24 Sep
|
Dun u0026 Bradstreet
|
Hyderabad
24 Sep
Dun u0026 Bradstreet
Hyderabad
Shape the Future with Dun & Bradstreet
At Dun & Bradstreet, we believe data has the power to create a better tomorrow. As a global leader in business decisioning data and analytics, we help companies worldwide grow, manage risk, and innovate. Since 1841, businesses have trusted us to turn uncertainty into opportunity. We’re a diverse, global team that values creativity, collaboration, and bold ideas. Are you ready to make an impact and help shape what’s next? Join us! Explore opportunities at dnb.com/careers.
The Senior Product Security Engineer designs, implements, and continuously improves secure-by-design capabilities across the software development lifecycle, with emphasis on application security, API security, software supply chain security, cloud-native product security, and cyber resilience. The role serves as a senior technical contributor, leading complex reviews and cross-team initiatives while translating product security risk into scalable engineering patterns, automated controls, measurable remediation plans, and secure adoption guidance for emerging technologies. n
Key Responsibilities:
- Design, implement, and mature Product Security capabilities across application security, API security, software supply chain security, secure SDLC, cloud-native workloads, and resilience engineering.
- Lead threat modeling, secure architecture reviews, design assessments, and control recommendations for critical products, platforms, APIs, data flows, third-party integrations, and customer-facing services.
- Drive adoption of secure design patterns and resilience expectations across SDLC, DevSecOps, CI/CD, release, and operational readiness processes.
- Lead software supply chain improvements involving SCA, SBOM, build pipeline hardening, artifact integrity, secrets prevention, code signing, build provenance, and open-source risk.
- Perform application and API security assessments utilizing SAST, DAST, SCA, code review findings, API analysis,
and remediation validation activities.
- Develop scalable security patterns, reference architectures, guardrails, and automation that support engineering velocity.
- Define and guide security controls for AI-enabled products, copilots, autonomous agents, retrieval architectures, model and tool permissions, agent identity, data access, logging, monitoring, and abuse-case testing.
- Collaborate with IAM, Data Security, Cloud Security, and Security Operations teams to align product security requirements with enterprise security standards and control objectives.
- Lead risk-based triage, validate exploitability and business impact, improve remediation quality, and drive reduction of recurring vulnerability classes.
- Lead or support in resilience activities including application risk reviews, incident investigations, tabletop exercises, resilience testing, and post-incident improvement efforts.
- Research emerging threats, vulnerabilities, attack techniques, and security technologies to improve product security capabilities and engineering practices.
- Define and communicate metrics, trends, control maturity, remediation progress, and measurable risk reduction to technical leaders and senior stakeholders.
- Mentor engineers, influence design decisions without direct authority, and lead cross-functional Product Security initiatives.
- Promote secure development practices through engineering collaboration, documentation, security guidance, and knowledge sharing.
Key Requirements:
- Experience in application security,
product security, software security, DevSecOps, cloud security, or related cybersecurity disciplines.
- Experience with SAST, DAST, SCA, secrets detection, container scanning, IaC scanning, and remediation validation.
- Strong understanding of software supply chain security, including dependency governance, SBOM, open-source risk, CI/CD controls, artifact integrity, and secure release practices.
- Experience securing APIs and cloud-native environments, including authentication, authorization, containers, Kubernetes, microservices, and serverless architectures.
- Understanding of AI security risks, including prompt injection, data leakage, retrieval architectures, agent identity, model and tool permissions, logging, and monitoring.
- Experience with Python, PowerShell, REST APIs, Terraform, CI/CD platforms, policy-as-code, or related automation.
- Knowledge of OWASP, NIST, ISO 27001, PCI-DSS, and related standards. Relevant security or cloud certifications are preferred.
- Robust experience leading threat modeling, secure architecture reviews, abuse-case analysis, and risk-based remediation for complex systems.
- Ability to translate complex technical risk into scalable requirements, reference patterns, remediation strategies, metrics, and senior-leadership narratives.
- Ability to operate independently, mentor others, influence across organizational boundaries, and drive enterprise outcomes.
nAll Dun & Bradstreet job postings can be found at https://jobs.lever.co/dnb. Official communication from Dun & Bradstreet will come from an email address ending in @dnb.com.
Notice to Applicants: Please be advised that this job posting page is hosted and powered by Lever, a subsidiary of Employ Inc. Your use of this page is subject to Employ's Privacy Notice and Cookie Policy, which governs the processing of visitor data on this platform.
📌 Senior Product Security Engineer (Hyderabad)
🏢 Dun u0026 Bradstreet
📍 Hyderabad