Whatfix

Senior Product Security Engineer

Whatfix
Apply
14 hours ago
Bengaluru, IndiaSenior

Responsibilities

  • Define, evolve, and execute Product Security and Secure SDLC strategies using security automation, risk-based gates, and developer-friendly workflows.
  • Lead threat modeling and security design reviews for multi-tenant SaaS applications, microservices, cloud-native infrastructure, and AI/LLM integrations.
  • Perform hands-on AI/LLM security assessments for risks including prompt injection, jailbreaks, data poisoning, insecure output handling, excessive agency, and model abuse.
  • Architect identity, OAuth 2.0, OIDC, PKI, and zero-trust controls, including resilient data-boundary isolation.
  • Build and integrate automated security scanners and continuous testing guardrails across CI/CD and LLMOps workflows.
  • Create security blueprints, reference designs, secure code patterns, and supply chain security controls including SBOM management and dependency risk tracking.
  • Provide Staff-level technical direction and mentorship while collaborating with cloud platform, data engineering, AI/ML, product, and engineering teams.
  • Participate in customer security calls and technical discussions covering architecture, compliance, risk assessments, and security requirements.

Requirements

  • 8+ years of progressive experience in Product Security, Application Security, or Product Security Engineering in SaaS or cloud-native environments.
  • Deep expertise in threat modeling, Azure cloud architecture, API security, microservices design, and DevSecOps tooling.
  • Hands-on experience identifying and mitigating risks in AI/LLM architectures, including RAG, vector databases, agentic frameworks, and fine-tuning pipelines.
  • Strong practical knowledge of OAuth 2.0, OIDC, PKI, and zero-trust concepts.
  • Ability to write maintainable security automation scripts or tools using Python, Go, or similar languages.
  • Proven ability to lead through influence, communicate technical risks to executive stakeholders, and guide senior engineers at Staff/Principal level.
  • Experience implementing software supply chain frameworks such as SLSA and NIST SSDF, including dependency scanning, attestation, and component risk management.
  • Hands-on experience with Trivy, Jenkins, GitHub, GitHub Actions, TruffleHog, Checkmarx One, and Burp Suite for automated security checks and CI/CD integration.

Tech Stack

AzureGitHub ActionsGoJenkinsPython

Categories

Whatfix

About Whatfix

1,001-5,000 employees

Whatfix builds a digital adoption platform for enterprises, delivered as SaaS, that provides in-app guidance, hands-on simulation training (Mirror), and adoption/product analytics to improve how users learn and use software. Companies use it across internal and customer-facing applications to onboard users, standardize workflows, and reduce support needs. Founded in 2013 and headquartered in San Jose, CA, the company is privately held and operates globally.

Contact me