Haystack
← Back to Jobs
Technology
PI

Product Security Engineer

Precisely International JobsIndia🇮🇳IndiaPosted 5 Oct 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
India
Posted
12 hours ago
GCPAWSOWASPAzureGitLLMPenetration TestingPostmanPythonTriage

Job Description

At Precisely, we're not just building software — we're shaping the future of data integrity. As a global leader in data quality, data enrichment, and location intelligence, Precisely helps thousands of the world's most trusted brands make confident decisions with data they can rely on. We're an AI-first organization, which means artificial intelligence isn't a buzzword here — it's woven into how we build products, how we work, and how we think about solving complex problems for our customers. When you join Precisely, you join a team of curious, driven innovators who believe that better data makes the world run better. If you're ready to do meaningful work at the intersection of AI and data — and help define what's possible — we'd love for you to apply!

Overview: 

You will join our global Product Security team to test our products the way an attacker would — finding real, exploitable risk across web applications, APIs, containers, cloud environments and AI-enabled features, and working with engineering and product teams to get it fixed. You will work across a wide range of products and systems, so you will build breadth quickly, and your findings will directly shape how securely we design and ship. We're looking for someone who tests methodically, communicates findings clearly, and keeps building new skills as attack techniques and AI-assisted tooling evolve.

What you will do:

  • Perform hands-on security testing across web applications, APIs, containers, cloud environments (AWS, Azure, GCP) and AI-enabled features, using manual techniques and security tooling to validate real, exploitable risk rather than raw scanner output.
  • Prioritize findings by exploitability and business impact rather than automated severity score alone, and track them through to verified remediation and retest.
  • Contribute to threat modeling, secure design reviews and architecture discussions early in the development lifecycle, so risks are caught before code ships.
  • Assess identity and access control weaknesses, authentication and authorization models, and modern application and cloud architectures for privilege escalation and misconfiguration risk.
  • Test AI-enabled features and agentic workflows for prompt injection, tool misuse, excessive agency and other AI-specific failure modes, and frame probabilistic findings as reproducible, actionable reports.
  • Partner with engineering and product teams to explain findings clearly, review fixes, and support secure design and development practices.
  • Strengthen security across the software delivery lifecycle, including build pipelines, deployment processes and release practices.
  • Document findings and recommendations clearly, and support triage of externally reported vulnerabilities alongside the team that owns coordinated disclosure.
  • Research emerging attack techniques and AI-assisted testing tools, and apply them to improve testing coverage, consistency and speed without giving up manual validation of what matters.
  • Share knowledge across the team to continuously improve how we test, communicate risk and support secure product development.

What we are looking for:

  • Education: Bachelor's degree in Computer Science, Information Security or a related field; equivalent practical experience accepted in place of formal education.
  • Years of experience: 3+ years of experience performing penetration testing or application security.
  • Years of experience needed with specific skills Experience testing across web applications, APIs, containerized deployments and multi-cloud environments (AWS, Azure, GCP), including embedded or agentic AI applications.
  • Specific technical or software skills required Demonstrable expertise with tools such as Burp Suite, OWASP ZAP, Postman, Git, and Python or similar scripting languages.
  • Necessary certifications None required; see Preferred Skills.
  • Travel is required: No
  • Strong understanding of the OWASP Top 10, the OWASP Top 10 for LLM Applications, SANS, and MITRE ATT&CK.
  • Experience validating vulnerabilities through manual testing, distinguishing real, exploitable risk from raw scanner output.

AI Skills/Knowledge:

  • Familiarity with security risks in AI-enabled features — prompt injection, tool misuse, excessive agency, memory poisoning and insecure model integrations — and how they chain into real attack scenarios.
  • Able to evaluate AI-generated content critically, verify technical accuracy, and use sound judgment before applying outputs to security testing, analysis or decision-making.
  • Demonstrated ability to identify security testing activities that can be automated with AI, and implement practical automation that improves coverage, consistency, speed or reporting quality while maintaining human validation of security decisions.
  • Comfort configuring and tuning AI-assisted coding and testing tools (e.g., GitHub Copilot, Claude Code), and staying current with emerging AI attack techniques and testing methodologies.

Preferred Skills (a plus but not required):

  • Experience with threat modeling and secure design reviews.
  • Familiarity with cloud security concepts and common risks in modern application environments.
  • Experience testing APIs, desktop applications, or legacy and mainframe systems (IBM i, z) is beneficial.
  • Relevant security certifications such as OSCP, PNPT, GPEN, GWAPT, CEH, or CompTIA Security+; a background in software engineering is also a plus.

#LI-SA1

Application and Interview Impersonation Notice:  Impersonating another individual when applying for employment, and/or participating in an interview process to assist another individual in obtaining employment, with Precisely Software Incorporated (“Precisely”) is unlawful.  If Precisely identifies such fraudulent conduct, then as applicable and to the extent permitted by law, the application will be rejected, an offer (if made) will be rescinded, or the employment will be terminated, and legal action may be taken against the impersonators.

The personal data that you provide as a part of this job application will be handled in accordance with relevant laws. For more information about how Precisely handles the personal data of job applicants, please see the Precisely Candidate Privacy Notice

Similar jobs