08 Aug
|
JAGGAER
|
Hyderabad
Job Summary
Product Security Engineer
AI Application Security | Cyber Architecture Defense
Reporting to the Director of Cyber Architecture Defense, we are seeking a Product Security Engineer with a strong background in application and product security, and working exposure to the security challenges introduced by AI-powered and agentic platforms. This role designs, implements, and coordinates a comprehensive security strategy across the Software Development Life Cycle (SDLC) - including our AI/ML-enabled product lines - and is responsible for identifying, assessing, and reporting security vulnerabilities across our products and applications. You will partner closely with development, platform, and AI engineering teams to embed security practices, run security assessments using industry-standard DAST/SAST and vulnerability management tooling, evaluate risk in agentic AI and LLM-integrated features, and oversee third-party penetration testing activities.
Responsibilities
- Collaborate with product and platform development teams to integrate security into the SDLC by modeling threats, identifying vulnerabilities, and performing penetration tests, applying frameworks such as the OWASP Top 10 and OWASP API Security Top 10.
- Conduct security assessments using agile application security testing (DAST) and static application security testing (SAST) tools.
- Own software supply chain security for the product portfolio - software composition analysis (SCA) of third-party and open-source libraries, dependency and SBOM management, and remediation of vulnerabilities introduced through the build and release pipeline.
- Assess security risks specific to AI/ML-powered features and agentic AI platforms, applying frameworks such as the OWASP LLM Top 10 and OWASP Agentic AI Top 10 to identify issues like prompt injection, insecure output handling, and excessive agency.
- Review AI-assisted software development workflows (e.g., AI coding assistants) and contribute to secure usage guidelines and guardrails for engineering teams.
- Support cross-tenant and multi-tenant risk assessments for SaaS products with AI/ML components deployed across GCP, AWS, and Azure.
- Perform technical risk assessments, evaluate DAST/SAST and AI security tool results, triage findings, and manage security response actions through to resolution.
- Oversee third-party penetration testing activities, objectively prioritizing findings, identifying critical risks, and adhering to compliance requirements.
- Support the companys Vulnerability Disclosure Program (VDP) - triaging externally reported findings, coordinating remediation with product teams, and managing researcher communication through resolution.
- Manage vulnerabilities and incidents across the product portfolio to ensure swift, well-documented resolution.
- Develop and maintain a balanced product security program grounded in well-defined application and AI security frameworks.
- Partner with development teams and architects to design, implement, and continuously improve application and AI security controls.
- Support compliance activities including customer security audits, regulatory compliance projects, and information security reviews.
- Participate in offensive security exercises alongside security operations.
- Serve as a security champion - promoting a culture of security and raising awareness of secure development and AI usage practices across the organization.
- Stay current with security, AI, and threat landscape trends, and recommend improvements to posture and tooling.
- Maintain functional understanding of common compliance and AI governance frameworks, including NIST 800-53, ISO 27001, PCI DSS, SOC 2 Type II, CSA CCM, NIST AI RMF, and ISO/IEC 42001.
Qualifications
- Bachelors degree in Computer Science, Information Security, or a related field.
- 5+ years of experience in product or application security, with a focus on the software development life cycle.
- Proficient in Python, Java, or other programming languages.
- Experience with industry-standard DAST/SAST tools and vulnerability management platforms.
- Experience with software composition analysis (SCA), SBOM generation, and software supply chain security practices.
- Experience running or supporting a Vulnerability Disclosure Program (VDP) or bug bounty program is a plus.
- Working knowledge of web application, network, and cloud security across multi-cloud environments (GCP, AWS, Azure).
- Familiarity with AI/LLM security concepts and agentic AI systems (e.g., prompt injection, model supply chain risk, secure tool-use/harness design) is a strong plus.
- Strong analytical and problem-solving skills.
- Excellent communication and collaboration skills, with the ability to work across security, engineering, and AI/product teams.
- Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), or similar certifications are a plus.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Product Security Engineer (Hyderabad)
🏢 JAGGAER
📍 Hyderabad