D
Senior Staff Engineer, Product Security
Druva
🟢 Active · Posted Today · 👁 1 views · 👥 1 applied
Job Description
Druva is looking for a Senior Staff Product Security Engineer to lead and shape an AI‑first secure development lifecycle for its SaaS platform. You will design automated security controls that embed directly into CI/CD pipelines, drive threat modeling for both traditional services and emerging generative‑AI architectures, and partner with engineering, InfoSec, GRC, and DevOps teams to harden products while enabling safe AI‑driven features.
Key Responsibilities:
- Architect and implement AI‑driven SAST, DAST, SCA, container, and secrets detection into build pipelines.
- Conduct threat models for core services and agentic AI systems (MCP, autonomous agents, prompt injection, memory poisoning).
- Review code in Python, Go, JavaScript; triage findings and guide engineers on robust fixes.
- Manage third‑party risk, SBOM generation, and secure open‑source/agent server ecosystems.
- Run secure coding workshops, train developers on safe AI usage, and grow a Security Champions network.
Required Skills:
- 6‑10 years product security experience in SaaS with proven technical leadership.
- Deep knowledge of OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).
- Hands‑on expertise with AI‑first SDLC, LLM/agentic AI security, and MCP authorization/tool‑poisoning risks.
- Experience using AI tools to automate root‑cause analysis, threat modeling, and policy generation.
- Proficiency in Python, Go, or JavaScript for code review and scripting; familiarity with Burp Suite, Snyk, OWASP ZAP, CI/CD scanners.
- Bachelor’s in CS/IT; certifications (OSCP, OSWE, CSSLP, GIAC) or community contributions a plus.
This role is verified by Employee Table — no fees to apply.
✅ Verified by Employee Table — free to apply, no registration fee required.