14 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Define, evolve, and execute Product Security and Secure SDLC strategies using security automation, risk-based gates, and developer-friendly workflows.
- Lead threat modeling and security design reviews for multi-tenant SaaS applications, microservices, cloud-native infrastructure, and AI/LLM integrations.
- Perform hands-on AI/LLM security assessments for risks including prompt injection, jailbreaks, data poisoning, insecure output handling, excessive agency, and model abuse.
- Architect identity, OAuth 2.0, OIDC, PKI, and zero-trust controls, including resilient data-boundary isolation.
- Build and integrate automated security scanners and continuous testing guardrails across CI/CD and LLMOps workflows.
- Create security blueprints, reference designs, secure code patterns, and supply chain security controls including SBOM management and dependency risk tracking.
- Provide Staff-level technical direction and mentorship while collaborating with cloud platform, data engineering, AI/ML, product, and engineering teams.
- Participate in customer security calls and technical discussions covering architecture, compliance, risk assessments, and security requirements.
Requirements
- 8+ years of progressive experience in Product Security, Application Security, or Product Security Engineering in SaaS or cloud-native environments.
- Deep expertise in threat modeling, Azure cloud architecture, API security, microservices design, and DevSecOps tooling.
- Hands-on experience identifying and mitigating risks in AI/LLM architectures, including RAG, vector databases, agentic frameworks, and fine-tuning pipelines.
- Strong practical knowledge of OAuth 2.0, OIDC, PKI, and zero-trust concepts.
- Ability to write maintainable security automation scripts or tools using Python, Go, or similar languages.
- Proven ability to lead through influence, communicate technical risks to executive stakeholders, and guide senior engineers at Staff/Principal level.
- Experience implementing software supply chain frameworks such as SLSA and NIST SSDF, including dependency scanning, attestation, and component risk management.
- Hands-on experience with Trivy, Jenkins, GitHub, GitHub Actions, TruffleHog, Checkmarx One, and Burp Suite for automated security checks and CI/CD integration.
About Whatfix
Whatfix builds a digital adoption platform for enterprises, delivered as SaaS, that provides in-app guidance, hands-on simulation training (Mirror), and adoption/product analytics to improve how users learn and use software. Companies use it across internal and customer-facing applications to onboard users, standardize workflows, and reduce support needs. Founded in 2013 and headquartered in San Jose, CA, the company is privately held and operates globally.
