Posted on: 18/08/2026
About the Role :
Druva is looking for a hands-on Staff Product Security Engineer to bridge traditional AppSec with modern AI security. You will automate shift-left pipelines, conduct threat models for core services and AI architectures, and leverage AI tools to accelerate vulnerability remediation.
What You Will Do :
- Shift-Left Automation & DevSecOps: Integrate and maintain automated security controls (SAST, DAST, SCA, Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows.
- Operational & Strategic AI Security: Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features.
- AI & Emerging Tech Threat Modeling: Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections, and memory/context poisoning (OWASP Top 10 for LLMs / Agentic Apps).
- Developer Guidance & Vulnerability Remediation: Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes.
- Supply Chain & Software Integrity: Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems.
- Enablement & Champions Program: Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network.
What You Will Bring :
- Experience: 3+ years of security engineering experience in a SaaS product company.
- AppSec Fundamentals: Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).
- AI Security Expertise: Hands-on experience reviewing AI security risks - specifically around Agentic AI systems, MCP security (authorization, tool poisoning, confused deputy risks), and LLM security controls.
- Operational AI Use-Cases: Experience using AI tools to optimize security engineering workflows (e.g., automating root-cause analysis, threat modeling assistance, automated policy generation).
- Programming & Tooling: Proficient in code review and scripting with Python, Go, or Javascript. Hands-on with tools like Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners.
- Education & Certifications: Bachelors degree in CS/IT or equivalent. Relevant certifications (OSCP, OSWE, CSSLP, GIAC) or active community contributions (OWASP, BSides, NullCon, Black Hat, etc) are a plus.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1664104