Job Description
Job Summary
Senior Vulnerability Remediation Engineer, Product Security Anaplan. Reports to: Senior Manager, Platform Security. Working model: Gurugram (Hybrid).
Role Overview
Why this role matters. This is an exciting opportunity to make a significant impact at Anaplan! In this role, you will be at the forefront of scaling security through automation and self-service. You'll be the driving force behind transforming security intent into enforced, self-service controls across the SDLC and CI/CD pipelines. Think dependency policy, secrets handling, least-privilege access, and the guardrails that allow engineering teams to innovate rapidly without compromising security.
When done right, this is some of the most high-leverage work in our function. Every control you implement will run continuously for every team, seamlessly integrated into their workflows!
Why Anaplan
Anaplan is not just another SaaS application; it's a powerful platform that performs highly dimensional, enterprise-scale modeling with responsive recalculation and strong correctness expectations. Our technical landscape is rich and varied, featuring the legacy Hyperblock engine, the innovative Polaris engine, and an expanding suite of AI-powered products like CoModeler for AI-assisted model building and CoPlanner for conversational, analyst-style planning support.
With AI revolutionizing software development, we are embracing more generated code and autonomous changes, making the need for encoded, verifiable guardrails more critical than ever. Security is woven into the fabric of how our platform evolves, rather than treated as an afterthought. Join our small, dynamic team where your contributions to automation will set the gold standard!
What you'll do
- Automate across the pipeline: build security automation into CI/CD and the broader SDLC so that controls run as code.
- Leverage AI to scale security automation: harness AI and LLM-assisted tools to speed up control development, triage, and remediation, extending automated coverage beyond what traditional scripts can achieve.
- Implement policy-as-code: encode guardrails for dependency and package policies, secrets, and configurations so they enforce themselves effortlessly.
- Build the controlled-repository model: automate the restriction of external dependencies and provide safe, approved package paths for our engineers.
- Automate secrets management and detection: ensure mishandled or leaked secrets are automatically caught and managed without the need for manual sweeps.
- Reduce standing privilege: develop automation for least privilege and just-in-time access, making persistent access the exception rather than the rule.
- Tame scanner output: integrate detection into low-noise, actionable workflows that feed remediation, preventing overwhelming flood of alerts.
- Automate attack-surface hardening: drive the creation of hardened, golden images and enforce baselines through code.
- Make controls self-service: default to providing engineers with a paved path wherever it's safe to do so, rather than imposing unnecessary gates.
What we're looking for
- Strong automation and engineering skills, particularly in languages such as Python or Go, along with expertise in infrastructure-as-code and pipeline work.
- In-depth knowledge of DevSecOps: CI/CD security and hands-on experience with policy-as-code using tools like OPA, Conftest, or Kyverno.
- Foundational understanding of cloud-native security, particularly in Kubernetes and at least one major cloud provider, along with knowledge of secrets management and identity basics.
- A builder's instinct: you create tools that engineers love because they simplify their work.
- Genuine care for developer experience, always striving to reduce friction rather than adding unnecessary barriers.
- The discernment to identify which controls are truly worth encoding and which can be set aside.
Nice to have
- Experience with supply-chain security: understanding of provenance and signing, as well as software or model bills of materials.
- Familiarity with zero-trust and least-privilege automation, including just-in-time access.
- Experience working in a regulated, enterprise environment.
- Contributions to open-source security tooling or relevant certifications.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
