DigitalOcean

Senior Product Security Engineer I

DigitalOcean
Apply
3 months ago
Bengaluru, IndiaSenior

Responsibilities

  • Assess security layers across infrastructure, applications, people, and processes.
  • Collaborate with product managers, designers, and engineers on threat modeling and secure, resilient architecture.
  • Review source code against secure-coding practices and contribute security requirements.
  • Design and implement security services, tools, and libraries with secure defaults.
  • Build developer-facing security tools and services, including Semgrep integrations and secrets-management capabilities.
  • Help build a secure and low-risk software-development platform.
  • Promote internal security culture through developer training and internal CTFs.
  • Explain the impact of security events and vulnerabilities such as Log4j CVEs and RetBleed to engineering teams.

Requirements

  • Strong communication and stakeholder-management skills with the ability to explain complex security risks and provide actionable guidance.
  • Hands-on experience with secure code reviews, threat modeling, and writing well-tested code.
  • Comfort with Python, JavaScript, and PHP development.
  • Working knowledge of virtualized environments, containerization, continuous integration and delivery, and public cloud platforms such as AWS and GCP.
  • Hands-on experience with MITRE ATLAS, MAESTRO, and OWASP Top 10 for LLMs/Agents/MCP, including mitigation of prompt injection, data poisoning, and data exfiltration risks.
  • Bachelor’s degree in Computer Science or a related field.
  • At least 3 years of software engineering experience may qualify candidates transitioning into a dedicated security role.
  • Preferred experience includes 5+ years guiding software teams on security architecture design and 5+ years in application security or product security.
  • Experience securing end-to-end AI/ML pipelines across ingestion, training, deployment, inference, and monitoring.
  • Experience creating threat models and malicious-user, attacker, and abuse/misuse cases.
  • Working knowledge of hardware and software supply-chain security.
  • Working knowledge of system and/or application architecture.

Benefits

  • Hybrid work arrangement in Bengaluru, India.
  • Reimbursement for relevant conferences, training, and education.
  • Access to LinkedIn Learning’s 10,000+ courses.
  • Employee Assistance Program, local employee meetups, and flexible time off.
  • Potential bonus and equity compensation, including equity grants upon hire and participation in an Employee Stock Purchase Program.
DigitalOcean

About DigitalOcean

1,001-5,000 employees

DigitalOcean provides cloud infrastructure and platform services for developers, startups, and small to mid-sized businesses, including virtual machines (Droplets), managed Kubernetes and databases, object/block storage, networking, and GPUs for AI workloads. It operates a usage-based, self-service public cloud with APIs, CLI, and a marketplace to deploy and scale applications. Founded in 2012 and headquartered in Broomfield, Colorado, DigitalOcean is a public company listed on the NYSE.

Contact me