About Gurucul
Security teams today are trying to keep watch over a world that keeps expanding, with machines and AI agents multiplying faster than anyone can hire analysts to watch them, and the attacks aimed at that world move faster every year than most tools were ever built to catch. Gurucul’s mission comes out of that gap: give defenders a system that sees a threat the moment it starts forming, whether it comes from a person, a machine, or an AI agent, so a risk climbing quietly over days turns into something an organization can act on long before anything is lost.
Building that takes fusing behavioral models with deterministic detections and a real-time graph that connects signals analysts would otherwise have to piece together by hand, and it means working alongside people who have spent a decade refining behavioral analytics nobody else in the industry has matched, solving problems that show up in production at Fortune 500 companies, Global 5000 enterprises, and governments who are counting on getting ahead of what’s coming for them.
That work has already earned Gurucul recognition as a Leader in the 2025 Gartner Magic Quadrant for SIEM and as Overall Leader in KuppingerCole’s Intelligent SIEM Leadership Compass, the kind of validation that comes from actually cutting data costs, false positives, and response times at scale rather than just claiming to.
If spending your career on something that actually changes how fast defenders can see and respond to what’s coming sounds like the kind of work you want, this is the team doing it, and we’re hiring.
Role Summary
Gurucul is seeking a Senior/Lead Security Engineer (8–10 years experience) to strengthen our Product Security and Secure SDLC practices. The role will focus on proactive vulnerability detection, triaging security issues, enabling shift-left security practices,
and collaborating with engineering teams to remediate vulnerabilities effectively. The engineer will play a key role in implementing the organization’s security strategy, detection workflow, vulnerability management process, and remediation SLAs.
Key Responsibilities
Security Testing & Vulnerability Detection
- Perform Application Security Testing for web applications, APIs, and microservices.
- Conduct Vulnerability Assessment and Penetration Testing (VAPT).
- Execute manual and automated security testing using tools such as: Burp Suite, Fortify, OWASP ZAP, Nessus / Qualys.
- Identify vulnerabilities aligned with OWASP Top 10 and industry security standards
Secure SDLC & Shift-Left Security
- Integrate security practices into CI/CD pipelines.
- Enable shift-left security testing across the development lifecycle.
- Work closely with engineering teams during design and architecture review.
- Support implementation of secure coding practices
Vulnerability Management & Triage
- Analyze and triage vulnerabilities based on CVSS scoring and exploitability.
- Prioritize vulnerabilities based on risk and business impact.
- Create and manage security defect tickets in Jira.
Track vulnerabilities through detection triage remediation
- verification workflow.
Security Verification & Release Readiness
- Validate remediation of vulnerabilities.
- Perform security verification before release.
- Collaborate with development teams to ensure vulnerabilities are fixed within defined SLA timelines.
Security Tools & Automation
- Manage and operate security tools such as: Fortify (SAST), BurpSuite (DAST), ScoutSuite / Cloud security tools.
- Automate scanning and security testing wherever possible.
Cloud & Infrastructure Security
- Conduct security assessments for cloud infrastructure (AWS preferred).
- Evaluate security posture for: Servers, Containers, Databases, APIs.
- Ensure alignment with CIS benchmarks and security best practices.
Security Awareness & Engineering Enablement
- Conduct security awareness sessions for developers and QA teams.
- Help implement Security Champion programs across SCRUM teams.
- Provide guidance on secure coding practices
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science/Information Security/IT
- 8–10 years in Application Security / Product Security
- Experience working with engineering teams in Agile/SCRUM environments
- Application Security: VAPT; Web Application Security Testing; API Security Testing; OWASP Top 10
- Security Tools: Burp Suite; Fortify; OWASP ZAP; Nessus / Qualys; Nmap
- DevSecOps: CI/CD security integration; SAST / DAST / SCA; Security automation
- Cloud Security: AWS security fundamentals; Cloud configuration security; IAM and network security basics
Preferred Qualifications (Nice-to-Have)
- Experience in SaaS product companies
- Certifications such as: CEH; OSCP; CISSP; AWS Security Specialty; Certified Application Security Engineer
Location
Pune, India
Equal Opportunity Employer
Gurucul Solutions, LLC is an equal chance employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
To apply:
Please send resumes to
[email protected] for consideration.
📌 Senior / Lead Security Engineer (Pune)
🏢 Gurucul
📍 Pune