2 hours ago
Responsibilities
- Integrate and maintain SAST, DAST, SCA, container, and secrets-detection controls in CI/CD pipelines and developer workflows.
- Use AI tooling for security operations such as auto-triage, threat-model drafting, and fix generation, while defining controls for product-facing AI features.
- Threat-model generative and agentic AI architectures, including MCP integrations, autonomous agents, tool-calling interfaces, multi-agent communication, prompt injection, and memory or context poisoning risks.
- Review Python, Go, and JavaScript code, triage security findings, and partner with engineering on short- and long-term remediation.
- Manage third-party open-source risks, dependency tracking, SBOMs, and secure MCP and agent-server ecosystems.
- Conduct secure-coding workshops, train developers on secure AI usage, and grow the Security Champions network.
- Partner with engineering, Information Security, GRC, BuildOps, and DevOps teams to secure Druva’s SaaS products.
Requirements
- 3–5 years of security engineering experience in a SaaS product company.
- Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks including SAMM and Microsoft SDL.
- Hands-on experience assessing Agentic AI systems, MCP security, authorization, tool poisoning, confused deputy risks, and LLM security controls.
- Experience using AI tools for root-cause analysis, threat-modeling assistance, automated policy generation, or similar security workflows.
- Proficiency in code review and scripting with Python, Go, or JavaScript; hands-on development experience is a major plus.
- Hands-on experience with Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners.
- Bachelor’s degree in Computer Science or Information Technology, or equivalent experience.
- Relevant certifications such as OSCP, OSWE, CSSLP, or GIAC are preferred.
- Active contributions to communities or events such as OWASP, BSides, NullCon, or Black Hat are preferred.
Tech Stack
Categories
About Druva
Druva is the leading provider of data security solutions, empowering customers to secure and recover their data from all threats. The Druva Data Security Cloud is a fully managed SaaS solution offering air-gapped and immutable data protection across cloud, on-premises, and edge environments. By centralizing data protection, Druva enhances traditional security measures and enables faster incident response, effective cyber remediation, and robust data governance.