About the role
structured by ORILead - Product Security EngineerJob type: Full Time · Department: Engineering · Work type: On-SiteChennai, Tamil Nadu, India Job detailsApplication formRocketlane is a B2B SaaS platform for client onboarding and project delivery, building Nitro, our AI-native product layer on Claude and MCP. We're hiring a Security…
What you will do
- Be the senior escalation point to investigate security incidents and lead root cause analysis for the incident and prepare RCA reports within one business day
- Own the customer-facing incident communication and response process
- Manage and mentor Product Security Engineers, reviewing their pentest findings, vulnerability triage, and remediation work, and stepping in on anything above their current level
- Set the technical bar for what "secure" means across our web app, APIs, mobile, cloud infra, and our AI/LLM-powered surfaces
- Own our cloud security posture: AWS WAF, IAM, TLS/cipher policy, container isolation, secrets management, and get ahead of the recurring findings
What they are looking for
- 6+ years in security, with real ownership of incident response for production SaaS systems, not just a support role in someone else's process
- Track record of leading root cause analysis on serious incidents: access control failures, data exposure, or RCE-class vulnerabilities, and turning that into concrete preventive controls
- Strong AWS security background: WAF, IAM, TLS/ALB/CloudFront policy, container and network isolation
- Experience managing or mentoring at least one other security engineer, or clear readiness to do so
- Comfortable being the calm, credible voice in a live incident, both internally with engineering and leadership, and externally with customers and their security teams
- Hands-on knowledge of AppSec fundamentals (OWASP Top 10, SAST/DAST, dependency management) and ideally some exposure to securing LLM/AI-powered applications
- Excellent written communication. You'll be writing incident RCAs, customer communications, and executive updates, often about the same incident on the same day
Nice to have
- Experience building or scaling a security function from a single IC to a small team
- Familiarity with GRC tooling (Sprinto or similar) and enterprise questionnaire platforms
- Background in a multi-tenant SaaS environment where tenant isolation is a first-order concern
- Security certifications (OSCP, CISSP, or equivalent hands-on credibility)
Full posting text
Lead - Product Security EngineerJob type: Full Time · Department: Engineering · Work type: On-SiteChennai, Tamil Nadu, India Job detailsApplication formRocketlane is a B2B SaaS platform for client onboarding and project delivery, building Nitro, our AI-native product layer on Claude and MCP. We're hiring a Security Lead to own product and infrastructure security end-to-end: setting direction, leading incident response. This is not a compliance-only role. You'll be the person we call when something breaks on a Saturday night, and the person who makes sure it doesn't keep happening.What you'll ownIncident responseBe the senior escalation point to investigate security incidentsLead root cause analysis for the incident and prepare RCA reports within one business dayOwn the customer-facing incident communication and response processProduct security leadershipManage and mentor Product Security Engineers, reviewing their pentest findings, vulnerability triage, and remediation work, and stepping in on anything above their current levelSet the technical bar for what "secure" means across our web app, APIs, mobile, cloud infra, and our AI/LLM-powered surfaces (prompt injection, unsafe code execution in agent tooling, tool-call boundaries)Own our cloud security posture: AWS WAF, IAM, TLS/cipher policy, container isolation, secrets management, and get ahead of the recurring findingsCross-functional ownershipBe a direct partner to the CTO on security strategy and risk decisionsRepresent security in front of customers and prospects when the stakes are high, including exec-level calls during live incidentsBuild the muscle and the process so that security incidents get caught internally, get root-caused properly, and get communicated to customers accuratelyWhat we're looking for6+ years in security, with real ownership of incident response for production SaaS systems, not just a support role in someone else's processTrack record of leading root cause analysis on serious incidents: access control failures, data exposure, or RCE-class vulnerabilities, and turning that into concrete preventive controlsStrong AWS security background: WAF, IAM, TLS/ALB/CloudFront policy, container and network isolationExperience managing or mentoring at least one other security engineer, or clear readiness to do soComfortable being the calm, credible voice in a live incident, both internally with engineering and leadership, and externally with customers and their security teamsHands-on knowledge of AppSec fundamentals (OWASP Top 10, SAST/DAST, dependency management) and ideally some exposure to securing LLM/AI-powered applicationsExcellent written communication. You'll be writing incident RCAs, customer communications, and executive updates, often about the same incident on the same dayNice to haveExperience building or scaling a security function from a single IC to a small teamFamiliarity with GRC tooling (Sprinto or similar) and enterprise questionnaire platformsBackground in a multi-tenant SaaS environment where tenant isolation is a first-order concernSecurity certifications (OSCP, CISSP, or equivalent hands-on credibility)Why this roleYou'd be the senior security voice at a fast-moving product company shipping AI agent features into production every week, with a direct line to the CTO and real authority over what gets fixed, how incidents get handled. If you want to build the process rather than just follow one, this is that role.Apply for this positionAutofill from resumeSave time by uploading your resume. (Only PDF or DOCX format supported)Upload fileLoading...Made with