SDE 3 - Product Security Engineer

Mumbai (On-Site) /
Dream11 – Technology /
Technology @Dream11:
Our Tech Team is the core of Dream11’s mobile-first cross-platform (Android & iOS, Mobile + Desktop PWA) product, serving more than 10 Crore users with over 70 million rpm (requests per minute) at peak with user concurrency of 5.5 million. Our tech stack is hosted on AWS and comprises multiple distributed systems like Cassandra, Aerospike, Akka, Voltdb, Ignite etc.

We have around 100+ micro-services primarily written in Java backed by vert.x framework. They serve isolated product features with discrete architectures to serve the respective use-cases. We have a completely in-house data infrastructure built on top of Kafka, Redshift, Spark, Druid etc. which powers our Machine Learning and Predictive Analytics use-cases. We ingress Terabytes of Data every day, which flows all over our Data pipelines to power a plethora of use-cases. 

To know more about Dream11 Tech, visit here.

Security Engineering @Dream11:
“Security First” is the principle on which Dream11 Engineering is based at. Secure SDLC is ingrained into the process and religiously followed upon. Dream11 Security team takes care of all aspects of Application, Cloud and Data/Enterprise Security working as a close knit team. It strongly believes in automating everything that can be. The team strives all the time to have Infrastructure / Configuration as a Code paradigm.

Your Role:

    • Working closely with development stakeholders to ensure secure design, development, and implementation of applications
    • Understanding complex technical and architectural issues from the security perspective
    • Understanding the implications associated with the chosen technical strategy and improvise them to meet security compliances
    • Performing Application Vulnerability Assessment & Penetration Testing
    • Writing in-house tools and automated scripts to enhance the security assessment
    • Contributing to the delivery, automation, and maintenance of Dream11 security policies, controls, and processes as part of the Application Risk Assessment team

Must Have:

    • Strong experience in backend and frontend security
    • 5+ experience on Web and Mobile application Vulnerability Assessment & Penetration Testing
    • Knowledge of Secure Code Review and Secure SDLC
    • Good understanding of any of the programming languages (Python, Java, GoLang, Javascript, etc.)
    • Strong understanding of applications design and architecture

Good to Have:

    • Understanding of any cloud based platform like AWS, GCP etc.
    • Worked on WAF and Log Analytics solutions
    • Participated in Bug Bounties & Capture The Flag (CTF)
    • Basic understanding of Infrastructure/Network Vulnerability Assessment and Penetration Testing
    • Certifications like OSCP, G-Mob, OSWP, etc.
More on our company:

About our Benefits:
We offer numerous benefits to every one of our team members a.k.a. Sportans:
- Ownership (ESOP) in one of the fastest-growing startups in the world
- Unlimited leaves, including one week of complete #Unplug from work
- Professional learning allowance
- Complimentary and healthy meals are served every day
- International Offsite every year for achieving company targets
- Relocation budget is taken care of, and additional rent coverage for living in close proximity to work

Click this link to go through all our benefits

About our Culture:
At Dream11, we DO-PUT our culture first. What’s DO-PUT, you ask? Those are the five core values that completely cover how things are here!
- We are data-obsessed i.e. 99% data-driven work and 1% gut
- We own what we do 100% as a team
- We on-board high performing superstars and get out of their way
- Everything we build and design is by putting our users first
Transparent communication processes are something we believe in the most

Click this link and get to know the Dream11 Culture

Dream Sports is India’s leading sports technology company with 140 million users, housing brands such as Dream11, the world’s largest fantasy sports platform, FanCode, a premier sports content & commerce platform, Dream Capital, a CVC and M&A arm, DreamSetGo, a sports experiences platform, and DreamPay, a payment solutions provider.

Dream Sports is based in Mumbai and has a workforce of close to 1,000 ‘Sportans’. Founded in 2008 by Harsh Jain and Bhavit Sheth, Dream Sports’ mission is to ‘Make Sports Better’ for fans through the confluence of sports and technology. Since 2018, Dream Sports has been consistently featured as the only sports tech company in the ‘Great Places to Work’ survey.

For more information: