Staff Engineer, Software Security

Druva · Pune, Maharashtra, India

onsitefull-time6-10 years

posted 17 Aug

Sign in to apply

<p><strong>About Druva</strong><strong><br></strong>Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity, and AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint, and edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond faster, recover cleanly, and govern data with greater confidence.<br><br>Trusted by nearly 7,500 customers, including 75 of the Fortune 500, Druva helps safeguard the critical information and systems businesses depend on in an increasingly connected world.</p> <p>Visit<a href="https://www.druva.com/"> druva.com</a> and follow us on <a href="https://www.linkedin.com/company/druva/mycompany/">LinkedIn</a>, <a href="https://twitter.com/druvainc">X</a> and <a href="https://www.facebook.com/DruvaInc/">Facebook</a>.</p> <p>We are looking for a hands-on <strong>Staff Product Security Engineer</strong> to join our team. In this role, you will bridge traditional AppSec with modern AI security - automating shift-left pipelines, conducting threat models for core services and AI architectures, and leveraging AI tools to accelerate vulnerability remediation. You will partner directly with engineering,&nbsp; Information Security, GRC, BuildOps &amp; DevOps teams to secure our SaaS products and safely enable cutting-edge agentic features.</p> <h3><strong>What you will do:</strong></h3> <ul> <li><strong>Shift-Left Automation &amp; DevSecOps:</strong> Integrate and maintain automated security controls (SAST, DAST, SCA,Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows.</li> <li><strong>Operational &amp; Strategic AI Security:</strong> Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features.</li> <li><strong>AI &amp; Emerging Tech Threat Modeling:</strong> Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections, and memory/context poisoning (OWASP Top 10 for LLMs / Agentic Apps).</li> <li><strong>Developer Guidance &amp; Vulnerability Remediation:</strong> Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes.</li> <li><strong>Supply Chain &amp; Software Integrity:</strong> Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems.</li> <li><strong>Enablement &amp; Champions Program:</strong> Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network.</li> </ul> <h3><strong>What you will bring in:</strong></h3> <ul> <li><strong>Experience:</strong> 3–5 years of security engineering experience in a SaaS product company.</li> <li><strong>AppSec Fundamentals:</strong> Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).</li> <li><strong>AI Security Expertise:</strong> Hands-on experience reviewing AI security risks - specifically around Agentic AI systems, MCP security (authorization, tool poisoning, confused deputy risks), and LLM security controls.</li> <li><strong>Operational AI Use-Cases:</strong> Experience using AI tools to optimize security engineering workflows (e.g., automating root-cause analysis, threat modeling assistance, automated policy generation).</li> <li><strong>Programming &amp; Tooling:</strong> Proficient in code review and scripting with Python, Go, or Javascript (hands-on development experience