Staff Engineer, Software Security
Druva•2w ago
Pune, Maharashtra, IndiaOnsiteFull-timeStaff Level7+ yrs exp
Top focus
Staff EngineerSoftware EngineerSecurity EngineerSoftware Engineer Ii
- About Druva
- Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity
- AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint
- edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond faster, recover cleanly
- govern data with greater confidence.
- Trusted by nearly 7,500 customers, including 75 of the Fortune 500, Druva helps safeguard the critical information and systems businesses depend on in an increasingly connected world.
- Visit druva.com and follow us on LinkedIn , X and Facebook .
- We are looking for a hands-on Staff Product Security Engineer to join our team. In this role, you will bridge traditional AppSec with modern AI security - automating shift-left pipelines, conducting threat models for core services and AI architectures
- leveraging AI tools to accelerate vulnerability remediation. You will partner directly with engineering, Information Security, GRC, BuildOps & DevOps teams to secure our SaaS products and safely enable cutting-edge agentic features
What You Will Do
- Shift-Left Automation & DevSecOps: Integrate and maintain automated security controls (SAST, DAST, SCA,Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows.
- Operational & Strategic AI Security: Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features.
- AI & Emerging Tech Threat Modeling: Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections
- memory/context poisoning (OWASP Top 10 for LLMs / Agentic Apps).
- Developer Guidance & Vulnerability Remediation: Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes.
- Supply Chain & Software Integrity: Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems.
- Enablement & Champions Program: Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network.
- What you will bring in:
- Experience: 3–5 years of security engineering experience in a SaaS product company.
- AppSec Fundamentals: Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).
- AI Security Expertise: Hands-on experience reviewing AI security risks - specifically around Agentic AI systems, MCP security (authorization, tool poisoning, confused deputy risks), and LLM security controls.
- Operational AI Use-Cases: Experience using AI tools to optimize security engineering workflows (e.g., automating root-cause analysis, threat modeling assistance, automated policy generation).
- Programming & Tooling: Proficient in code review and scripting with Python, Go
- Javascript (hands-on development experience is a major plus). Hands-on with tools like Burp Suite, Snyk, OWASP ZAP
- CI/CD security scanners.
- Education & Certifications: Bachelor’s degree in CS/IT or equivalent. Relevant certifications (OSCP, OSWE, CSSLP, GIAC) or active community contributions (OWASP, BSides, NullCon, Black Hat, etc) are a plus.
Required skills
PythonJavaScriptGoLLMCI/CDSecurity