13 Sep
|
People Gamut
|
India
13 Sep
People Gamut
India
How You'll Make an Impact :
This is an early, high-ownership role where you'll be one of the first dedicated members of our Security team and own application security end to end. Your charter is to secure our application from code to artifact to runtime - including the agents driving our AI SDLC and our platform itself.
As an Application Security company, you'll also be customer zero of our product, using it firsthand and helping shape the roadmap in the process. You'll partner closely with the Head of Security & IT, as well as our engineering and product teams.
- Own software supply chain security, including defenses against risks from open-source packages, third-party binaries, container base images, build tools, and other software dependencies.
- Own first-party software security, including code and container scanning, automated security testing in CI, external penetration tests, and the integrity and provenance of software we build and publish.
- Harden our AI agents by enforcing least-privilege access across MCP, credentials, filesystem, and network resources, while maintaining visibility into agent inventory and activity.
- Own and run the responsible disclosure program, including triaging external reports, maintaining submission quality standards, and scaling the review process.
- Partner with engineering teams from concept through implementation to conduct security design reviews, define secure architectures, and ensure security best practices are followed.
- Help shape and evolve our application security program as one of its earliest dedicated security team members.
What You Bring to the Table :
If you are excited about building an application security program from the ground up and enjoy working at the intersection of security, engineering, and AI, we would love to talk to you!
- 6 years of experience in application security or product security, with strong hands-on experience across application security fundamentals.
- At least 2 years of experience working with the security implications of agentic software development, with a strong understanding of how to capture its benefits while managing associated risks.
- Strong experience with threat modeling and secure architecture design.
- Practical experience securing build systems and CI/CD pipelines at scale;
experience with Bazel monorepos is a solid plus.
- Hands-on experience running penetration tests end-to-end and triaging bug bounty or responsible disclosure submissions.
- Strong ability to investigate, understand, and remediate security issues rather than simply identifying and reporting them.
- Comfortable working in ambiguous, fast-moving environments and defining priorities without an established playbook.
- Relentlessly curious with an attacker mindset and the ability to dig deep into how systems work and identify root causes.
- Strong collaboration and communication skills, with the ability to build trust and work effectively with engineering and product teams.
- Willingness to be a customer zero of our security platform, provide thoughtful feedback, and help influence the product roadmap.
📌 Product Security Engineer (India)
🏢 People Gamut
📍 India