Druva

Senior Staff Engineer, Product Security

Pune · On-site · 6–10 yrs · Staff · Full-time

  • python
  • go
  • javascript
  • sast
  • dast
  • sca
  • burp suite
  • snyk
  • owasp zap
  • owasp top 10

Senior Staff Product Security Engineer to lead AI-first SDLC and AppSec initiatives at Druva's SaaS platform.

Apply on Druva's site Ask for a referral

Posted 1 Oct 2026 · found on Druva's own careers page

Read the full job description

<h3>&nbsp;</h3> <p><strong>About Druva<br></strong>Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity, and AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint, and edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond faster, recover cleanly, and govern data with greater confidence.<br><br>Trusted by nearly 7,500 customers, including 75 of the Fortune 500, Druva helps safeguard the critical information and systems businesses depend on in an increasingly connected world.<strong><br></strong></p> <p>Visit<a href="https://www.druva.com/">&nbsp;druva.com</a>&nbsp;and follow us on&nbsp;<a href="https://www.linkedin.com/company/druva/mycompany/">LinkedIn</a>,&nbsp;<a href="https://twitter.com/druvainc">X</a>&nbsp;and&nbsp;<a href="https://www.facebook.com/DruvaInc/">Facebook</a>.</p> <p><strong>

Experience

Level:</strong> 6–10 Years<br><strong>Domain:</strong> Product Security / AppSec / DevSecOps / AI Security / AI-First SDLC</p> <h4>Role Summary</h4> <p>We are looking for a hands-on <strong>Senior Staff Product Security Engineer</strong> to join and lead initiatives across our product security landscape. In this role, you will redefine modern Product Security by architecting an AI-first SDLC seamlessly integrating traditional AppSec with advanced AI security practices, automating shift-left pipelines, conducting rigorous threat models for core services and complex AI architectures, and leveraging cutting-edge AI tools to accelerate vulnerability remediation. You will partner directly with engineering leadership, Information Security, GRC, BuildOps, and DevOps teams to secure our SaaS products and safely enable cutting-edge agentic features.</p> <h4>Role &amp; Responsibilities</h4> <ul> <li><strong>AI-First SDLC &amp; Shift-Left Automation:</strong> Architect and embed AI-driven security controls (SAST, DAST, SCA, Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows, establishing an intelligent, highly automated AI-first SDLC.</li> <li><strong>Operational &amp; Strategic AI Security:</strong> Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features.</li> <li><strong>AI &amp; Emerging Tech Threat Modeling:</strong> Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections, and memory/context poisoning (OWASP Top 10 for LLMs / Agentic Apps).</li> <li><strong>Developer Guidance &amp; Vulnerability Remediation:</strong> Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes.</li> <li><strong>Supply Chain &amp; Software Integrity:</strong> Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems.</li> <li><strong>Enablement &amp; Champions Program:</strong> Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network.</li> </ul> <h4>Skills &amp; Qualifications</h4> <ul> <li><strong>Experience:</strong> 6–10 years of product security engineering experience in a SaaS environment, with a proven track record of technical leadership.</li> <li><strong>AppSec Fundamentals:</strong> Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).</li> <li><strong>AI Security &amp; AI-First SDLC Expertise:</strong> Strong hands-on expertise with AI-first SDLC methodologies and reviewing AI security risks specifically around Agentic AI systems, MCP security (authorization, tool poisoning, confused deputy risks), and LLM security controls.</li> <li><strong>Operational AI Use-Cases:</strong> Experience using AI tools to optimize security engineering workflows (e.g., automating root-cause analysis, threat modeling assistance, automated policy generation).</li> <li><strong>Programming &amp; Tooling:</strong> Proficient in code review and scripting with Python, Go, or Javascript (hands-on development experience is a major plus). Hands-on with tools like Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners.</li> <li><strong>Education &amp; Certifications:</strong> Bachelor’s degree in CS/IT or equivalent.

Relevant certifications (OSCP, OSWE, CSSLP, GIAC) or active community contributions (OWASP, BSides, NullCon, Black Hat, etc) are a plus.</li> </ul> <p>&nbsp;</p>

Members get roles like this as soon as we find them on the company's careers page, and paid plans email the ones that match their resume.

Get new roles first — free

More at Druva