Lead Security Engineer
BlueConic Pune, Maharashtra, India
Software Development · 201-500 employees
About the role
The Lead Security Engineer will drive secure coding practices and threat modeling within an AI-centric product development lifecycle. They are responsible for building security automation, managing vulnerabilities, and establishing guardrails for agentic systems.
What they look for
Requirements
Candidates must have 7+ years of experience in security engineering with a focus on staff-level leadership and cross-team initiatives. Deep expertise in AI-generated code risks, web application security, and hands-on experience with AI coding agents is required.
Benefits
Full description
About BlueConic:
We are building products with AI at the core, and we build our products using AI. Agents and skills write a share of our code, run parts of our SDLC, and operate alongside our engineers every day. We need a Staff Security Engineer who can secure that reality, not the SDLC of five years ago.
In conjunction with the CISO you represent security across the product development lifecycle, lead threat modeling and vulnerability management, and drive secure coding practices in an environment where code review means reviewing agent output as often as human output. You will use AI agents and skills as core tools of your own job: building automation, running threat models, triaging vulnerabilities, and scaling your impact across teams.
Lead Security Engineer
What you'll do
- Drive adoption of secure coding practices, including practices specific to AI-generated and AI-assisted code.
- Conduct security assessments, threat modeling, and risk analysis so threats are understood, documented, and mitigated.
- Automate security processes wherever it creates leverage, using scripts, AI agents, and AI skills as your default tools.
- Identify emerging classes of vulnerabilities and build solutions before they become incidents.
- Build and maintain security tooling, automation, and monitoring capabilities, including custom agents and skills for security workflows
- Threat model agentic systems: prompt injection, tool misuse, unauthorized agent privilege escalation, and data exfiltration through agent actions.
- Define guardrails and human-in-the-loop checkpoints for agent-driven changes to code and infrastructure.
- Set and enforce review standards for code produced by AI coding agents, including required checks before agent-authored changes reach production.
- Break large, cross-team security projects into individual tasks. Manage scope across teams and drive projects to closure.
- Monitor, investigate, and respond to security incidents, coordinating remediation across teams.
- Support compliance initiatives and security audits with technical expertise and evidence.
- Evaluate emerging threats, including risks introduced by AI development tools, and recommend improvements to security architecture.
We are looking for someone with following skills
- 7+ years in security engineering or application security, with demonstrated staff-level scope: leading cross-team initiatives and setting technical direction.
- Understanding of risks unique to AI-generated code and agentic workflows: prompt injection, insecure dependencies introduced by agents, hallucinated logic, and excessive agent permissions.
- Comfort reviewing and verifying AI-authored code rather than writing everything from scratch, with a mindset built for a review-and-verify SDLC.
- Experience building or configuring custom agents or skills for security use cases such as threat modeling, code review, or incident triage.
- Hands-on experience using AI coding agents and skills (for example Claude Code, Copilot, or similar) in a production engineering workflow.
- Deep understanding of web application architecture and design principles.
- Knowledge of common security flaws and fixes as published by OWASP, SANS, and similar bodies.
- Strong grasp of application security concepts: authentication, authorization, encryption, secure coding, and common attack vectors.
- Experience running vulnerability assessments and managing remediation programs.
- Familiarity with security tools: vulnerability scanners, endpoint security, SIEM platforms, and monitoring tools.
- Experience investigating and responding to security incidents.
Reasons to join us
- Be part of a dynamic, professional, and highly collaborative Product & Technology team
- Work on cutting-edge applied ML problems at the intersection of AI, decisioning, and customer growth
- Combine deep technical work with real-world customer impact
- Help build a category-defining Customer Growth Engine
- Enjoy a competitive salary and work in an international environment with strong opportunities for growth and ownership
- Excellent hospitalisation, personal accident, and term insurance coverage.
- Located in a top-notch facility in Baner - one of the best neighbourhoods for tech startups.
Similar roles
-
GNMA IAISO Cybersecurity Program Manager
Crest Security Assurance $150K–$160K/yr
-
Cyber Security Engineer I
Durango Casino & Resort Las Vegas, Nevada, United States
-
IT Security Engineer / Penetration Tester 60% - 100% (m/w/d)
KastGroup GmbH Wallisellen, Zurich, Switzerland
-
Cybersecurity Compliance Analyst
RCG Suitland, Maryland, United States · $115K–$125K/yr
-
Security Engineer I
S.P. Richards Company Atlanta, Georgia, United States
-
Cybersecurity Analyst
Michigan Schools and Government Credit Union Troy, Michigan, United States · $79K/yr