Senior Staff Engineer, Product Security
Core
Architecting an AI-first SDLC that integrates traditional AppSec with advanced AI security practices to secure SaaS products and enable agentic features.
Role type
Senior Staff Product Security Engineer (AI Security & AppSec)
Builds
AI-first CI/CD pipelines, secure AI/Agentic architectures, and automated security controls for SaaS products.
Domain
Product Security / AppSec / AI Security / DevSecOps (via careerplan.io/jobs/8814777002-senior-staff-engineer-product-security-at-druva)
Deliverable
production ML models
Required skills
AI-first SDLC architecture, Agentic AI threat modeling, LLM security controls, AppSec fundamentals (OWASP Top 10, CWE 25), cryptography, container security, supply chain security (SBOMs), code review (Python, Go, Javascript), CI/CD security tooling.
Preferred skills
OSCP/OSWE/CSSLP/GIAC certifications, active community contributions (OWASP, BSides, Black Hat), hands-on development experience.
Technologies
Burp Suite, Snyk, OWASP ZAP, MCP, Python, Go, Javascript.
Responsibilities
Architect AI-driven security controls into CI/CD pipelines, conduct threat models for AI architectures, review code and triage vulnerabilities, manage open-source risks and SBOMs, lead secure coding workshops and Security Champions program.
Seniority
Senior Staff, hands-on IC with technical leadership
