Base Career helps you apply smarter for this job.
Key skills for this role
Establish agent identities and least-privilege permissions, with clear separation of read, write, execute, approval, and administrative capabilities.
Govern model, tool, skill, connector, plug-in, memory, and data access, including tenant isolation and boundaries between trusted and untrusted context.
Validate untrusted inputs and tool outputs, and design defenses against direct and indirect prompt injection, goal manipulation, tool misuse, privilege escalation, sensitive-data exposure, memory poisoning, unsafe delegation, and cascading failures.
Assess multi-agent workflows to implement approval requirements for consequential or irreversible actions, runtime policy enforcement, rate and resource limits, and tamper-resistant auditability.
Lead high-risk threat modeling and architecture reviews for complex, multi-tenant, cloud-native, event-driven, and AI-enabled systems.
Develop and demonstrate reusable secure patterns for microservices, APIs, event-driven systems, containers, Kubernetes, cloud services, and agentic AI applications.
Contribute to platform roadmaps and engineering practice so controls are implemented at the most effective layer and reused across products.
Provide evidence from implementation, testing, and incidents to help Information Security team continuously improve enterprise standards and assurance expectations.
Partner across distributed engineering hubs, including North America and Chennai, to drive adoption of secure patterns and automation at scale.
Translate findings into prioritized, actionable engineering work reflecting technical severity, exploitability, customer impact, and delivery context.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Pune, IND
Pune, IND
Pune, IND
, CAN
, CAN
, USA
, USA
Houston, USA
Mentor senior engineers and technical leaders in secure design, development, threat modeling, and remediation.
Serve as the application and AI security technical lead during relevant incidents – coordinating with designated incident lead and Information Security team to support investigation, containment, eradication, recovery, remediation validation, and lessons learned.
Represent application and AI security in significant technical, executive, customer, audit, and assurance discussions when needed.
8+ years of experience in application security or secure software engineering, with demonstrated responsibility for production software and security controls.
A degree in computer science, cybersecurity, engineering, or a related field is welcome but not required. Equivalent practical experience is fully recognized.
Deep application and API security expertise, including authentication, authorization, session management, data protection, input validation, and multi-tenant isolation. This is the core of the role.
Ability to review, write, test, and improve production-quality code in one or more languages commonly used in cloud applications, automation, and security engineering.
Experience leading source-code reviews, application and API security testing, threat modeling, and architecture reviews for complex systems.
Experience integrating and tuning security tooling in CI/CD and converting findings into risk-based automated controls.
Production experience with a major cloud provider (Azure, AWS, or comparable) and practical understanding of cloud identity, platform services, and the shared-responsibility model.
Demonstrated ability to set technical direction, create reusable capabilities across multiple products, and influence senior stakeholders without relying on formal authority.
Ability to explain material security risk clearly to engineers, product leaders, executives, customers, and assurance stakeholders.
Strong written and verbal English communication skills.
We conduct pre-employment drug and background screening.
Practical AI-agent security experience, including excessive permissions, insecure tool invocation, untrusted inputs, memory or context risks, sensitive-data exposure, insufficient human oversight, and unsafe autonomous action.
Experience applying AI to security testing, code analysis, vulnerability triage, or security automation.
Experience securing distributed, event-driven, multi-tenant, or critical enterprise systems where authorization and data boundaries are material risks.
Container, Kubernetes, infrastructure-as-code, and software-supply-chain security.
Incident response, vulnerability investigation, exploit validation, and remediation verification.
Hands-on depth with Veracode, Burp Suite Professional, or equivalents, and practical familiarity with OWASP application, API, and agentic AI security guidance.
Certifications are a plus, demonstrated hands-on ability matters more. Relevant credentials include OSCP, GIAC GWAPT, GWEB, GCSA, AZ-500, AWS Certified Security - Specialty, CISSP, or CCSP.
Global independent expert in assurance and risk management.
Visit company websiteJobs and hiring trendsUSD 175000-225000 yearly / year
Full-time
Senior · 8+ years experience
Hybrid
Apply faster on company sites with our extension.