Principal / Staff Application Security Engineer

Aidash
Posted on
Aidash logo

Experience
8 - 13 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Application Security Engineer
Job Type
Not specified

Job Description

The Role

Were hiring a Principal or Staff Application Security Engineer to be our deepest technical voice on security. In the role, youll own our AppSec program and lead AI/LLM security hardening across the platform. Youll embed security into every layer of the SDLC (from PR to production), and be the person who figures out what secure agentic AI looks like in a product that ships to critical infrastructure operators. You will report to senior leadership and work closely with Platform, ML, and DevOps across our US and India teams.

How youll make an impact:

AppSec DevSecOps

  • Own and mature the AppSec toolchain across CI/CD SAST, DAST, SCA, secrets scanning, and IaC policy-as-code
  • Champion shift-left security: threat modeling and secure-design reviews embedded in PRs and sprint planning, not bolted on at release
  • Run SBOM/AIBOM tooling; enforce risk-tiered dependency controls; extend SLSA practices to model artifacts
  • Write and enforce IaC policy-as-code (OPA/Rego, Checkov, Kyverno, or equivalent) in live pipelines

AI LLM Security

  • Harden production GenAI deployments on AWS (managed model APIs, agentic/MCP services) IAM, VPC routing, prompt-layer guardrails, output filtering, rate and cost controls
  • Codify OWASP LLM Top 10 and MITRE ATLAS controls into the SDLC; introduce LLM eval-as-gate in CI
  • Govern internal AI-assisted developer tooling DLP for what egresses to external model providers, sensitive-data discovery in prompts, acceptable-use telemetry
  • Stand up controls for shadow AI and vibe-coded apps: discover, classify, gate with sane defaults, and bring under the SDLC

Cloud Security (AWS)

  • Harden AWS posture across accounts Organizations, SCPs, Control Tower and mature Kubernetes security (admission controllers, runtime visibility)
  • Operate CSPM/CNAPP tooling; own vulnerability management across containers and IaC
  • Support zero-trust privileged access for production infra, databases, and Kubernetes (in partnership with DevOps)

Compliance Support

  • Support the companys path to ISO 27001 and ISO 42001 certifications in 2027 gap assessments, control sets, evidence pipeline
  • Maintain SOC 2 Type II posture in partnership with the compliance team
  • Translate emerging AI regulation (EU AI Act, NIST AI RMF, utility-sector mandates) into concrete engineering requirements

Minimum Qualifications

  • 8+ years in security engineering with meaningful AppSec depth you have shipped and operated SAST/DAST/SCA (Semgrep, CodeQL, Snyk, Veracode, or equivalent) at production scale
  • Hands-on experience securing production LLM or agentic AI deployments IAM, guardrails, prompt injection controls, eval gating. RAG-demo experience alone does not meet the bar
  • Cloud-native security experience in AWS comfortable with Organizations/SCPs, Kubernetes security, container hardening, and CSPM tooling
  • IaC policy-as-code in a live pipeline (OPA/Rego, Checkov, Kyverno, tfsec, or equivalent)
  • SBOM/AIBOM tooling at production scale (Interlynk, Anchore, Dependency-Track, or equivalent)
  • Compliance fluency: has personally contributed to a SOC 2 Type II or ISO 27001 audit can read a control map without flinching
  • SF Bay Area based; able to work hybrid (2 days/week in Palo Alto)

Preferred Qualifications

  • Hands-on MCP work design, hardening, or auth even early-stage
  • LLM eval-as-gate in CI (Promptfoo, Garak, DeepEval, Giskard) and AI red-teaming experience
  • Prompt-layer DLP and AI runtime guardrails (Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, Protect AI, NVIDIA NeMo Guardrails)
  • ISO 42001 familiarity; NIST AI RMF and EU AI Act high-risk system requirements
  • Experience securing SaaS sold into regulated sectors (utilities, energy, financial services, healthcare)
  • EDR/XDR operations experience (CrowdStrike, SentinelOne, Defender) helpful but not the primary focus of this role
  • Comfort working across US/India time zones with a distributed team
  • Public signals: conference talks, open-source contributions in CI/CD, MCP, or LLM-deployment security
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.