Product Security Engineer

Jaggaer

Hyderabad

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Accidental Insurance
Term Life

Job summary

JAGGAER in India seeks a Product Security Engineer to strengthen security across the Software Development Life Cycle, including AI/ML-enabled products, reporting to the Director of Cyber Architecture & Defense.

You will collaborate with development, platform, and AI engineering teams to embed security practices, run DAST/SAST assessments, manage SBOMs, and oversee third‑party penetration testing to ensure product security posture.

Qualifications

  • 5+ years in product or application security focused on SDLC.

Responsibilities

  • Integrate security into the SDLC; model threats and perform penetration tests.
  • Conduct security assessments using DAST/SAST tools.
  • Own software supply chain security and SBOM management.
  • Assess AI/ML security risks and OWASP Top10 variants.

Skills

Python
Java
Application security
Security assessments
Cloud security
Communication skills

Education

Bachelor's degree in Computer Science or Information Security

Tools

DAST/SAST tools
Vulnerability management platforms
SBOM generation tools
Software Composition Analysis (SCA)

Job description

Overview

About JAGGAER

JAGGAER provides an intelligent Source-to-Pay and Supplier Collaboration Platform that empowers organizations to manage and automate complex processes while enabling a highly resilient, responsible, and integrated supplier base. With 30 years of expertise, we specialize in solving complex procurement and supply chain challenges across various industries.

Our 1,200+ global employees are obsessed with ensuring customers get full value from our products—ultimately enhancing and transforming their businesses.

For more information, visit www.jaggaer.com

Product Security Engineer – AI & Application Security | Cyber Architecture & Defense

Overview

Why Consider JAGGAER? JAGGAER is the world's leading provider of comprehensive source-to-pay solutions. Some of the largest commercial, manufacturing, and life sciences companies, and government organizations in the world, trust JAGGAER with billions of dollars of annual spend. JAGGAER eProcurement and strategic sourcing customers across the globe have gained access to the best suppliers, with the best terms, on our scalable, customizable, user-friendly platform. Our SaaS‑based, source‑to‑settle solution provides unparalleled visibility, insights, and recommendations to procurement leaders and suppliers, driving a fluid supply chain through powerful spend analysis, comprehensive contract management, and efficient accounts payable solutions.

What We're Looking For

Reporting to the Director of Cyber Architecture & Defense, we are seeking a Product Security Engineer with a strong background in application and product security, and working exposure to the security challenges introduced by AI‑powered and agentic platforms. This role designs, implements, and coordinates a comprehensive security strategy across the Software Development Life Cycle (SDLC) – including our AI/ML‑enabled product lines – and is responsible for identifying, assessing, and reporting security vulnerabilities across our products and applications. You will partner closely with development, platform, and AI engineering teams to embed security practices, run security assessments using industry‑standard DAST/SAST and vulnerability management tooling, evaluate risk in agentic AI and LLM‑integrated features, and oversee third‑party penetration testing activities.

Principal Responsibilities
  • Collaborate with product and platform development teams to integrate security into the SDLC by modeling threats, identifying vulnerabilities, and performing penetration tests, applying frameworks such as the OWASP Top10 and OWASP API Security Top10.
  • Conduct security assessments using dynamic application security testing (DAST) and static application security testing (SAST) tools.
  • Own software supply chain security for the product portfolio — software composition analysis (SCA) of third‑party and open‑source libraries, dependency and SBOM management, and remediation of vulnerabilities introduced through the build and release pipeline.
  • Assess security risks specific to AI/ML‑powered features and agentic AI platforms, applying frameworks such as the OWASP LLM Top10 and OWASP AgenticAI Top10 to identify issues like prompt injection, insecure output handling, and excessive agency.
  • Review AI‑assisted software development workflows (e.g., AI coding assistants) and contribute to secure usage guidelines and guardrails for engineering teams.
  • Support cross‑tenant and multi‑tenant risk assessments for SaaS products with AI/ML components deployed across GCP, AWS, and Azure.
  • Perform technical risk assessments, evaluate DAST/SAST and AI security tool results, triage findings, and manage security response actions through to resolution.
  • Oversee third‑party penetration testing activities, objectively prioritizing findings, identifying critical risks, and adhering to compliance requirements.
  • Support the company's Vulnerability Disclosure Program (VDP) — triaging externally reported findings, coordinating remediation with product teams, and managing researcher communication through resolution.
  • Manage vulnerabilities and incidents across the product portfolio to ensure swift, well‑documented resolution.
  • Develop and maintain a balanced product security program grounded in well‑defined application and AI security frameworks.
  • Partner with development teams and architects to design, implement, and continuously improve application and AI security controls.
  • Support compliance activities including customer security audits, regulatory compliance projects, and information security reviews.
  • Participate in offensive security exercises alongside security operations.
  • Serve as a security champion — promoting a culture of security and raising awareness of secure development and AI usage practices across the organization.
  • Stay current with security, AI, and threat landscape trends, and recommend improvements to posture and tooling.
  • Maintain functional understanding of common compliance and AI governance frameworks, including NIST800‑53, ISO27001, PCIDSS, SOC2 TypeII, CSACCM, NISTAIRMF, and ISO/IEC42001.
Position Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in product or application security, with a focus on the software development life cycle.
  • Proficient in Python, Java, or other programming languages.
  • Experience with industry‑standard DAST/SAST tools and vulnerability management platforms.
  • Experience with software composition analysis (SCA), SBOM generation, and software supply chain security practices.
  • Experience running or supporting a Vulnerability Disclosure Program (VDP) or bug bounty program is a plus.
  • Working knowledge of web application, network, and cloud security across multi‑cloud environments (GCP, AWS, Azure).
  • Familiarity with AI/LLM security concepts and agentic AI systems (e.g., prompt injection, model supply chain risk, secure tool‑use/harness design) is a strong plus.
  • Strong analytical and problem‑solving skills.
  • Excellent communication and collaboration skills, with the ability to work across security, engineering, and AI/product teams.
  • Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), or similar certifications are a plus.
What We Offer
  • Health
  • Accidental Insurance
  • Term Life
Our Values – T.E.A.M

At JAGGAER, our business is about people.Our products are built on intellectual property, but the real differentiator is the teams behind them–the way we collaborate, innovate, solve problems and deliver for customers. TEAM gives us a common set of expectations for how we work together across products, cultures, and geographies.

Transparency – Openness Builds Trust: Candor strengthens relationships, speeds decision‑making, and ensures problems are solved together—with customers, teammates, and partners.

Entrepreneurial Spirit – Own It, Drive It, Make It: A scrappy, customer obsessed, problem‑solving mindset is at the cornerstone of both organizational and personal growth.

Accountability – Thumbs In, Not Fingers Out: We take responsibility ourselves before pointing elsewhere.

Metrics‑Driven Results – Outcomes Over Activities: Data and evidence guide our decisions, help us course‑correct quickly, and ensure we’re delivering real impact.

EEO

EEO: JAGGAER is a proud equal opportunity/affirmative action employer supporting workforce diversity. We do not discriminate based upon race, ethnicity, ancestry, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), marital status, caregiver status, sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, genetic information, military, or veteran status, mental or physical disability, or other applicable legally protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

JAGGAER • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Health
Accidental Insurance
Term Life
Principal Data Scientist
Principal Data Scientist

JAGGAER • Hyderabad

On-site
INR 5,000,000 - 7,500,000
Health benefits
Accidental Insurance
Term Life
Associate GCC Analyst
Associate GCC Analyst

JAGGAER • Telangana

On-site
INR 500,000 - 750,000
Health benefits
Accidental Insurance
Term Life
Principal Data Scientist
Principal Data Scientist

JAGGAER • Telangana

On-site
INR 3,500,000 - 6,000,000
Health insurance
Accidental Insurance
Term Life
SW Engineer - Workato Integrations
SW Engineer - Workato Integrations

JAGGAER • Hyderabad

On-site
INR 1,200,000 - 2,100,000
Health Insurance
Accidental Insurance
Term Life
SW Engineer -- Workato Integrations
SW Engineer -- Workato Integrations

JAGGAER • Hyderabad

On-site
INR 1,500,000 - 2,600,000
Health insurance
Accidental Insurance
Term Life
Vulnerability Analyst
Vulnerability Analyst

JAGGAER • Hyderabad

On-site
INR 800,000 - 1,500,000
Health insurance
Accidental Insurance
Term Life
Founding Member, Senior AI & Application Security Specialist (Delhi NCR - Hybrid)
Founding Member, Senior AI & Application Security Specialist (Delhi NCR - Hybrid)

J.S. Held LLC • Delhi

Hybrid
INR 3,600,000 - 7,200,000
Remote work flexibility
Generous annual leave
Digital Marketing Manager
Digital Marketing Manager

JAGGAER • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Health Insurance
Accidental Insurance
Term Life
Cloud Engineer
Cloud Engineer

JAGGAER • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Health Insurance
Accidental Insurance
Term Life