Rocketlane

Product Security Engineer

Rocketlane Chennai, Tamil Nadu, India

Software Development · 201-500 employees

4 h ago
security Mid (2-5 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will own product and infrastructure security by conducting penetration tests, hunting for vulnerabilities, and hardening cloud environments. Additionally, you will manage compliance audits, respond to customer security questionnaires, and coordinate with engineering teams to prioritize and implement security fixes.

What they look for

Penetration testing Vulnerability research AWS security CI/CD security Cloud security Application security API security Mobile security Compliance auditing Risk assessment Threat modeling Prompt injection mitigation Container security IAM WAF Security documentation

Requirements

The role requires 3+ years of hands-on experience in security, specifically in penetration testing and vulnerability research across web, API, and cloud platforms. Candidates must possess strong knowledge of AWS security, CI/CD pipeline integration, and the ability to communicate technical risks to both engineering and non-technical stakeholders.

Full description

About Rocketlane

Rocketlane is a B2B SaaS platform for client onboarding and project delivery, and we're building Nitro, our AI-native product layer. We're looking for a Product Security Engineer to own product and infrastructure security for the company.

What you'll own

This is a hands-on, individual-contributor security role covering the full range of product security work, not just one slice of it.

Offensive security and vulnerability discovery

  • Run internal penetration tests across our web app, APIs, mobile app, and cloud infrastructure, and triage findings from external pentest vendors
  • Actively hunt for vulnerabilities in new features, including in AI/LLM-powered surfaces (prompt injection paths, unsafe code execution in agent tooling, unauthenticated internal endpoints)
  • Have found and driven the fix for real vulnerabilities before. We need someone who thinks like an attacker, not just someone who runs a scanner and files a ticket

Cloud and infrastructure security

  • Review and harden our AWS setup: WAF rules, ALB/CloudFront TLS policies and cipher suites, container isolation, IAM and secrets hygiene
  • Investigate and close out Dependabot and other CI/CD security alerts across dozens of repos, and work with engineering teams to get fixes prioritized and shipped
  • Build and maintain internal security tooling

Compliance and customer trust

  • Help with our compliance audit cycles end to end: evidence collection, control testing, and coordinating with auditors. This typically takes up 5% of the work.
  • Respond to customer security questionnaires and InfoSec review requests, working with sales and customer success to turn these around quickly and accurately
  • Keep our security documentation and posture current as the product and infrastructure evolve

Cross-team coordination

  • Work directly with engineering, platform, and ops teams to get security fixes prioritized and shipped, not just logged
  • Report critical findings up to leadership with clear, actionable writeups (source, sink, impact, fix)

What we're looking for

  • 3+ years in a hands-on security role covering penetration testing and vulnerability research, ideally across web, API, mobile, and cloud
  • Real, demonstrable experience finding and helping fix serious vulnerabilities (RCE, auth bypass, injection classes), not just running automated scans
  • Solid working knowledge of AWS security: WAF, ALB/CloudFront, IAM, container security on ECS or similar
  • Comfort integrating security tooling into CI/CD pipelines (SAST/DAST, dependency scanning) and driving remediation with engineering teams
  • Experience with, or strong interest in, securing LLM/AI-powered applications: unsafe code execution, prompt injection, agent tool-call boundaries
  • Strong written communication. You'll be writing up findings for engineers and explaining risk to non-technical stakeholders in the same week

Nice to have

  • Experience building or maintaining internal security scanning tools
  • Familiarity with Java/Spring Boot stacks (our backend) or Python (our AI/LLM stack)
  • A CTF background, bug bounty track record, or security certifications (OSCP, etc.)
  • Prior exposure to SOC 2 or similar compliance frameworks and customer-facing security questionnaires would be a plus

Why this role

You'd be the primary security engineer for a fast-moving product company actively shipping AI agent features, with direct access to leadership and real ownership over what gets fixed and when.

Similar roles