D

Senior Staff Engineer, Product Security

Druva

🟢 Active · Posted Today  ·  👁 1 views  ·  👥 1 applied

📍 LocationPune
💼 Job TypeFull-Time
⏱ Experience5+ years
🎓 QualificationBE/BTech
🛠 SkillsAI-First SDLC, Shift-Left Automation, Threat Modeling (GenAI/Agentic AI), Secure Code Review (Python, Go, JavaScript), Supply Chain Security (SBOM, OSS), CI/CD Security Tooling (SAST, DAST, SCA, Container, Secrets Detection), Security Champions Enablement, AI Security Controls (LLM, MCP)

Job Description

Druva is looking for a Senior Staff Product Security Engineer to lead and shape an AI‑first secure development lifecycle for its SaaS platform. You will design automated security controls that embed directly into CI/CD pipelines, drive threat modeling for both traditional services and emerging generative‑AI architectures, and partner with engineering, InfoSec, GRC, and DevOps teams to harden products while enabling safe AI‑driven features.

Key Responsibilities:

  • Architect and implement AI‑driven SAST, DAST, SCA, container, and secrets detection into build pipelines.
  • Conduct threat models for core services and agentic AI systems (MCP, autonomous agents, prompt injection, memory poisoning).
  • Review code in Python, Go, JavaScript; triage findings and guide engineers on robust fixes.
  • Manage third‑party risk, SBOM generation, and secure open‑source/agent server ecosystems.
  • Run secure coding workshops, train developers on safe AI usage, and grow a Security Champions network.

Required Skills:

  • 6‑10 years product security experience in SaaS with proven technical leadership.
  • Deep knowledge of OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).
  • Hands‑on expertise with AI‑first SDLC, LLM/agentic AI security, and MCP authorization/tool‑poisoning risks.
  • Experience using AI tools to automate root‑cause analysis, threat modeling, and policy generation.
  • Proficiency in Python, Go, or JavaScript for code review and scripting; familiarity with Burp Suite, Snyk, OWASP ZAP, CI/CD scanners.
  • Bachelor’s in CS/IT; certifications (OSCP, OSWE, CSSLP, GIAC) or community contributions a plus.

This role is verified by Employee Table — no fees to apply.

Apply Now ↗ 🔖 Save Job

✅ Verified by Employee Table — free to apply, no registration fee required.

Join WhatsApp m