Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
Software Development · 201-500 employees
About the role
The Lead Product Security Engineer will own end-to-end incident response and set the technical security strategy for the company's AI-native product layer. This role involves mentoring the security team, conducting root cause analysis, and partnering with the CTO to manage security risks.
What they look for
Requirements
Candidates must have 6+ years of experience in security with a strong background in AWS infrastructure and incident response for production SaaS systems. Excellent written communication skills and the ability to lead security initiatives in a fast-paced environment are essential.
Full description
Rocketlane is a B2B SaaS platform for client onboarding and project delivery, building Nitro, our AI-native product layer on Claude and MCP. We're hiring a Security Lead to own product and infrastructure security end-to-end: setting direction, leading incident response.
This is not a compliance-only role. You'll be the person we call when something breaks on a Saturday night, and the person who makes sure it doesn't keep happening.
What you'll own
Incident response
- Be the senior escalation point to investigate security incidents
- Lead root cause analysis for the incident and prepare RCA reports within one business day
- Own the customer-facing incident communication and response process
Product security leadership
- Manage and mentor Product Security Engineers, reviewing their pentest findings, vulnerability triage, and remediation work, and stepping in on anything above their current level
- Set the technical bar for what "secure" means across our web app, APIs, mobile, cloud infra, and our AI/LLM-powered surfaces (prompt injection, unsafe code execution in agent tooling, tool-call boundaries)
- Own our cloud security posture: AWS WAF, IAM, TLS/cipher policy, container isolation, secrets management, and get ahead of the recurring findings
Cross-functional ownership
- Be a direct partner to the CTO on security strategy and risk decisions
- Represent security in front of customers and prospects when the stakes are high, including exec-level calls during live incidents
- Build the muscle and the process so that security incidents get caught internally, get root-caused properly, and get communicated to customers accurately
What we're looking for
- 6+ years in security, with real ownership of incident response for production SaaS systems, not just a support role in someone else's process
- Track record of leading root cause analysis on serious incidents: access control failures, data exposure, or RCE-class vulnerabilities, and turning that into concrete preventive controls
- Strong AWS security background: WAF, IAM, TLS/ALB/CloudFront policy, container and network isolation
- Experience managing or mentoring at least one other security engineer, or clear readiness to do so
- Comfortable being the calm, credible voice in a live incident, both internally with engineering and leadership, and externally with customers and their security teams
- Hands-on knowledge of AppSec fundamentals (OWASP Top 10, SAST/DAST, dependency management) and ideally some exposure to securing LLM/AI-powered applications
- Excellent written communication. You'll be writing incident RCAs, customer communications, and executive updates, often about the same incident on the same day
Nice to have
- Experience building or scaling a security function from a single IC to a small team
- Familiarity with GRC tooling (Sprinto or similar) and enterprise questionnaire platforms
- Background in a multi-tenant SaaS environment where tenant isolation is a first-order concern
- Security certifications (OSCP, CISSP, or equivalent hands-on credibility)
Why this role
You'd be the senior security voice at a fast-moving product company shipping AI agent features into production every week, with a direct line to the CTO and real authority over what gets fixed, how incidents get handled. If you want to build the process rather than just follow one, this is that role.
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr
-
DevSecOps & Product Security Engineer
Weekday AI Hyderabad, Telangana, India · ₹300K–₹1M/yr