Senior Product Security Engineer

Bengaluru, Karnataka, India | Full-time

Apply by: No close date
Apply

Who are we?

Founded in 2014 by Khadim Batti and Vara Kumar, Whatfix is a leading global B2B SaaS provider and the largest pure-play enterprise digital adoption platform (DAP). Whatfix empowers companies to maximize the ROI of their digital investments across the application lifecycle, from ideation to training to the deployment of software. Driving user productivity, ensuring process compliance, and improving user experience of internal and customer-facing applications.

Spearheading the category with serial innovation and unmatched customer-centricity, Whatfix is the only DAP innovating beyond the category, positioning itself as a comprehensive suite for GenAI-powered digital adoption, analytics, and application simulation. Whatfix product suite consists of 3 products - DAP, Product Analytics, and Mirror. This product suite helps businesses accelerate ROI on digital investments by streamlining application deployment across its lifecycle.

Whatfix has seven offices across the US, India, UK, Germany, Singapore, and Australia and a presence across 40+ countries.

Customers: 700+ enterprise customers, including over 80 Fortune 500 companies such as Shell, Microsoft, Schneider Electric, and UPS Supply Chain Solutions. 

Investors: Raised a total of ~$270 million. Most recently Series E round of $125 Million led by Warburg Pincus with participation from existing investor SoftBank Vision Fund 2. Other investors include Cisco Investments, Eight Roads Ventures (A division of Fidelity Investments), Dragoneer Investments, Peak XV Partners, and Stellaris Venture Partners.

  • With over 45% YoY sustainable annual recurring revenue (ARR) growth, Whatfix is among the “Top 50 Indian Software Companies” as per G2 Best Software Awards. 

  • Recognized as a “Leader” in the digital adoption platforms (DAP) category for the past 4+ years by leading analyst firms like Gartner, Forrester, IDC, and Everest Group.

  • The only vendor recognized as a Customers’ Choice in the 2024 Gartner® Voice of the Customer for Digital Adoption Platforms has once again earned the Customers’ Choice distinction in 2025. We also boast a star rating of 4.6 on G2 Crowd, 4.5 on Gartner Peer Insights, and a high CSAT of 99.8%

  • Only DAP to be among the top 35% companies worldwide in sustainability excellence with EcoVadis Bronze Medal

On the G2 peer review platform, Whatfix has received 77 Leader badges across all market segments, including Small, Medium, and Enterprise, in 2024, among numerous other industry recognitions.

About the Role & Impact

We are seeking a visionary and hands-on Senior Product Security Engineer to serve as the technical authority and champion for security across modern applications, cloud platforms, and cutting-edge AI/LLM ecosystems. In this high-impact role, you will bridge the gap between innovation and resilience - combining security architecture, threat modeling, secure SDLC, AI security governance, and automated security engineering. Partnering directly with senior engineering leaders and product managers, you will shape our long-term security posture while fostering a security-first engineering culture.

Key Responsibilities

  • Secure SDLC & Security Process Optimization: Define, evolve, and execute the Product Security and Secure SDLC strategy, continuously optimizing security processes through AI Development Lifecycle (AIDLC) practices, security automation, risk-based security gates, and developer-friendly workflows across system design, development, CI/CD, deployment, and runtime environments.

  • Architecture & Threat Modeling: Lead comprehensive threat modeling and security design reviews for multi-tenant SaaS applications, microservices, cloud-native infrastructure, and emerging AI/LLM integrations.

  • AI & LLM Security Testing: Perform hands-on AI/LLM security assessments and testing aligned with the OWASP Top 10 for LLM Applications and MITRE ATLAS, identifying and validating risks such as prompt injection, jailbreaks, data poisoning, insecure output handling, excessive agency, and model abuse.

  • Identity & Zero-Trust Architecture: Architect and refine resilient controls for OAuth 2.0, OIDC, and zero-trust data boundary isolation.

  • DevSecOps & Pipeline Automation: Build and integrate scalable automated security scanners and continuous testing guardrails across CI/CD and LLMOps workflows to empower developer self-service.

  • Cross-Functional Collaboration: Work in lockstep with cloud platform, data engineering, and AI/ML teams to translate security requirements into pragmatic, non-blocking engineering patterns.

  • Standards & Golden Paths: Author reusable security blueprints, standard reference designs, and secure code patterns to simplify compliance across product engineering teams.

  • Leadership & Mentorship: Provide Staff-level technical direction and mentorship to junior engineers, elevating technical quality and cultivating a strong proactive security posture across the enterprise.

  • Supply Chain Security: Establish software supply chain security controls, including Software Bill of Materials (SBOM) management, dependency risk tracking, and open-source vulnerability management across production software and third-party components.

  • Customer Security Engagement: Participate in customer security calls and technical discussions to address security queries, architecture concerns, compliance requirements, and risk assessments, working with engineering and product teams to provide accurate and actionable security responses.

Required Experience

  • Demonstrated Experience: 8+ years of progressive experience in Product Security, Application Security, or Product Security Engineering within SaaS or cloud-native environments.

  • Technical Mastery: Deep expertise in threat modeling, cloud architecture (Azure), API security, microservices design, and DevSecOps tooling.

  • AI/LLM Expertise: Hands-on experience identifying and mitigating risks in modern AI/LLM architectures (RAG, vector databases, agentic frameworks, and fine-tuning pipelines).

  • Identity & Cryptography Knowledge: Strong practical knowledge of OAuth 2.0, OIDC, PKI, and zero-trust concepts.

  • Engineering & Automation Mindset: Ability to write clean, maintainable automation scripts or tools (Python, Go, or similar) to integrate security deeply into standard developer workflows.

  • Strategic Influence: Proven ability to lead by influence, articulate complex technical risks to executive stakeholders, and guide senior engineers at a Staff/Principal level.

  • Supply Chain Assurance: Experience implementing software supply chain frameworks (e.g., SLSA, NIST SSDF) and tools for dependency scanning, attestation, and component risk management.

  • Security Tooling & Automation: Hands-on experience with security and DevSecOps tools such as Trivy, Jenkins, GitHub/GitHub Actions, TruffleHog, Checkmarx One (SAST, SCA, SAST, Secret Scanning, IaC, and Container Security), and Burp Suite, with the ability to integrate and automate security checks across CI/CD pipelines.

Core Areas

Product Security | AI/LLM Security | Application Security | Threat Modeling | Cloud Security | OAuth/OIDC | Secure SDLC | DevSecOps | Security Architecture | Automation