Senior Staff Engineer, Product Security
Pune · On-site · 6–10 yrs · Staff · Full-time
- python
- go
- javascript
- sast
- dast
- sca
- burp suite
- snyk
- owasp zap
- owasp top 10
Senior Staff Product Security Engineer to lead AI-first SDLC and AppSec initiatives at Druva's SaaS platform.
Apply on Druva's site Ask for a referral
Read the full job description
<h3> </h3> <p><strong>About Druva<br></strong>Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity, and AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint, and edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond faster, recover cleanly, and govern data with greater confidence.<br><br>Trusted by nearly 7,500 customers, including 75 of the Fortune 500, Druva helps safeguard the critical information and systems businesses depend on in an increasingly connected world.<strong><br></strong></p> <p>Visit<a href="https://www.druva.com/"> druva.com</a> and follow us on <a href="https://www.linkedin.com/company/druva/mycompany/">LinkedIn</a>, <a href="https://twitter.com/druvainc">X</a> and <a href="https://www.facebook.com/DruvaInc/">Facebook</a>.</p> <p><strong>
Experience
Level:</strong> 6–10 Years<br><strong>Domain:</strong> Product Security / AppSec / DevSecOps / AI Security / AI-First SDLC</p> <h4>Role Summary</h4> <p>We are looking for a hands-on <strong>Senior Staff Product Security Engineer</strong> to join and lead initiatives across our product security landscape. In this role, you will redefine modern Product Security by architecting an AI-first SDLC seamlessly integrating traditional AppSec with advanced AI security practices, automating shift-left pipelines, conducting rigorous threat models for core services and complex AI architectures, and leveraging cutting-edge AI tools to accelerate vulnerability remediation. You will partner directly with engineering leadership, Information Security, GRC, BuildOps, and DevOps teams to secure our SaaS products and safely enable cutting-edge agentic features.</p> <h4>Role & Responsibilities</h4> <ul> <li><strong>AI-First SDLC & Shift-Left Automation:</strong> Architect and embed AI-driven security controls (SAST, DAST, SCA, Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows, establishing an intelligent, highly automated AI-first SDLC.</li> <li><strong>Operational & Strategic AI Security:</strong> Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features.</li> <li><strong>AI & Emerging Tech Threat Modeling:</strong> Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections, and memory/context poisoning (OWASP Top 10 for LLMs / Agentic Apps).</li> <li><strong>Developer Guidance & Vulnerability Remediation:</strong> Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes.</li> <li><strong>Supply Chain & Software Integrity:</strong> Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems.</li> <li><strong>Enablement & Champions Program:</strong> Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network.</li> </ul> <h4>Skills & Qualifications</h4> <ul> <li><strong>Experience:</strong> 6–10 years of product security engineering experience in a SaaS environment, with a proven track record of technical leadership.</li> <li><strong>AppSec Fundamentals:</strong> Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).</li> <li><strong>AI Security & AI-First SDLC Expertise:</strong> Strong hands-on expertise with AI-first SDLC methodologies and reviewing AI security risks specifically around Agentic AI systems, MCP security (authorization, tool poisoning, confused deputy risks), and LLM security controls.</li> <li><strong>Operational AI Use-Cases:</strong> Experience using AI tools to optimize security engineering workflows (e.g., automating root-cause analysis, threat modeling assistance, automated policy generation).</li> <li><strong>Programming & Tooling:</strong> Proficient in code review and scripting with Python, Go, or Javascript (hands-on development experience is a major plus). Hands-on with tools like Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners.</li> <li><strong>Education & Certifications:</strong> Bachelor’s degree in CS/IT or equivalent.
Relevant certifications (OSCP, OSWE, CSSLP, GIAC) or active community contributions (OWASP, BSides, NullCon, Black Hat, etc) are a plus.</li> </ul> <p> </p>
Members get roles like this as soon as we find them on the company's careers page, and paid plans email the ones that match their resume.
Get new roles first — free