17 Aug
|
Rubiscape
|
Pune
About the Role
Every line of code that ships in Rubiscape’s platform touches sensitive enterprise data, AI model outputs, and business-critical decisions for Fortune 500 customers. As an Application Security Engineer, you will be the security champion embedded in the software
development lifecycle — owning SAST/DAST tooling, secure code review, and developer security enablement across Rubiscape’s six studios. You will transform AppSec from a gate into a growth accelerator, ensuring that Rubiscape
ships fast without trading away the security posture that enterprise customers and government deployments require.
Key Responsibilities
· Integrate and operate SAST (SonarQube, Semgrep) and DAST (OWASP ZAP, Burp Suite) tooling into CI/CD pipelines; define severity thresholds and enforce build-break policies.
· Perform security design reviews and secure code reviews for high-risk features including RubiAI prompt injection surfaces, RubiStudio model serving endpoints, and multi-tenant data isolation in RubiSight.
· Maintain and continuously update Rubiscape’s secure development lifecycle (SDL) standards, OWASP Top 10 / API Security Top 10 mappings, and language-specific secure coding guidelines.
· Run bug bounty triage, coordinate responsible disclosure processes, and manage external penetration testing engagements end-to-end.
· Build automated dependency and SCA scanning (Snyk, Dependabot) into the build process; own the third-party library vulnerability backlog and drive resolution within policy SLAs.
· Deliver secure coding workshops, threat modelling training,
and security champions programme for Rubiscape’s engineering guilds.
· Produce application-layer security findings for SOC 2, ISO 27001, and customer security audits; liaise with GRC on evidence collection and control mapping.
Nice to Have
· Certifications: OSWE, GWEB, or BSCP (PortSwigger Web Security).
· Experience securing LLM/GenAI application surfaces including prompt injection, model inversion, and data exfiltration via AI APIs.
· Familiarity with supply-chain security standards (SLSA, SBOM generation, Sigstore).
· Prior work on a multi-tenant B2B SaaS platform serving regulated-sector enterprise customers.
About Rubiscape
Rubiscape is India’s leading Decision Intelligence Platform, unifying data engineering, BI, machine learning, and agentic AI in a single governed platform. Built in Pune and trusted by Fortune 500 enterprises across BFSI, manufacturing, healthcare, and government. 8 international innovation patents. 10 Industry-Academia Labs & COEs. From BI to AI — One Platform. Every Decision.
Requirements
Requirements
· 3+ years of application security experience in a product engineering setting with a shipped SaaS or enterprise software product.
· Demonstrated hands-on skill with SAST/DAST tools and CI/CD integration (GitHub Actions, Jenkins, or GitLab CI).
· Strong understanding of OWASP Top 10, API Security Top 10, and common web application vulnerability classes (SQLi, XSS, SSRF, IDOR, prompt injection).
· Ability to read and review code in at least two of: Python, Java, TypeScript/Node.js, Go.
· Experience managing SCA tooling and coordinating remediation of CVEs in third-party dependencies.
📌 Application Security Engineer (AppSec) (Pune)
🏢 Rubiscape
📍 Pune