HHiring Reality
← Druva

Staff Engineer, Software Security

Druva
Location
Pune, Maharashtra, India
Posted
1 month ago
Department
Engineering Product Security
What they actually want (must-haves)
  • 3–5 years of security engineering experience in a SaaS product company
  • Deep expertise in OWASP Top 10, CWE 25, threat modeling, cryptography, container security, and secure SDLC frameworks
  • Hands-on experience reviewing AI security risks, particularly around Agentic AI systems and LLM security controls
  • Experience using AI tools to optimize security engineering workflows
  • Proficient in code review and scripting with Python, Go, or Javascript
  • Hands-on with tools like Burp Suite, Snyk, OWASP ZAP, and CI/CD security scanners
Nice to have
  • Relevant certifications (OSCP, OSWE, CSSLP, GIAC)
  • Active community contributions (OWASP, BSides, NullCon, Black Hat, etc)
What the job really is

The Staff Engineer, Software Security role at Druva involves integrating security practices into the software development lifecycle, particularly focusing on AI security and automation. Responsibilities include conducting threat modeling, automating security controls within CI/CD pipelines, and collaborating with various teams to enhance the security of SaaS products. The position also requires reviewing code and managing third-party open-source risks while providing training and guidance to developers on secure coding practices.

Things to weigh
  • Focus on AI security may require continuous learning due to the rapidly evolving nature of the field
  • No specific salary or benefits information provided
  • Hands-on development experience is considered a major plus, which may imply a need for coding skills beyond security expertise
Job score2.6/5
Benefits1/5
Freshness4/5
Career value4/5
Role clarity4/5
Pay transparency0/5

Applying to Druva?

See how your résumé matches this role — and tailor it from what actually gets interviews.