Source description
About the role
As a Senior Security Engineer at Truveta, you will be responsible for leading data security, threat modeling, and security reviews across applications and platforms to ensure the protection of sensitive data and the implementation of strong security foundations. Your role will involve collaborating closely with engineering teams to influence architecture decisions and embed security early in the development lifecycle. Key Responsibilities: - Lead security design reviews for new and existing systems, identifying risks and driving secure architecture decisions. - Perform threat modeling for services and platforms, translating threats into actionable engineering requirements. - Define and implement data protection strategies, including data classification and handling standards, encryption (at rest/in transit), key management, and secrets handling. - Review application architectures and APIs for security weaknesses and design flaws. - Conduct third-party/vendor security assessments to identify and mitigate risks. - Partner with engineering teams to remediate findings and enhance system design. - Establish and evolve secure design patterns and guidelines for developers. - Integrate security into design and development workflows (shift-left). - Evaluate and secure AI/ML use cases, addressing risks such as data leakage and prompt injection. - Contribute to security standards, policies, and best practices across the organization. Required Qualifications: - 812+ years of experience in security engineering or application security. - Strong expertise in threat modeling and secure system design. - Deep understanding of application security principles (OWASP Top 10, API security), data protection and privacy concepts, authentication, and authorization mechanisms. - Experience conducting architecture and design-level security reviews. - Ability to read and understand code across common languages. - Strong communication skills to influence engineering teams. Preferred Qualifications: - Experience in cloud environments (Azure preferred). - Familiarity with secure SDLC practices and DevSecOps tooling. - Experience with regulated environments (e.g., healthcare, finance). - Knowledge of AI/ML security risks. - Relevant certifications (e.g., CISSP, CSSLP). Truveta is seeking a strong analytical thinker who can identify risks early in design, translate security into practical engineering guidance, and work effectively across teams to influence decisions. As a Senior Security Engineer at Truveta, you will be responsible for leading data security, threat modeling, and security reviews across applications and platforms to ensure the protection of sensitive data and the implementation of strong security foundations. Your role will involve collaborating closely with engineering teams to influence architecture decisions and embed security early in the development lifecycle. Key Responsibilities: - Lead security design reviews for new and existing systems, identifying risks and driving secure architecture decisions. - Perform threat modeling for services and platforms, translating threats into actionable engineering requirements. - Define and implement data protection strategies, including data classification and handling standards, encryption (at rest/in transit), key management, and secrets handling. - Review application architectures and APIs for security weaknesses and design flaws. - Conduct third-party/vendor security assessments to identify and mitigate risks. - Partner with engineering teams to remediate findings and enhance system design. - Establish and evolve secure design patterns and guidelines for developers. - Integrate security into design and development workflows (shift-left). - Evaluate and secure AI/ML use cases, addressing risks such as data leakage and prompt injection. - Contribute to security standards, policies, and best practices across the organization. Required Qualifications: - 812+ years of experience in security engineering or application security. - Strong expertise in threat modeling and secure system design. - Deep understanding of application security principles (OWASP Top 10, API security), data protection and privacy concepts, authentication, and authorization mechanisms. - Experience conducting architecture and design-level security reviews. - Ability to read and understand code across common languages. - Strong communication skills to influence engineering teams. Preferred Qualifications: - Experience in cloud environments (Azure preferred). - Familiarity with secure SDLC practices and DevSecOps tooling. - Experience with regulated environments (e.g., healthcare, finance). - Knowledge of AI/ML security risks. - Relevant certifications (e.g., CISSP, CSSLP). Truveta is seeking a strong analytical thinker who can identify risks early in design, translate security into practical engineering guidance, and work effectively across teams to influence decisions.
More at Truveta
Related open roles
Senior Security Engineer Data Security (Hyderabad)
Hyderabad
Security Engineer - Endpoint
Hyderabad
Senior Security Engineer Endpoint
Hyderabad
Security Engineer - Microsoft 365 Security Administration
Hyderabad · Onsite
Senior Security Engineer - IAM
Hyderabad
Senior Security Engineer – Vulnerability Management & Penetration Testing
Hyderabad · Onsite