16 Sep
|
Rocketlane
|
Chennai
16 Sep
Rocketlane
Chennai
About Rocketlane
Rocketlane is a B2B SaaS platform for client onboarding and project delivery, and we're building Nitro, our AI-native product layer. We're looking for a Product Security Engineer to own product and infrastructure security for the company.
What you'll own
This is a hands-on, individual-contributor security role covering the full range of product security work, not just one slice of it.
Offensive security and vulnerability discovery
- Run internal penetration tests across our web app, APIs, mobile app, and cloud infrastructure, and triage findings from external pentest vendors
- Actively hunt for vulnerabilities in new features, including in AI/LLM-powered surfaces (prompt injection paths, unsafe code execution in agent tooling, unauthenticated internal endpoints)
- Have found and driven the fix for real vulnerabilities before. We need someone who thinks like an attacker, not just someone who runs a scanner and files a ticket
Cloud and infrastructure security
- Review and harden our AWS setup: WAF rules, ALB/CloudFront TLS policies and cipher suites, container isolation, IAM and secrets hygiene
- Investigate and close out Dependabot and other CI/CD security alerts across dozens of repos, and work with engineering teams to get fixes prioritized and shipped
- Build and maintain internal security tooling
Compliance and customer trust
- Help with our compliance audit cycles end to end: evidence collection, control testing, and coordinating with auditors. This typically takes up 5% of the work.
- Respond to customer security questionnaires and InfoSec review requests, working with sales and customer success to turn these around quickly and accurately
- Keep our security documentation and posture current as the product and infrastructure evolve
Cross-team coordination
- Work directly with engineering, platform, and ops teams to get security fixes prioritized and shipped, not just logged
- Report critical findings up to leadership with clear, actionable writeups (source, sink, impact, fix)
What we're looking for
- 3+ years in a hands-on security role covering penetration testing and vulnerability research, ideally across web, API, mobile, and cloud
- Real, demonstrable experience finding and helping fix responsible vulnerabilities (RCE, auth bypass, injection classes), not just running automated scans
- Solid working knowledge of AWS security: WAF, ALB/CloudFront, IAM, container security on ECS or similar
- Comfort integrating security tooling into CI/CD pipelines (SAST/DAST, dependency scanning) and driving remediation with engineering teams
- Experience with, or strong interest in, securing LLM/AI-powered applications: unsafe code execution, prompt injection, agent tool-call boundaries
- Strong written communication. You'll be writing up findings for engineers and explaining risk to non-technical stakeholders in the same week
Nice to have
- Experience building or maintaining internal security scanning tools
- Familiarity with Java/Spring Boot stacks (our backend) or Python (our AI/LLM stack)
- A CTF background, bug bounty track record, or security certifications (OSCP, etc.)
- Prior exposure to SOC 2 or similar compliance frameworks and customer-facing security questionnaires would be a plus
Why this role
You'd be the primary security engineer for a fast-moving product company actively shipping AI agent features, with direct access to leadership and real ownership over what gets fixed and when.
📌 Product Security Engineer (Chennai)
🏢 Rocketlane
📍 Chennai