Freshworks

Freshworks

Principal Engineer — Product & Application Security

San Mateo, CA, United States · Principal

Sponsorship not specifiedDetected 7 days ago
JavaScriptTypeScriptPythonJavaGoRubyCode ReviewAWSKubernetesTerraformCI/CDOAuthLLMsAgentic AICybersecurityPenetration TestingSIEMIncident ResponseComplianceCRMZero TrustResearchLeadershipCommunication

About the role

  • Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives.
  • Software is a choice that can make or break a business.
  • Business software has become a blocker instead of ways to get work done.

Responsibilities

  • Define the secure-by-design reference architectures, paradigms, and organization-wide standards (authN/authZ, tenant isolation, data protection, secrets, API security) that thousands of engineers build against
  • Lead threat modeling and security design reviews for the most critical, cross-cutting, and highest-risk systems - including identity and access, the integrations/connector framework (300+ apps), and the agent runtime
  • Set the standard for secure code review, manual and AI-assisted penetration testing, and vulnerability analysis; drive root-cause remediation strategies that eliminate whole vulnerability classes across the estate, not one bug at a time
  • Own the security design for AI/agentic features - prompt injection defense, tool-invocation authorization, non-human identity, and permission-scoped context access
  • Own the software supply-chain security strategy: centralized software artifact repository management (e.g., Sonatype Nexus), code artifact repository guardrails, and CI/CD pipeline hardening
  • Set the risk-based prioritization framework for findings from internal testing, bug bounty, third-party pen tests, and researcher disclosures, and drive systemic fixes
  • Drive cross-organizational security initiatives to completion through technical credibility and clarity - building consensus across many teams without formal authority
  • To create a better experience for their customers and employees.
  • Create better or worse experiences.
  • Freshworks Inc. builds uncomplicated service software that delivers exceptional employee and customer experiences.

Nice to have

  • Deep experience securing ITSM, CX/CRM, or service-management products and their data models
  • Recognized external contributions: open-source security projects, published research, CVEs, standards bodies, or conference talks (e.g., Black Hat, DEF CON, OWASP)
  • Industry certifications such as OSCP, OSWE, GWAPT, CISSP, or equivalent (valued, not required)
  • Experience defining or
  • Authoritative grasp of cryptographic and compliance standards relevant to enterprise SaaS - e.g., FIPS 140-2/140-3, PCI, SOC 2, ISO 27001, and Google CASA / TX-RAMP control frameworks
  • Deep understanding of securing AI/LLM and agentic systems - including Claude and other LLM security concerns such as prompt injection, insecure tool use, model/data exposure, and non-human identity
  • Ability to set technical direction for and influence an entire engineering organization - and senior executives (VP/CISO) - through technical credibility and clear communication
  • A genuine service-oriented, "make the secure path the easy path" mindset toward internal developers

Skills

  • Shape the strategy for the bug bounty and responsible-disclosure program

Benefits

  • With a fresh vision for how the world works.

Company info

  • Influence company-level strategy: advise VP Engineering, the CISO organization, and product leadership; represent Freshworks' product-security posture to enterprise customers, auditors, and (where appropriate) the external security community

This listing is sourced directly from Freshworks's careers page and normalized into a canonical job model.