Every line of code that ships inRubiscape’s platform touches sensitive enterprise data, AI model outputs, andbusiness-critical decisions for Fortune 500 customers. As an ApplicationSecurity Engineer, you will be the security champion embedded in the softwaredevelopment lifecycle — owning SAST/DAST tooling, secure code review, anddeveloper security enablement across Rubiscape’s six studios. You willtransform AppSec from a gate into a growth accelerator, ensuring that Rubiscapeships fast without trading away the security posture that enterprise customersand government deployments require.
Key Responsibilities
- Integrate and operate SAST(SonarQube, Semgrep) and DAST (OWASP ZAP, Burp Suite) tooling into CI/CDpipelines; define severity thresholds and enforce build-break policies.
- Perform security design reviewsand secure code reviews for high-risk features including RubiAI promptinjection surfaces, RubiStudio model serving endpoints, and multi-tenant dataisolation in RubiSight.
- Maintain and continuouslyupdate Rubiscape’s secure development lifecycle (SDL) standards, OWASP Top 10 /API Security Top 10 mappings, and language-specific secure coding guidelines.
- Run bug bounty triage,coordinate responsible disclosure processes, and manage external penetrationtesting engagements end-to-end.
- Build automated dependency andSCA scanning (Snyk, Dependabot) into the build process; own the third-partylibrary vulnerability backlog and drive resolution within policy SLAs.
- Deliver secure codingworkshops, threat modelling training, and security champions programme forRubiscape’s engineering guilds.
- Produce application-layersecurity findings for SOC 2, ISO 27001, and customer security audits; liaisewith GRC on evidence collection and control mapping.
Nice to Have
- Certifications: OSWE, GWEB, orBSCP (PortSwigger Web Security).
- Experience securing LLM/GenAIapplication surfaces including prompt injection, model inversion, and dataexfiltration via AI APIs.
- Familiarity with supply-chainsecurity standards (SLSA, SBOM generation, Sigstore).
- Prior work on a multi-tenantB2B SaaS platform serving regulated-sector enterprise customers.
About Rubiscape
Rubiscape is India’s leading DecisionIntelligence Platform, unifying data engineering, BI, machine learning, andagentic AI in a single governed platform. Built in Pune and trusted by Fortune500 enterprises across BFSI, manufacturing, healthcare, and government. 8international innovation patents. 10 Industry-Academia Labs & COEs. From BIto AI — One Platform. Every Decision.
Requirements
- 3+ years of applicationsecurity experience in a product engineering environment with a shipped SaaS orenterprise software product.
- Demonstrated hands-on skillwith SAST/DAST tools and CI/CD integration (GitHub Actions, Jenkins, or GitLabCI).
- Strong understanding of OWASPTop 10, API Security Top 10, and common web application vulnerability classes(SQLi, XSS, SSRF, IDOR, prompt injection).
- Ability to read and review codein at least two of: Python, Java, TypeScript/Node.js, Go.
- Experience managing SCA toolingand coordinating remediation of CVEs in third-party dependencies.