Product Security Engineer, Senior

TraceLink

Pune District

On-site

INR 2,400,000 - 4,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

TraceLink is seeking a senior security contributor to secure AI-enabled products and the SDLC. You will own critical security tasks, perform hands-on assessments, and guide developers on secure coding across Java and JavaScript.

You will lead security reviews, threat modeling, and toolchain operations while advancing security across CI/CD and AI aspects in a global product. This role expects autonomy and deep technical hands-on work.

Qualifications

  • 7+ years in application or product security or software engineering with security ownership.
  • Hands-on experience with threat modeling or risk identification techniques.
  • Strong knowledge of application security testing tools across SAST, SCA, DAST, secrets, IaC.

Responsibilities

  • Serve as senior security SME for engineering by supporting secure architecture, security requirements, and design reviews.
  • Lead threat modeling including abuse and misuse cases for AI-enabled and agentic features.
  • Triage and validate findings from SAST, SCA, DAST and secrets scanning; drive fixes to closure.
  • Hands-on security assessments and white-box testing of services, APIs, and multi-tenant boundaries.
  • Author secure design patterns, guidance, and reusable components for engineering teams.

Skills

Threat modeling
Security ownership
SAST/DAST tooling
Secure coding (Java/JavaScript)
Cloud platforms (AWS/Azure)
CI/CD & automation

Education

Bachelor's degree in CS/IS or related

Tools

SAST
SCA
DAST
Secrets scanning
IaC tooling

Job description

Company overview:

TraceLink is the world’s largest Agentic Business Network, enabling life sciences and healthcare companies to build and manage a scalable digital workforce of governed, no-code AI agents that execute and coordinate mission‑critical supply chain operations alongside human teams. Powered by the Integrate-Once™ OPUS platform, TraceLink links more than 300,000 network participants, enabling multi‑enterprise processes at global scale.

Founded in 2009 with the simple mission of protecting patients, today Tracelink has 5 global offices, over 800 employees and more than 1700 customers in over 60 countries around the world. Our expanding product suite continues to protect patients and now also enhances multi‑enterprise collaboration through innovative new applications such as MINT.

Tracelink is recognized as an industry leader by Gartner and IDC, and for having a great company culture by Comparably.

As part of the Product Security team, you will help secure and advance TraceLink's products and internal application development. Working closely with Product Managers, Architects, Software Engineers, and Security and continually improve how security is built into the software development lifecycle, including AI aspects.

This is a senior individual contributor role. You will take on our hardest and least‑defined product security problems, act as the security technical lead on major products and initiatives, and work with a high degree of autonomy. You are trusted to scope your own work, decide how a problem should be approached, and deliver with minimum supervision. You will remain deeply hands‑on running assessments, reading and writing code, building the tooling and patterns that other engineers reuse.

It increasingly also means securing AI‑enabled product capabilities and the agentic tooling inside our own development pipeline, an area where the right answers are still being written and where we expect you to help work them out.

What you will do:

Partner with Engineering across the SDLC

  • Serve as senior security SME for engineering by supporting secure architecture, security requirements, and design reviews
  • Lead threat modeling including abuse and misuse cases for AI‑enabled and agentic features
  • Secure coding guidance for Java and JavaScript, manual and automated code review, including review of AI‑assisted and agent‑generated code
  • Triage and validate findings from SAST, SCA, DAST and secrets scanning, separating signal from noise and driving fixes to closure and tuning or retiring rules that produce more noise than value
  • Hands‑on security assessments and white‑box testing of services, APIs, and multi‑tenant boundaries
  • Author the secure design patterns, guidance, and reusable components that engineering teams build against by default

Build the paved road

  • Build and improve automation and guardrails in our CI/CD pipelines including pre‑merge checks, policy‑as‑code, and golden paths that make secure the default rather than a gate
  • Use AI and LLM tooling to scale security work by finding triage, code review, test generation, remediation guidance — with human verification of the output
  • Maintain and tune the existing security toolchain, evaluate and pilot new tooling, bringing a clear technical recommendation when it is time to adopt or drop something
  • Drive innovation and maturity in the SDLC with new toolsets and automation
  • Track coverage, false‑positive rate, time to remediate, and act on what they show

Secure our AI features and AI supply chain

  • Review LLM and agent‑backed features for prompt injection, excessive agency and data leakage
  • Maintain clear security guidelines and controls for agentic code contributions, ensuring code review standards, proper attribution, and appropriate access safeguards
  • Implement safeguards that detect and block unapproved or malicious changes introduced by AI agents
  • Apply references such as the OWASP Top 10 for LLM Applications and MITRE ATLAS as practical engineering checklists against real attack paths and write our own guidance wherever necessary

Software supply chain and vulnerability management

  • Maintain supply chain integrity through SBOM accuracy, build provenance, and artifact signing
  • Drive risk‑based vulnerability prioritization using reachability, exploitability, and EPSS against agreed SLAs
  • Serve as technical lead during PSIRT response for significant product vulnerabilities
  • Support customer‑facing vulnerability communications and drive the systemic fixes that prevent recurrence

Grow the practice, inside and out

  • Develop and deliver training, run office hours and threat modeling workshops, and support security champions program
  • Maintain expertise in application security, emerging threat vectors, and attacker tradecraft and improve standards accordingly
  • Represent TraceLink's security practice externally through customer conversations, written content, and conference or community participation
Skills and Requirements:
  • 7+ years in application or product security or software engineering with substantial security ownership
  • Hands‑on experience applying threat modeling or other risk identification techniques
  • Strong knowledge of application security testing tools across SAST, SCA, DAST, secrets, IaC and a clear‑eyed view of what each one does and doesn’t catch
  • Deep understanding of the OWASP Top 10 for web, APIs and AI/LLM, including avoidance and remediation techniques, and the ability to explain real exploitability to an engineer
  • Strong knowledge of secure coding practices in Java and/or JavaScript able to read code fluently and submit remediation pull requests
  • Experience remediating complex enterprise‑level security issues end to end
  • Working knowledge of cloud environments (ideally AWS and Azure) and CI/CD pipelines
  • A working understanding of how LLM‑based features and AI coding assistants change the risk picture and the curiosity to go deeper
  • Strong analytical and problem‑solving skills
  • Strong verbal and written communication skills, with both engineering and non‑engineering audiences

Preferred Skills:

  • Familiarity with AWS and Azure services
  • Knowledge of microservices, event‑driven architecture and multi‑tenant SaaS isolation
  • Experience with ASPM platforms and reachability‑based vulnerability prioritization
  • Experience securing or red teaming AI, ML, or agentic systems
  • Penetration testing, CTF experience, a hacker's mindset
  • Bachelor's degree or equivalent experience in Computer Science, Information Systems Security, or a related field

Please see the Tracelink Privacy Policy for more information on how Tracelink processes your personal information during the recruitment process and, if applicable based on your location, how you can exercise your privacy rights. If you have questions about this privacy notice or need to contact us in connection with your personal data, including any requests to exercise your legal rights referred to at the end of this notice, please contact Candidate-Privacy@tracelink.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Product Security Engineer
Sr Product Security Engineer

Tracelink • Pune District

On-site
INR 300,000 - 600,000
Software Engineer, Senior
Software Engineer, Senior

TraceLink • Pune District

On-site
INR 1,800,000 - 3,200,000
Cloud Engineer II
Cloud Engineer II

TraceLink, Inc • Pune District

On-site
INR 2,000,000 - 3,500,000
Cloud Engineer II
Cloud Engineer II

TraceLink • Pune District

On-site
INR 1,800,000 - 2,400,000
Software Engineer Intern
Software Engineer Intern

TraceLink, Inc • Pune District

On-site
INR 1,800,000 - 2,400,000
Senior Software Engineer in Test - Agentic AI
Senior Software Engineer in Test - Agentic AI

TraceLink • Pune District

On-site
INR 800,000 - 1,200,000
Senior Product Security Engineer
Senior Product Security Engineer

Whatfix Inc. • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Security Software Engineer
Security Software Engineer

Teradyne • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Product Security Engineer
Senior Product Security Engineer

Whatfix • Bengaluru

On-site
INR 4,200,000 - 7,000,000
AI Security Engineer (Teradyne, India)
AI Security Engineer (Teradyne, India)

Teradyne • Bengaluru

On-site
INR 4,000,000 - 6,000,000