Principal Product Security Engineer

Candescent (Digital First Holdings LLC)

Bengaluru

On-site

INR 3,500,000 - 5,500,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Candescent, a forward-thinking technology company, seeks a Principal Product Security Engineer to drive secure SDLC practices in our AI-augmented financial tech stack in Bengaluru.

You will champion shift-left security across CI/CD pipelines, lead threat modeling, and define secure design patterns while integrating third-party AI/LLM services with robust API security and data protections. The role demands 5-7+ years in security engineering within software environments and a hands-on approach.

Qualifications

  • 5-7+ years of experience in security engineering, application security, or product security.
  • Hands-on experience configuring, managing, and automating SAST/DAST/SCA tooling.

Responsibilities

  • Embed threat modeling and security architecture reviews early in the product lifecycle.
  • Pipeline automation: integrate and tune SAST/DAST/SCA in CI/CD workflows.
  • Secure coding practices and OWASP Top 10 awareness and mentoring.
  • Secure AI integration: define patterns, API security, secrets mgmt, data-in-transit protections.
  • Mitigate AI/LLM risks: prompt injection, data leakage, model manipulation.
  • Regulatory alignment for AI security controls and financial norms.

Skills

SAST
DAST
SCA
Threat modeling
CI/CD security
Secure coding practices
OWASP Top 10
AI/LLM security
Cloud security
API security

Tools

CI/CD tooling
SAST tooling
DAST tooling
SCA tooling
Cloud platforms (AWS/Azure/GCP)

Job description

Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutions—creating seamless engagement across digital, remote, and in-person channels.Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growth—turning every customer interaction into a moment of clarity, confidence, and connection.Role SummaryWe are seeking a Principal Product Security Engineer to drive the security posture of Candescent’s applications and services throughout the entire Software Development Lifecycle (SDLC). This is a hands-on practitioner role designed for a senior security professional with a strong foundation in software development or engineering.In this role, you will champion a "shift-left" security culture, embedding core application security practices—including SAST, DAST, SCA, and secure coding standards—directly into modern CI/CD pipelines. Additionally, you will serve as the primary expert responsible for defining secure design patterns and governance for integrating third-party artificial intelligence and large language model (LLM) services across the enterprise.Key Responsibilities and DeliverablesCore Product Security & Shift-Left EngineeringShift-Left Implementation: Partner closely with engineering teams to embed threat modeling, security architecture reviews, and automation early in the product development lifecycle.Pipeline Automation (SAST/DAST/SCA): Own the selection, integration, and tuning of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools within automation pipelines.Vulnerability Management: Analyze tool outputs, filter out false positives, and collaborate directly with developers to provide actionable, prioritized remediation guidance.Secure Coding & Awareness: Define, maintain, and evangelize secure coding best practices based on OWASP Top 10 and real-world threat vectors; conduct technical code reviews and security mentorship for engineering teams.Secure AI Integration & Governance (Specialized Skill Set)Secure AI Architecture: Ability to define and maintain secure integration patterns for third-party AI and LLM services, focusing on API security, authentication, secrets management, and data-in-transit protections.Data Guardrails: Ability to establish and enforce input/output controls, prompt handling standards, and data classification guardrails for AI-enabled applications.Threat Mitigation: Ability to identify and mitigate AI-specific risks including prompt injection, model manipulation, data leakage, adversarial inputs, and shadow AI adoption.Regulatory Compliance: Align internal AI security controls to emerging frameworks (NIST AI RMF, ISO/IEC 42001) and ensure usage satisfies financial regulations (GLBA, PCI DSS, DORA, and NYDFS 23 NYCRR 500).RequirementsExperience & Technical BackgroundSoftware Engineering Foundation: Strong background as a past software developer and/or security practitioner with a verifiable track record in software engineering.AppSec Core: 5-7+ years of experience in security engineering, application security, or product security.Hands-on AppSec Tooling: Proven experience configuring, managing, and automating SAST, DAST, and SCA tooling inside automated enterprise deployment workflows.Cloud & API Expert: Deep expertise in securing cloud-native environments (AWS, Azure, or GCP) and microservices/API-based integrations.AI/ML Security Exposure: Working knowledge of AI/ML enterprise consumer risks (e.g., OWASP LLM Top 10, MITRE ATLAS) and experience securing integrations with major LLM providers.Security Foundations (Any of the following)CISSP — Certified Information Systems Security ProfessionalCCSP — Certified Cloud Security ProfessionalCloud Platform Security Certification — AWS Certified Security - Specialty, AZ-500, or Google Professional Cloud Security EngineerPreferred QualificationsAdvanced AI Credentials: CAISP (Certified AI Security Professional), CAISS, or AIGP (Artificial Intelligence Governance Professional).Regulated Environment Experience: Background working within regulated financial services or a tightly controlled compliance environmentStatement to Third Party AgenciesTo ALL recruitment agencies: Candescent only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, Candescent employees, or any Candescent facility. Candescent is not responsible for any fees or charges associated with unsolicited resumes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Principal Engineer
Software Principal Engineer

Candescent Technologies Corporation • Hyderabad

On-site
INR 2,500,000 - 3,500,000
Principal Engineer - Channels Engineering
Principal Engineer - Channels Engineering

Candescent Technologies Corporation • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Principal Engineer - Channels Engineering
Principal Engineer - Channels Engineering

Capitolis • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Lead Software Product Manager - AI
Lead Software Product Manager - AI

Candescent Technologies Corporation • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Software Principal Engineer - CSP - Branch
Software Principal Engineer - CSP - Branch

Candescent • Hyderabad

On-site
INR 4,600,000 - 7,200,000
Software Principal Engineer - CSP - Imaging
Software Principal Engineer - CSP - Imaging

Candescent • Hyderabad

On-site
INR 2,800,000 - 6,000,000
Software Principal Engineer - CSP - Branch
Software Principal Engineer - CSP - Branch

Candescent (Digital First Holdings LLC) • Hyderabad

On-site
INR 6,000,000 - 10,000,000
Embedded DevOps Engineer III
Embedded DevOps Engineer III

Candescent (Digital First Holdings LLC) • Bengaluru

On-site
INR 1,200,000 - 1,800,000
SW Engineer III - .NET, Angular
SW Engineer III - .NET, Angular

Candescent • Hyderabad

On-site
INR 1,500,000 - 2,700,000
Staff SW Engineer
Staff SW Engineer

Candescent • Bengaluru Urban

On-site
INR 800,000 - 1,200,000