HamburgerMenu
hirist

Druva - Staff Engineer - Software Security

Druva Data Solutions
3 - 6 Years
Pune

Posted on: 18/08/2026

Job Description

About the Role :

Druva is looking for a hands-on Staff Product Security Engineer to bridge traditional AppSec with modern AI security. You will automate shift-left pipelines, conduct threat models for core services and AI architectures, and leverage AI tools to accelerate vulnerability remediation.

What You Will Do :

- Shift-Left Automation & DevSecOps: Integrate and maintain automated security controls (SAST, DAST, SCA, Container, Secrets Detection) directly into CI/CD build pipelines and developer workflows.

- Operational & Strategic AI Security: Leverage AI tooling operationally (e.g., auto-triage, threat-model drafting, fix generation) while strategizing security controls for product-facing AI features.

- AI & Emerging Tech Threat Modeling: Assess risks specific to Generative and Agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injections, and memory/context poisoning (OWASP Top 10 for LLMs / Agentic Apps).

- Developer Guidance & Vulnerability Remediation: Review code (Python, Go, Javascript, etc), triage findings, and partner with engineering to implement robust short and long-term security fixes.

- Supply Chain & Software Integrity: Manage third-party open-source risks, open-source dependency tracking, Software Bills of Materials (SBOMs), and secure MCP/agent server ecosystems.

- Enablement & Champions Program: Conduct secure coding workshops, train developers on secure AI usage, and help grow an active Security Champions network.

What You Will Bring :

- Experience: 3+ years of security engineering experience in a SaaS product company.

- AppSec Fundamentals: Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks (SAMM, Microsoft SDL).

- AI Security Expertise: Hands-on experience reviewing AI security risks - specifically around Agentic AI systems, MCP security (authorization, tool poisoning, confused deputy risks), and LLM security controls.

- Operational AI Use-Cases: Experience using AI tools to optimize security engineering workflows (e.g., automating root-cause analysis, threat modeling assistance, automated policy generation).

- Programming & Tooling: Proficient in code review and scripting with Python, Go, or Javascript. Hands-on with tools like Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners.

- Education & Certifications: Bachelors degree in CS/IT or equivalent. Relevant certifications (OSCP, OSWE, CSSLP, GIAC) or active community contributions (OWASP, BSides, NullCon, Black Hat, etc) are a plus.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...