BlueConic

Lead Security Engineer

BlueConic Pune, Maharashtra, India

Software Development · 201-500 employees

5 h ago
security Principal (10+ yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Lead Security Engineer will drive secure coding practices and threat modeling within an AI-centric product development lifecycle. They are responsible for building security automation, managing vulnerabilities, and establishing guardrails for agentic systems.

What they look for

Security engineering Application security Threat modeling Vulnerability management Secure coding AI-assisted development Prompt injection Agentic systems Web application architecture OWASP SANS Vulnerability assessment SIEM Incident response Automation Risk analysis

Requirements

Candidates must have 7+ years of experience in security engineering with a focus on staff-level leadership and cross-team initiatives. Deep expertise in AI-generated code risks, web application security, and hands-on experience with AI coding agents is required.

Benefits

Competitive salary Hospitalisation insurance Personal accident insurance Term insurance coverage

Full description

About BlueConic:

We are building products with AI at the core, and we build our products using AI. Agents and skills write a share of our code, run parts of our SDLC, and operate alongside our engineers every day. We need a Staff Security Engineer who can secure that reality, not the SDLC of five years ago.

In conjunction with the CISO you represent security across the product development lifecycle, lead threat modeling and vulnerability management, and drive secure coding practices in an environment where code review means reviewing agent output as often as human output. You will use AI agents and skills as core tools of your own job: building automation, running threat models, triaging vulnerabilities, and scaling your impact across teams.

Lead Security Engineer

What you'll do

  • Drive adoption of secure coding practices, including practices specific to AI-generated and AI-assisted code.
  • Conduct security assessments, threat modeling, and risk analysis so threats are understood, documented, and mitigated.
  • Automate security processes wherever it creates leverage, using scripts, AI agents, and AI skills as your default tools.
  • Identify emerging classes of vulnerabilities and build solutions before they become incidents.
  • Build and maintain security tooling, automation, and monitoring capabilities, including custom agents and skills for security workflows
  • Threat model agentic systems: prompt injection, tool misuse, unauthorized agent privilege escalation, and data exfiltration through agent actions.
  • Define guardrails and human-in-the-loop checkpoints for agent-driven changes to code and infrastructure.
  • Set and enforce review standards for code produced by AI coding agents, including required checks before agent-authored changes reach production.
  • Break large, cross-team security projects into individual tasks. Manage scope across teams and drive projects to closure.
  • Monitor, investigate, and respond to security incidents, coordinating remediation across teams.
  • Support compliance initiatives and security audits with technical expertise and evidence.
  • Evaluate emerging threats, including risks introduced by AI development tools, and recommend improvements to security architecture.

We are looking for someone with following skills

  • 7+ years in security engineering or application security, with demonstrated staff-level scope: leading cross-team initiatives and setting technical direction.
  • Understanding of risks unique to AI-generated code and agentic workflows: prompt injection, insecure dependencies introduced by agents, hallucinated logic, and excessive agent permissions.
  • Comfort reviewing and verifying AI-authored code rather than writing everything from scratch, with a mindset built for a review-and-verify SDLC.
  • Experience building or configuring custom agents or skills for security use cases such as threat modeling, code review, or incident triage.
  • Hands-on experience using AI coding agents and skills (for example Claude Code, Copilot, or similar) in a production engineering workflow.
  • Deep understanding of web application architecture and design principles.
  • Knowledge of common security flaws and fixes as published by OWASP, SANS, and similar bodies.
  • Strong grasp of application security concepts: authentication, authorization, encryption, secure coding, and common attack vectors.
  • Experience running vulnerability assessments and managing remediation programs.
  • Familiarity with security tools: vulnerability scanners, endpoint security, SIEM platforms, and monitoring tools.
  • Experience investigating and responding to security incidents.

Reasons to join us

  • Be part of a dynamic, professional, and highly collaborative Product & Technology team
  • Work on cutting-edge applied ML problems at the intersection of AI, decisioning, and customer growth
  • Combine deep technical work with real-world customer impact
  • Help build a category-defining Customer Growth Engine
  • Enjoy a competitive salary and work in an international environment with strong opportunities for growth and ownership
  • Excellent hospitalisation, personal accident, and term insurance coverage.
  • Located in a top-notch facility in Baner - one of the best neighbourhoods for tech startups.

Similar roles