Overview
Own Anyscale's secure software development lifecycle and partner with engineering to build security into the product. This senior, high-ownership role reports to the Head of Security and is based in India.
What you'll do
- Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt.
- Partner with engineering on security features and secure-by-design architecture, from early design through implementation.
- Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work.
- Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand.
- Drive vulnerabilities to resolution with engineering against defined SLAs.
- Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks.
- Mentor other engineers and raise the security bar across the organization.
What you'll need
- 8+ years in product or application security, with senior-level depth, ideally at a high-growth startup.
- Demonstrated ownership of a secure software development lifecycle at scale, including threat modeling and secure design review.
- A strong hands-on background partnering with engineering on security features and architecture, not just reporting findings.
- Deep experience with software composition analysis, secret scanning, and SAST or secure-development tooling in real repositories.
- A solid understanding of software supply chain security and how to enumerate what an organization ships, including SBOM approaches.
- Experience triaging vulnerabilities using CVSS and business context and driving them to resolution with engineering.
- The communication and seniority to set direction, review others' work, and raise the bar for those around you.
Nice to have
- Experience producing vulnerability or security posture reporting for enterprise or regulated customers.
- Familiarity with container artifact security, including image scanning, signing, and SBOM generation.
- Experience building or maturing an SSDL program at scale.
- Background in AI or ML platforms or distributed systems.
Details
Read the full description and apply on the company’s own careers page.