Senior Product Security Engineer

Dun & Bradstreet

Hyderabad

On-site

INR 4,000,000 - 7,000,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Dun & Bradstreet is seeking a Senior Product Security Engineer to design and implement secure-by-design capabilities across the software development lifecycle, with emphasis on application security, API security, software supply chain security, cloud-native product security, and cyber resilience.

The role acts as a senior technical contributor, leading complex reviews and cross-team initiatives while translating product security risk into scalable engineering patterns, automated controls,

Qualifications

  • Experience in application security, product security, software security, DevSecOps, cloud security.
  • Experience with SAST, DAST, SCA, secrets detection, container scanning, IaC scanning, and remediation validation.
  • Strong understanding of software supply chain security, including dependency governance, SBOM, open-source risk, CI/CD controls, artifact integrity, and secure release practices.
  • Experience securing APIs and cloud-native environments, including authentication, authorization, containers, Kubernetes, microservices, and serverless architectures.
  • Understanding of AI security risks, including prompt injection, data leakage, retrieval architectures, agent identity, model and tool permissions, logging, and monitoring.
  • Experience with Python, PowerShell, REST APIs, Terraform, CI/CD platforms, policy-as-code, or related automation.
  • Knowledge of OWASP, NIST, ISO 27001, PCI-DSS, and related standards. Relevant security or cloud certifications are preferred.
  • Strong experience leading threat modeling, secure architecture reviews, abuse-case analysis, and risk-based remediation for complex systems.

Responsibilities

  • Design, implement, and mature Product Security capabilities across application security, API security, software supply chain security, secure SDLC, cloud-native workloads, and resilience engineering.
  • Lead threat modeling, secure architecture reviews, design assessments, and control recommendations for critical products, platforms, APIs, data flows, third-party integrations, and customer-facing services.
  • Drive adoption of secure design patterns and resilience expectations across SDLC, DevSecOps, CI/CD, release, and operational readiness processes.
  • Lead software supply chain improvements involving SCA, SBOM, build pipeline hardening, artifact integrity, secrets prevention, code signing, build provenance, and open-source risk.
  • Perform application and API security assessments utilizing SAST, DAST, SCA, code review findings, API analysis, and remediation validation activities.
  • Develop scalable security patterns, reference architectures, guardrails, and automation that support engineering velocity.
  • Define and guide security controls for AI-enabled products, copilots, autonomous agents, retrieval architectures, model and tool permissions, agent identity, data access, logging, monitoring, and abuse-case testing.
  • Collaborate with IAM, Data Security, Cloud Security, and Security Operations teams to align product security requirements with enterprise security standards and control objectives.
  • Lead risk-based triage, validate exploitability and business impact, improve remediation quality, and drive reduction of recurring vulnerability classes.
  • Lead or support in resilience activities including application risk reviews, incident investigations, tabletop exercises, resilience testing, and post-incident improvement efforts.
  • Research emerging threats, vulnerabilities, attack techniques, and security technologies to improve product security capabilities and engineering practices.
  • Define and communicate metrics, trends, control maturity, remediation progress, and measurable risk reduction to technical leaders and senior stakeholders.
  • Mentor engineers, influence design decisions without direct authority, and lead cross-functional Product Security initiatives.
  • Promote secure development practices through engineering collaboration, documentation, security guidance, and knowledge sharing.

Skills

Application security
Product security
DevSecOps
Cloud security
SAST
DAST
SCA
APIs & cloud-native
AI security
Python
PowerShell
REST APIs
Terraform
CI/CD
Policy-as-code
Kubernetes

Job description

The Senior Product Security Engineer designs, implements, and continuously improves secure-by-design capabilities across the software development lifecycle, with emphasis on application security, API security, software supply chain security, cloud-native product security, and cyber resilience.

The role serves as a senior technical contributor, leading complex reviews and cross-team initiatives while translating product security risk into scalable engineering patterns, automated controls, measurable remediation plans, and secure adoption guidance for emerging technologies.

Key Responsibilities
  • Design, implement, and mature Product Security capabilities across application security, API security, software supply chain security, secure SDLC, cloud-native workloads, and resilience engineering.
  • Lead threat modeling, secure architecture reviews, design assessments, and control recommendations for critical products, platforms, APIs, data flows, third-party integrations, and customer-facing services.
  • Drive adoption of secure design patterns and resilience expectations across SDLC, DevSecOps, CI/CD, release, and operational readiness processes.
  • Lead software supply chain improvements involving SCA, SBOM, build pipeline hardening, artifact integrity, secrets prevention, code signing, build provenance, and open-source risk.
  • Perform application and API security assessments utilizing SAST, DAST, SCA, code review findings, API analysis, and remediation validation activities.
  • Develop scalable security patterns, reference architectures, guardrails, and automation that support engineering velocity.
  • Define and guide security controls for AI-enabled products, copilots, autonomous agents, retrieval architectures, model and tool permissions, agent identity, data access, logging, monitoring, and abuse-case testing.
  • Collaborate with IAM, Data Security, Cloud Security, and Security Operations teams to align product security requirements with enterprise security standards and control objectives.
  • Lead risk-based triage, validate exploitability and business impact, improve remediation quality, and drive reduction of recurring vulnerability classes.
  • Lead or support in resilience activities including application risk reviews, incident investigations, tabletop exercises, resilience testing, and post-incident improvement efforts.
  • Research emerging threats, vulnerabilities, attack techniques, and security technologies to improve product security capabilities and engineering practices.
  • Define and communicate metrics, trends, control maturity, remediation progress, and measurable risk reduction to technical leaders and senior stakeholders.
  • Mentor engineers, influence design decisions without direct authority, and lead cross-functional Product Security initiatives.
  • Promote secure development practices through engineering collaboration, documentation, security guidance, and knowledge sharing.
Key Requirements:
  • Experience in application security, product security, software security, DevSecOps, cloud security, or related cybersecurity disciplines.
  • Experience with SAST, DAST, SCA, secrets detection, container scanning, IaC scanning, and remediation validation.
  • Strong understanding of software supply chain security, including dependency governance, SBOM, open-source risk, CI/CD controls, artifact integrity, and secure release practices.
  • Experience securing APIs and cloud-native environments, including authentication, authorization, containers, Kubernetes, microservices, and serverless architectures.
  • Understanding of AI security risks, including prompt injection, data leakage, retrieval architectures, agent identity, model and tool permissions, logging, and monitoring.
  • Experience with Python, PowerShell, REST APIs, Terraform, CI/CD platforms, policy-as-code, or related automation.
  • Knowledge of OWASP, NIST, ISO 27001, PCI-DSS, and related standards. Relevant security or cloud certifications are preferred.
  • Strong experience leading threat modeling, secure architecture reviews, abuse-case analysis, and risk-based remediation for complex systems.
  • Ability to translate complex technical risk into scalable requirements, reference patterns, remediation strategies, metrics, and senior-leadership narratives.
  • Ability to operate independently, mentor others, influence across organizational boundaries, and drive enterprise outcomes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Architect
Senior Product Security Architect

Cubic Corporation • Telangana

On-site
INR 2,000,000 - 3,000,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Cybersecurity Subject Matter Expert
Cybersecurity Subject Matter Expert

Sunovaa Tech • Pune District, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Lead- Product Security
Lead- Product Security

42 Gears Mobility Systems • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Product Security Specialist
Product Security Specialist

Nokia • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Principal Software Engineer / Engineering Manager – Security
Principal Software Engineer / Engineering Manager – Security

ULTISOURCE • Bengaluru

Hybrid
INR 3,800,000 - 6,800,000
Principal Security Engineer
Principal Security Engineer

Majoris Technologies • Bengaluru

On-site
INR 4,000,000 - 7,000,000