with the ability to work independently and collaboratively to enable cross-functional teams to build secure products. You will play a pivotal role in integrating and advancing security by working with Developers, Product Owners, Program Managers, Product Architects and Security Engineers
As part of the Security Engineering team, you will advocate secure design principles, secure code reviews, securing devops, build security solutions, frameworks and libraries to improve the security posture of the products, build security automation and conduct thematic assessments to unearth critical vulnerabilities. We also expect you to deliver security training and drive security design solutions at org level
Responsibilities
- Drive the implementation of security testing tools (SAST / DAST / SCA) integration in the Product’s CI / CD pipelines ( Github actions, Jenkins etc., )
- Design & architect the security automation tool frameworks,libraries and drive the implementation creating impact at the organisational level
- Mentor Security Engineers for developing industry-standard programming practices
- Drive Infrastructure as Code solution (Terraform, Ansible, Chef etc)
- Drive the implementation of security hardening controls for Docker, Kubernetes and other container orchestration services across the organisation
- Examine the products in detail to discover vulnerabilities and collaborate with the other security engineers to practically demonstrate the exploitability and risk factors
- Be at the forefront of emerging vulnerabilities/threats which could affect Freshworks products through independent research and study. Engage with the developers in developing workarounds/mitigation plans and ensure they are implemented per policy
- Drive thematic security assessments to discover and exploit unique vulnerabilities having a serious business impact
- Build secure coding principles and propagate them across the development community
- Be the to-go person for developers in solving critical issues relating to secure product development
- Engage with the development teams to conduct secure design reviews/threat modelling exercises to enumerate threats and mitigation strategies
- Enable the developers with knowledge of threat modelling by conducting focused workshops
- Conduct workshops/security tech talks to disseminate security knowledge and awareness
Staff Security Engineer Responsibilities
- Be a role model for the team/Org and provide a healthy platform for the team to learn and grow
- Collaborate and engage with the cyber security leadership team and provide inputs for decision support
- Play the role of solution architect in designing and implementing security engineering programs
Basic Qualification
- 8 to 12 years of experience in application security, desirable to have 2 years of software development experience
- Experience in integrating and automating security in DevOps through implementing/building orchestration tools
- Expert-level knowledge in multiple classes of vulnerabilities that includes cross-site scripting, SQL Injection, CSRF, cryptographic-related weakness, and code injection
- Expert-level knowledge of SAML / OAuth / Open ID Connect
- Expert-level knowledge of programming/scripting languages such as Java, Ruby, and Python
- Experience in conducting security assessments in cloud platforms (SaaS, PaaS, IaaS)
- Ability to automate security testing and improve productivity in security assessments
- Expert-level understanding and knowledge of web frameworks and architecture
- Ability to communicate and interpret security vulnerabilities to various audiences such as development and management teams
Advanced Qualification
- Published CVEs / research papers/articles pertaining to the security of the application layer and related protocols
- Strong security development experience in Java / Ruby on Rails
Additional Information
All your information will be kept confidential according to EEO guidelines.
At Freshworks, we are creating a global workplace that enables everyone to find their true potential, purpose, and passion irrespective of their background, gender, race, sexual orientation, religion and ethnicity. We are committed to providing equal opportunity for all and believe that diversity in the workplace creates a more vibrant, richer work environment that advances the goals of our employees, communities and the business.