Back to jobs
D
Hiring companyDruva

Verified today

Staff Engineer, Software Security

Pune, Maharashtra, India

About the role

Druva is seeking a Staff Product Security Engineer to join its Pune, India team, bridging traditional AppSec with modern AI security. You will automate shift-left pipelines, conduct threat models for core services and AI architectures, and leverage AI tools to accelerate vulnerability remediation. The role involves partnering with engineering, Information Security, GRC, BuildOps, and DevOps teams to secure SaaS products and safely enable agentic features.

What you’ll do

  • Integrate and maintain automated security controls (SAST, DAST, SCA, Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows
  • Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features
  • Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections, and memory/conte
  • Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes
  • Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems
  • Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network

What you’ll bring

  • 3–5 years of security engineering experience in a SaaS product company
  • Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL)
  • Hands-on experience reviewing AI security risks around Agentic AI systems, MCP security, and LLM security controls
  • Experience using AI tools to optimize security engineering workflows
  • Proficient in code review and scripting with Python, Go, or Javascript
  • Hands-on with tools like Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners
  • Bachelor’s degree in CS/IT or equivalent

Skills

OWASP Top 10CWE 25Threat ModelingCryptographyContainer SecuritySecure SDLCAI SecurityMCP Security

Education

Bachelor’s degree in CS/IT or equivalent