Staff Security Engineer II - Application Security - Confluent

IBM

Bengaluru

On-site

INR 4,000,000 - 6,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Confluent in Bengaluru seeks a Staff Application Security Engineer to shape the security posture of our distributed platforms across on‑prem and cloud environments. You will partner with Engineering and Product leadership to embed security by design, drive threat modeling, and build scalable security automation that reduces risk while accelerating software delivery.

You will also lead security reviews, foster a strong security culture, and mentor engineers across the organization in secure

Qualifications

  • 10–12 years of hands‑on Application Security experience in large‑scale distributed systems and global engineering teams.
  • Strong knowledge of web applications and cloud‑native platforms, secure design and architecture, and vulnerability classes.
  • Ability to partner with Engineering and Product leadership to embed security into core architecture.
  • Experience investigating incidents and driving preventive improvements through architecture and automation.
  • Experience evolving SDLC to embed security by default, securing CI/CD pipelines and deployment workflows.

Responsibilities

  • Identify security risks early with Engineering and Platform teams and drive secure‑by‑design adoption.
  • Lead threat modeling framework standardization and security design reviews for distributed systems.
  • Oversee security code reviews and API security testing; provide remediation guidance.
  • Architect security automation roadmaps and build scalable tooling for vulnerability management.
  • Design deployment automation to integrate security into cloud‑native pipelines.
  • Lead research initiatives and tabletop exercises to stay ahead of threats.
  • Deploy advanced controls to maximize observability and harden attack surfaces.

Skills

Application Security
Threat Modeling
Secure Coding
CI/CD Security
Automation
Cloud Security

Education

Master's Degree

Job description

Your Role And Responsibilities

As a Staff Application Security Engineer at Confluent, you will join a team of security architects and engineers responsible for shaping and advancing the application security strategy across our on‑premises products and cloud services. In this role, you will go beyond implementation to define the long‑term security posture of our ecosystem, spanning high‑scale distributed systems, on‑prem deployments, and globally operated cloud platforms.

You will lead the design and evolution of application security architecture, ensuring security is embedded throughout the product lifecycle—from early design decisions to cloud deployment and ongoing operations. Acting as a strategic partner to Engineering and Product leadership, you will influence architectural direction and proactively mitigate systemic and emerging security risks.

This role plays a key part in building and sustaining a strong security culture across Engineering, Product, and the broader organization. You will architect and oversee security automation and tooling that scales security operations and enables consistent, high‑quality outcomes. The ideal candidate brings deep technical expertise and sound security judgment, with a proven ability to eliminate entire classes of vulnerabilities through architecture, automation, and cross‑functional leadership.

What You Will Do
  • Partner closely with Engineering, Product, and Platform teams to identify security risks early, influence architectural decisions, and drive adoption of secure‑by‑design practices across the organization.
  • Define and standardize threat modeling frameworks and security design standards, and lead security design reviews for complex, distributed systems, providing actionable architectural guidance to engineers and product managers.
  • Serve as the subject‑matter expert (SME) for product security implementation reviews, overseeing security code reviews and API security testing while providing definitive remediation guidance.
  • Architect and drive the roadmap for security automation, building scalable software security tooling to transform product security operations and vulnerability management practices.
  • Design and lead the deployment of automation and orchestration frameworks that integrate security seamlessly into the cloud‑native deployment pipeline.
  • Proactively identify new vulnerability classes, lead research initiatives and orchestrate complex tabletop exercises to keep the organization ahead of the evolving threat landscape.
  • Strategically identify and deploy advanced technology controls to maximize observability and harden key attack surfaces across the ecosystem.
Preferred Education

Master's Degree

Required Technical And Professional Expertise
  • 10–12 years of hands‑on Application Security experience, who can drive measurable security improvements across large‑scale, distributed systems and global engineering organizations.
  • Comprehensive knowledge of security fundamentals as applied to modern web applications and cloud‑native platforms including secure software design and architecture, secure coding practices, common vulnerability classes.
  • Ability to partner as a trusted peer with Engineering and Product leadership to embed security into the core architecture of the organization.
  • Ability to lead technical investigation and response to application security incidents while driving preventive improvements through architecture and automation.
  • Proven experience evolving the software development lifecycle to embed security by default, from securing CI/CD pipelines and build systems to implementing automated security guardrails in cloud‑native deployment workflows. Passionate about applying AI and LLMs to automate complex security workflows, reduce manual toil, and drive measurable improvements in security outcomes.
  • Experience in Go, Python, or Java, with the ability to design and build scalable security automation frameworks.
  • Experience in leading cross‑functional initiatives in distributed environments, translating security requirements into clear, executable technical roadmaps.
  • A data‑driven decision‑maker who can balance security requirements with business velocity and engineering trade‑offs to deliver outcomes.
  • Ability to raise the organization’s security bar through architectural reviews, advanced technical guidance, and the development of engineers across all levels.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer Ii - Application Security - Confluent
Staff Security Engineer Ii - Application Security - Confluent

IBM Computing • Bengaluru

On-site
INR 4,500,000 - 6,000,000
Staff Security Engineer II
Staff Security Engineer II

Confluent • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior Security Engineer II - Confluent
Senior Security Engineer II - Confluent

IBM Computing • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Consultant - Application Security Job
Consultant - Application Security Job

YASH Technologies • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Security Engineer- 2
Senior Security Engineer- 2

42 Gears Mobility Systems • Bengaluru

On-site
INR 1,500,000 - 2,000,000
System Security
System Security

BigShip Technologies Pvt. Ltd • Dadri

On-site
INR 1,000,000 - 1,500,000