Live opening · Posted 7 days ago

Product Security Engineer, Senior

TraceLink, Inc · APAC - India - Pune
Greenhouse
You are 7 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 days ago
CompanyTraceLink, Inc
LocationAPAC - India - Pune
SourceGreenhouse
Listed7 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
23 min from Greenhouse publishing this role to us finding it
11 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,044 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Company overview:
TraceLink is the world’s largest Agentic Business Network, enabling life sciences and healthcare companies to build and manage a scalable digital workforce of governed, no-code AI agents that execute and coordinate mission-critical supply chain operations alongside human teams. Powered by the Integrate-Once™ OPUS platform, TraceLink links more than 300,000 network participants, enabling multi-enterprise processes at global scale.
Founded in 2009 with the simple mission of protecting patients, today Tracelink has 5 global offices, over 800 employees and more than 1700 customers in over 60 countries around the world. Our expanding product suite continues to protect patients and now also enhances multi-enterprise collaboration through innovative new applications such as MINT.
Tracelink is recognized as an industry leader by Gartner and IDC, and for having a great company culture by Comparably.
As part of the Product Security team, you will help secure and advance TraceLink's products and internal application development. Working closely with Product Managers, Architects, Software Engineers, and Security and continually improve how security is built into the software development lifecycle, including AI aspects.
This is a senior individual contributor role. You will take on our hardest and least-defined product security problems, act as the security technical lead on major products and initiatives, and work with a high degree of autonomy. You are trusted to scope your own work, decide how a problem should be approached, and deliver with minimum supervision. You will remain deeply hands-on running assessments, reading and writing code, building the tooling and patterns that other engineers reuse.
It increasingly also means securing AI-enabled product capabilities and the agentic tooling inside our own development pipeline, an area where the right answers are still being written and where we expect you to help work them out.
What you will do:
Partner with Engineering across the SDLC
Serve as senior security SME for engineering by supporting secure architecture, security requirements, and design reviews
Lead threat modeling including abuse and misuse cases for AI-enabled and agentic features
Secure coding guidance for Java and JavaScript, manual and automated code review, including review of AI-assisted and agent-generated code
Triage and validate findings from SAST, SCA, DAST and secrets scanning, separating signal from noise and driving fixes to closure and tuning or retiring rules that produce more noise than value
Hands-on security assessments and white-box testing of services, APIs, and multi-tenant boundaries
Author the secure design patterns, guidance, and reusable components that engineering teams build against by default
Build the paved road
Build and improve automation and guardrails in our CI/CD pipelines including pre-merge checks, policy-as-code, and golden paths that make secure the default rather than a gate
Use AI and LLM tooling to scale security work by finding triage, code review, test generation, remediation guidance — with human verification of the output
Maintain and tune the existing security toolchain, evaluate and pilot new tooling, bringing a clear technical recommendation when it is time to adopt or drop something
Drive innovation and maturity in the SDLC with new toolsets and automation
Track coverage, false-positive rate, time to remediate, and act on what they show
Secure our AI features and AI supply chain
Review LLM and agent-backed features for prompt injection, excessive agency and data leakage
Maintain clear security guidelines and controls for agentic code contributions, ensuring code review standards, proper attribution, and appropriate access safeguards
Implement safeguards that detect and block unapproved or malicious changes introduced by AI agents
Apply references such as the OWASP Top 10 for LLM Applications and MITRE ATLAS as practical engineering checklists against real attack paths and write our own guidance wherever necessary
Software supply chain and vulnerability management
Maintain supply chain integrity through SBOM accuracy, build provenance, and artifact signing
Drive risk-based vulnerability prioritization using reachability, exploitability, and EPSS against agreed SLAs
Serve as technical lead during PSIRT response for significant product vulnerabilities
Support customer-facing vulnerability communications and drive the systemic fixes that prevent recurrence
Grow the practice, inside and out
Develop and deliver training, run office hours and threat modeling workshops, and support security champions program
Maintain expertise in application security, emerging threat vectors, and attacker tradecraft and improve standards accordingly
Represent TraceLink's security practice externally through customer conversations, written content, and conference or community participation
Skills and Requirements:
7+ years in application or product security or software engineering with substantial security ownership
Hands-on experience applying threat modeling or other risk identification techniques
Strong knowledge of application security testing tools across SAST, SCA, DAST, secrets, IaC and a clear-eyed view of what each one does and doesn't catch
Deep understanding of the OWASP Top 10 for web, APIs and AI/LLM, including avoidance and remediation techniques, and the ability to explain real exploitability to an engineer
Strong knowledge of secure coding practices in Java and/or JavaScript able to read code fluently and submit remediation pull requests
Experience remediating complex enterprise-level security issues end to end
Working knowledge of cloud environments (ideally AWS and Azure) and CI/CD pipelines
A working understanding of how LLM-based features and AI coding assistants change the risk picture and the curiosity to go deeper
Strong analytical and problem-solving skills
Strong verbal and written communication skills, with both engineering and non-engineering audiences
Preferred Skills:
Familiarity with AWS and Azure services
Knowledge of microservices, event-driven architecture and multi-tenant SaaS isolation
Experience with ASPM platforms and reachability-based vulnerability prioritization
Experience securing or red teaming AI, ML, or agentic systems
Penetration testing, CTF experience, a hacker's mindset
Bachelor's degree or equivalent experience in Computer Science, Information Systems Security, or a related field
Please see the Tracelink Privacy Policy for more information on how Tracelink processes your personal information during the recruitment process and, if applicable based on your location, how you can exercise your privacy rights. If you have questions about this privacy notice or need to contact us in connection with your personal data, includ

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App