Software Principal Engineer

RSA Security

Bengaluru

On-site

INR 2,800,000 - 5,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RSA Security is seeking a Principal Security Engineer to act as the technical authority for our product’s security posture in Bengaluru. You will dive into the Java ecosystem, triage complex vulnerabilities, and architect fixes in a high-impact backend environment.

You will own vulnerability management, perform deep threat modeling, mentor teams on secure design, and guide cryptographic strategy with RSA BSAFE to maintain FIPS compliance.

Qualifications

  • 8-10 years of backend Java engineering and security research experience.
  • Proven track record fixing vulnerabilities in large-scale Java production environments.
  • Relevant certifications (CISSP, CSSLP, OSCP, or GWEB) are a plus but not a substitute for hands-on work.

Responsibilities

  • Own vulnerability management lifecycle for customer-reported issues and automated scans.
  • Triaging and analyzing reports for severity, exploitability, and business impact; decide false positives.
  • Design and implement high-quality fixes in a complex Java backend environment.
  • Mentor product teams to embed Security by Design into the development lifecycle.
  • Conduct threat modeling and architectural reviews to prevent weaknesses before production.
  • Lead strategy for legacy cryptographic implementations, focusing on RSA BSAFE compliance.

Skills

Java (Core & Enterprise)
PKI Architecture
Security by Design
Threat Modeling
Cloud & Container Security

Education

CISSP
CSSLP
OSCP
GWEB

Tools

Nessus
Veracode
Burp Suite

Job description

About the Role :

As a Principal Security Engineer, you will serve as the technical authority for our product’s security posture. This is a high-impact role that bridges the gap between customer trust and backend engineering. You won’t just be “checking boxes” - you will be diving deep into the Java ecosystem to triage complex vulnerabilities, architecting fixes for critical flaws, and distinguishing genuine threats from false positives.

Key Responsibilities:
  • Vulnerability Management: Own the lifecycle of security issues reported by customers, and automated scans.
  • Triage & Analysis: Expertly analyze incoming reports to determine severity, exploitability, and business impact. You will be the final word on “False Positives.”
  • Hands-on Remediation: Design and implement high-quality, performant fixes within a complex Java backend environment.
  • Security Mentorship: Act as a consultant to product teams, ensuring “Security by Design” is integrated into the development lifecycle.
  • Threat Modeling: Conduct deep-dive architectural reviews to identify potential weaknesses before they reach production.
  • Direct the strategy for maintaining or migrating legacy cryptographic implementations, specifically utilizing RSA BSAFE (Crypto-J / SSL-J) to ensure FIPS 140-2/3 compliance.
Required Technical Expertise:
  • The Java Specialist: Deep expertise in Java (Core and Enterprise) and common frameworks (Spring Boot, Hibernate). You should be able to read and debug complex code
  • PKI Architecture : Hands on skills in design and maintenance of the Public Key Infrastructure - Integration between Certificate Authorities (CAs), Registration Authorities (RAs), and the Java application layer.
  • Security Native: Strong understanding of the OWASP Top 10 and common attack vectors (XSS, SQLi, CSRF, SSRF, Deserialization flaws).
  • The Tooling: Experience with SAST, DAST, and SCA tools (e.g., "Nessus, Veracode, or Burp Suite").
  • Cloud & Infrastructure: Familiarity with securing cloud-native applications (AWS/Azure/GCP) and containerized environments (Docker/Kubernetes).
Qualifications
  • 8-10 years of experience in Backend Engineering in Java and/or Security Research.
  • Proven track record of fixing vulnerabilities in a large-scale Java production environment.
  • Relevant certifications (CISSP, CSSLP, OSCP, or GWEB) are a significant plus but not a substitute for hands-on experience.

RSA is committed to the principle of equal employment opportunity for all employees and applicants for employment and to providing employees with a work environment free of discrimination and harassment. All qualified applicants will receive consideration for employment without regard to race, color, and any other category protected by applicable country law.

If you need a reasonable accommodation during the application process, please contact the RSA Talent Acquisition Team at rsa.global.talent.acquisition@rsa.com. RSA and its approved consultants will never ask you for a fee to process or consider your application for a career with RSA. RSA reserves the right to amend or withdraw any job posting at any time, including prior to the advertised closing date.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Principal Engineer
Software Principal Engineer

RSA Security USA LLC • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Advisor, Cybersecurity Engineering
Advisor, Cybersecurity Engineering

RSA Security • Bengaluru

On-site
INR 1,200,000 - 2,100,000
Remote work not specified
Advisor, Cybersecurity Engineering
Advisor, Cybersecurity Engineering

RSA Security USA LLC • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Specialist, Application Security
Specialist, Application Security

Pearson • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Principal Product Manager
Principal Product Manager

RSA Security • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Sr. Security Engineer, Stores Application Security
Sr. Security Engineer, Stores Application Security

Amazon • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Principal DevOps Engineer
Principal DevOps Engineer

RSA Security • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Principal Product Manager
Principal Product Manager

RSA Security USA LLC • Bengaluru

On-site
INR 3,500,000 - 6,500,000