Product Security Engineer, Senior
Pune, India · Full-time
- Posted 2w ago
- From TraceLink’s careers page
- Location
- Pune, India
- Type
- Full-time
- Level
- Senior
- Experience
- 7+ years
- Department
- Information Technology
Opens the listing on tracelink.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Company overview:
TraceLink is the world’s largest Agentic Business Network, enabling life sciences and healthcare companies to build and manage a scalable digital workforce of governed, no-code AI agents that execute and coordinate mission-critical supply chain operations alongside human teams. Powered by the Integrate-Once™ OPUS platform, TraceLink links more than 300,000 network participants, enabling multi-enterprise processes at global scale.
Founded in 2009 with the simple mission of protecting patients, today Tracelink has 5 global offices, over 800 employees and more than 1700 customers in over 60 countries around the world. Our expanding product suite continues to protect patients and now also enhances multi-enterprise collaboration through innovative new applications such as MINT.
Tracelink is recognized as an industry leader by Gartner and IDC, and for having a great company culture by Comparably.
What you will do:
Partner with Engineering across the SDLC
- Serve as senior security SME for engineering by supporting secure architecture, security requirements, and design reviews
- Lead threat modeling including abuse and misuse cases for AI-enabled and agentic features
- Secure coding guidance for Java and JavaScript, manual and automated code review, including review of AI-assisted and agent-generated code
- Triage and validate findings from SAST, SCA, DAST and secrets scanning, separating signal from noise and driving fixes to closure and tuning or retiring rules that produce more noise than value
- Hands-on security assessments and white-box testing of services, APIs, and multi-tenant boundaries
- Author the secure design patterns, guidance, and reusable components that engineering teams build against by default
Build the paved road
- Build and improve automation and guardrails in our CI/CD pipelines including pre-merge checks, policy-as-code, and golden paths that make secure the default rather than a gate
- Use AI and LLM tooling to scale security work by finding triage, code review, test generation, remediation guidance — with human verification of the output
- Maintain and tune the existing security toolchain, evaluate and pilot new tooling, bringing a clear technical recommendation when it is time to adopt or drop something
- Drive innovation and maturity in the SDLC with new toolsets and automation
- Track coverage, false-positive rate, time to remediate, and act on what they show
Secure our AI features and AI supply chain
- Review LLM and agent-backed features for prompt injection, excessive agency and data leakage
- Maintain clear security guidelines and controls for agentic code contributions, ensuring code review standards, proper attribution, and appropriate access safeguards
- Implement safeguards that detect and block unapproved or malicious changes introduced by AI agents
- Apply references such as the OWASP Top 10 for LLM Applications and MITRE ATLAS as practical engineering checklists against real attack paths and write our own guidance wherever necessary
Software supply chain and vulnerability management
- Maintain supply chain integrity through SBOM accuracy, build provenance, and artifact signing
- Drive risk-based vulnerability prioritization using reachability, exploitability, and EPSS against agreed SLAs
- Serve as technical lead during PSIRT response for significant product vulnerabilities
- Support customer-facing vulnerability communications and drive the systemic fixes that prevent recurrence
Grow the practice, inside and out
- Develop and deliver training, run office hours and threat modeling workshops, and support security champions program
- Maintain expertise in application security, emerging threat vectors, and attacker tradecraft and improve standards accordingly
- Represent TraceLink’s security practice externally through customer conversations, written content, and conference or community participation
Skills they ask for
Pick one to see other roles that ask for it.
About TraceLink
Digital supply chain software for life sciencesTraceLink provides a digital network and software platform for supply chain orchestration across life sciences and healthcare, supporting the manufacture and distribution of medicines.
See all 13 roles at TraceLinkMore roles at TraceLink
See all 13- Director, Applied Artificial IntelligenceWilmington · DirectorResearch and Development (R&D) · DirectorWilmington, United States3d
- Product Manager, SeniorPune · SeniorProduct Management · SeniorPune, India1w
- Contract Sales RecruiterWilmington · Senior · HybridHuman Resources · Senior · HybridWilmington, United States1mo
- Cloud Engineer IIPune · SeniorInformation Technology · SeniorPune, India1mo
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.