Application Security Engineer (AppSec)
Rubiscape Application Security Engineer (AppSec)
About the Role
Every line of code that ships in
Rubiscape’s platform touches sensitive enterprise data, AI model outputs, and
business-critical decisions for Fortune 500 customers. As an Application
Security Engineer, you will be the security champion embedded in the software
development lifecycle — owning SAST/DAST tooling, secure code review, and
developer security enablement across Rubiscape’s six studios. You will
transform AppSec from a gate into a growth accelerator, ensuring that Rubiscape
ships fast without trading away the security posture that enterprise customers
and government deployments require.
Key Responsibilities
· Integrate and operate SAST
(SonarQube, Semgrep) and DAST (OWASP ZAP, Burp Suite) tooling into CI/CD
pipelines; define severity thresholds and enforce build-break policies.
· Perform security design reviews
and secure code reviews for high-risk features including RubiAI prompt
injection surfaces, RubiStudio model serving endpoints, and multi-tenant data
isolation in RubiSight.
· Maintain and continuously
update Rubiscape’s secure development lifecycle (SDL) standards, OWASP Top 10 /
API Security Top 10 mappings, and language-specific secure coding guidelines.
· Run bug bounty triage,
coordinate responsible disclosure processes, and manage external penetration
testing engagements end-to-end.
· Build automated dependency and
SCA scanning (Snyk, Dependabot) into the build process; own the third-party
library vulnerability backlog and drive resolution within policy SLAs.
· Deliver secure coding
workshops, threat modelling training, and security champions programme for
Rubiscape’s engineering guilds.
· Produce application-layer
security findings for SOC 2, ISO 27001, and customer security audits; liaise
with GRC on evidence collection and control mapping.
Nice to Have
· Certifications: OSWE, GWEB, or
BSCP (PortSwigger Web Security).
· Experience securing LLM/GenAI
application surfaces including prompt injection, model inversion, and data
exfiltration via AI APIs.
· Familiarity with supply-chain
security standards (SLSA, SBOM generation, Sigstore).
· Prior work on a multi-tenant
B2B SaaS platform serving regulated-sector enterprise customers.
About Rubiscape
Rubiscape is India’s leading Decision
Intelligence Platform, unifying data engineering, BI, machine learning, and
agentic AI in a single governed platform. Built in Pune and trusted by Fortune
500 enterprises across BFSI, manufacturing, healthcare, and government. 8
international innovation patents. 10 Industry-Academia Labs & COEs. From BI
to AI — One Platform. Every Decision.
Requirements
Requirements
· 3+ years of application
security experience in a product engineering environment with a shipped SaaS or
enterprise software product.
· Demonstrated hands-on skill
with SAST/DAST tools and CI/CD integration (GitHub Actions, Jenkins, or GitLab
CI).
· Strong understanding of OWASP
Top 10, API Security Top 10, and common web application vulnerability classes
(SQLi, XSS, SSRF, IDOR, prompt injection).
· Ability to read and review code
in at least two of: Python, Java, TypeScript/Node.js, Go.
· Experience managing SCA tooling
and coordinating remediation of CVEs in third-party dependencies.
