Bengaluru · Staff/Principal
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
LOW
InvestCloudOct2024 is showing limited hiring activity lately. Expect slight delayed response.
First 72 hours
Still inside it - posted 3h agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
SECURITY ENGINEERING AT INVESTCLOUD
At InvestCloud, we are building an intelligent security response capability that determines what to fix first based on the actual risk to our clients and business, not a scanner's native severity.
Traditional vulnerability management produces disconnected findings and long backlogs. It often misses whether vulnerable code is deployed, reachable by an attacker, connected to a critical service, capable of lateral movement, or already being exploited. We are solving that problem by combining threat intelligence, runtime and deployment evidence, configuration management data, attack path analysis, business criticality, and validation results.
The platform will ingest findings from infrastructure, cloud, application, software supply chain, secrets, containers, infrastructure as code, and adversarial testing. It will reconcile them to a canonical asset and service model, deduplicate them into unique exposures, and rank the remediation actions that remove the most risk.
The product is being built in Python on AWS with source-controlled connectors, deterministic policy code, an AI reasoning layer, human approval gates, complete audit evidence, and closed-loop validation. Large language models (LLMs) can correlate evidence, recommend remediation, and explain decisions. They do not calculate the authoritative priority score.
This is not another scanner or dashboard. It is a security decision and remediation platform that must answer one question reliably: what is the single next action that will remove the most material risk, why is it first, who owns it, and how will we verify the risk is gone? Every engineer on this team will build production software, operate what they build, and own the product after the initial consultant implementation.
THE ROLE
As our Application Security & Triage Engineer, you will own the deterministic risk intelligence layer that decides what InvestCloud fixes first. You will convert observations from infrastructure and code scanners into unique exposures, enrich them with threat, deployment, reachability, attack path, client, and business context, then map them to the remediation actions that remove the most risk.
Your output is not a bucket of critical, high, and medium findings. It is one explainable action queue that identifies the single next action, the risk it removes, the affected services and clients, the accountable owner, and the evidence required for closure. The authoritative ranking must be versioned policy code, not an LLM opinion.
WHAT YOU WILL OWN
WHAT WE ARE LOOKING FOR
CORE TOOLING & TECHNOLOGIES
Python · SQL · pytest · Snyk · Semgrep / SonarQube · Burp Suite · OWASP ZAP · Wiz · Rapid7 / Tenable · SARIF · SBOM / VEX · CVSS / EPSS / KEV / SSVC · Jira Assets · GitLab CI · REST / GraphQL · Datadog
WHY JOIN THIS TEAM
You will own the logic that differentiates this platform from a scanner. Without precise correlation and contextual ranking, the organization still has a larger backlog, not a better decision.
With this layer working, InvestCloud can state exactly which action should happen next and show the evidence behind it. Your judgment, code, and calibration will determine whether the team consistently removes the most material risk first.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
More Security Engineer roles in Bengaluru
See allKeep browsing