Lead Product Security Engineer
Thiruvananthapuram, India · Hybrid · Full-time
- Posted 1mo ago
- From Envestnet’s careers page
- Location
- Thiruvananthapuram, India
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Lead
- Department
- Information Technology
Opens the listing on careers.envestnet.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Description
Job Location
The primary work location for this role is Trivandrum with a hybrid or remote work model.
About Envestnet
Envestnet is an adaptive WealthTech company that is redefining the future of wealth management by helping advisors meet the moment with its comprehensive technology, actionable insights, and industry leading support. Backed by over 25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.
For a deeper look at how Envestnet is shaping the future of financial advice, visit www.envestnet.com.
The Team You’ll Join
You will join Envestnet’s Technology team, where we design, build, and maintain scalable, secure, and robust WealthTech solutions that power the future of financial advice. The team collaborates closely with product, operations, and business stakeholders to drive innovation, enhance efficiency, and enable sustainable growth. Guided by modern engineering practices and a commitment to domain excellence, technical rigor, and collaboration, the Technology team ensures our platforms remain resilient, adaptable, and aligned with evolving business needs making it a core driver of Envestnet’s long term success.
How You’ll Contribute
The Lead Product Security Engineer serves as the primary security partner for assigned products and platforms, ensuring security is embedded throughout product lifecycle. This role works closely with Product, Engineering, DevOps, and Cybersecurity teams to reduce security risk, drive secure-by-design practices and strengthen the overall security posture of Envestnet products.
The role combines hands-on security assessment, penetration testing, security review, vulnerability management and AI security expertise with technical leadership responsibilities. As a trusted security advisor and key point of contact, the individual supports day-to-day security operations across assigned product portfolio.
Key Responsibilities:
Product Security Operation and collaboration:
- Serve as the Product Security point of contact for assigned products and platforms.
- Partner with Product, Engineering and Architecture teams to embed security throughout the product life cycle.
- Monitor and oversee day-to-day security operations of assigned products and platform.
- Provide security review findings, remediation guidance, and risk-based recommendations to engineering teams.
- Coordinate within Cybersecurity team, Cloud Security, IAM, Security Operations, and Compliance teams address product security risks.
- Support adoption of established security standards, secure coding practices, and product security requirements.
Security reviews and assessments
- Conduct application security reviews and security design assessments.
- Perform hands-on penetration testing of web applications, APIs, cloud-native applications, and AI-enabled systems.
- Lead and perform security reviews for product releases and ensure Critical and High-risk findings are addressed before production deployment.
- Identify security weaknesses, validate remediation efforts, and drive vulnerability remediation initiatives.
- Participate in and support threat modeling and security design reviews.
Vulnerability Management and DevSecOps.
- Drive vulnerability management efforts across assigned products and platforms.
- Partner with engineering teams to prioritize and remediate findings from SAST, SCA, IAST, DAST, penetration testing, and cloud security assessments.
- Ensure security tooling is effectively integrated into CI/CD pipelines and development workflows.
- Monitor remediation SLAs, track security posture improvements, and reduce recurring security issues.
- Provide vulnerability matrix and other KPI data points to reporting team and other stakeholders in regular cadence.
AI Security
- Assess security risks associated with AI, LLM, Agentic AI, and RAG implementations.
- Conduct security reviews of Generative AI and Agentic AI applications, including LLM integrations, RAG pipelines, AI agents, MCP/tool integrations, orchestration frameworks, and third-party AI services.
- Validate AI security controls, guardrails, and secure-by-design implementations.
- Identify and drive remediation of risks including prompt injection, data leakage, excessive agent privileges, insecure tool execution, unsafe autonomy, and model misuse.
- Review AI-assisted development, coding agents, and AI-enabled software delivery workflows for security risks and required controls.
- Support AI security testing and secure adoption across assigned products and platforms.
Security Enablement
- Promote secure coding and secure-by-design practices across engineering teams.
- Support Security Champion and developer enablement programs.
What You’ll Need to Bring
- Bachelor’s/Master’s in Computer Science, Cybersecurity, or related field.
- Strong experience conducting product security reviews, threat modeling, security assessments, and secure design reviews within modern application environments.
- Hands on experience with threat modeling, security architecture reviews, and secure system design including AI-enabled systems.
- Solid understanding of modern application architectures, including microservices, APIs, and cloud native platforms.
- Working knowledge of AI/LLM concepts, including model integration patterns, RAG architecture, and agentic workflows.
- Knowledge of identity and access management, encryption standards, and secure integration patterns.
- Familiarity with industry frameworks such as OWASP, NIST, and security requirements for regulated environments including emerging AI governance practices.
- Strong communication skills to influence design decisions without direct ownership of delivery teams.
- Ability to translate security risks into actionable remediation guidance for product and engineering teams.
Nice-to-Haves
- Experience working within fintech, wealth management, banking, payments, or other highly regulated financial services environments.
- Hands-on experience testing APIs, microservices, cloud-native platforms, and AI-enabled applications.
- Familiarity with AI security testing methodologies, including prompt injection testing, LLM red teaming, agent and tool abuse testing, and AI-enabled software delivery workflows for security risks and required controls.
- Hands-on experience with application security and vulnerability management tools, including SAST, SCA, DAST, IAST, ASPM, cloud security, and penetration-testing platforms.
- Threat modeling and security design reviews.
- Certifications (optional): CISSP, CSSLP, CCSP
Skills they ask for
Pick one to see other roles that ask for it.
About Envestnet
Wealth technology for financial advisorsEnvestnet provides wealth management technology and services that help financial advisors support clients and manage investments.
See all 44 roles at EnvestnetMore roles at Envestnet
See all 44- Associate Solutions ArchitectThiruvananthapuram · Entry Level · HybridInformation Technology · Entry Level · HybridThiruvananthapuram, India2w
- Lead Software Development EngineerThiruvananthapuram · Lead · HybridSoftware Development · Lead · HybridThiruvananthapuram, India2w
- Senior Data Intelligence AdvisorThiruvananthapuram · Senior · HybridData and Analytics · Senior · HybridThiruvananthapuram, India2w
- Client Service AssociateRaleigh · HybridCustomer Service · HybridRaleigh, United States2w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.