Lead Security Engineer
Pune, India
- Posted 1mo ago
- From BlueConic’s careers page
- Location
- Pune, India
- Level
- Staff
- Experience
- 7+ years
- Department
- Information Technology
Apply on BlueConic’s site
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
What you'll do
- Drive adoption of secure coding practices, including practices specific to AI-generated and AI-assisted code.
- Conduct security assessments, threat modeling, and risk analysis so threats are understood, documented, and mitigated.
- Automate security processes wherever it creates leverage, using scripts, AI agents, and AI skills as your default tools.
- Identify emerging classes of vulnerabilities and build solutions before they become incidents.
- Build and maintain security tooling, automation, and monitoring capabilities, including custom agents and skills for security workflows
- Threat model agentic systems: prompt injection, tool misuse, unauthorized agent privilege escalation, and data exfiltration through agent actions.
- Define guardrails and human-in-the-loop checkpoints for agent-driven changes to code and infrastructure.
- Set and enforce review standards for code produced by AI coding agents, including required checks before agent-authored changes reach production.
- Break large, cross-team security projects into individual tasks. Manage scope across teams and drive projects to closure.
- Monitor, investigate, and respond to security incidents, coordinating remediation across teams.
- Support compliance initiatives and security audits with technical expertise and evidence.
- Evaluate emerging threats, including risks introduced by AI development tools, and recommend improvements to security architecture.
We are looking for someone with following skills
- 7+ years in security engineering or application security, with demonstrated staff-level scope: leading cross-team initiatives and setting technical direction.
- Understanding of risks unique to AI-generated code and agentic workflows: prompt injection, insecure dependencies introduced by agents, hallucinated logic, and excessive agent permissions.
- Comfort reviewing and verifying AI-authored code rather than writing everything from scratch, with a mindset built for a review-and-verify SDLC.
- Experience building or configuring custom agents or skills for security use cases such as threat modeling, code review, or incident triage.
- Hands-on experience using AI coding agents and skills (for example, Copilot, or similar) in a production engineering workflow.
- Deep understanding of web application architecture and design principles.
- Knowledge of common security flaws and fixes as published by OWASP, SANS, and similar bodies.
- Strong grasp of application security concepts: authentication, authorization, encryption, secure coding, and common attack vectors.
- Experience running vulnerability assessments and managing remediation programs.
- Familiarity with security tools: vulnerability scanners, endpoint security, SIEM platforms, and monitoring tools.
- Experience investigating and responding to security incidents.
Skills they ask for
Pick one to see other roles that ask for it.
About BlueConic
Customer data and activation for growthBlueConic provides a customer data and activation platform for marketers to unify customer profiles and coordinate personalized experiences across channels.
See all 2 roles at BlueConicMore roles at BlueConic
See all 2Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.