Freshworks
Principal Engineer — Product & Application Security
San Mateo, CA, United States · Principal
Sponsorship not specifiedDetected 8 days ago
JavaScriptTypeScriptPythonJavaGoRubyCode ReviewAWSKubernetesTerraformCI/CDOAuthLLMsAgentic AICybersecurityPenetration TestingSIEMIncident ResponseComplianceCRMZero TrustResearchLeadershipCommunication
About the role
- Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives.
- Software is a choice that can make or break a business.
- Business software has become a blocker instead of ways to get work done.
Responsibilities
- Define the secure-by-design reference architectures, paradigms, and organization-wide standards (authN/authZ, tenant isolation, data protection, secrets, API security) that thousands of engineers build against
- Lead threat modeling and security design reviews for the most critical, cross-cutting, and highest-risk systems - including identity and access, the integrations/connector framework (300+ apps), and the agent runtime
- Set the standard for secure code review, manual and AI-assisted penetration testing, and vulnerability analysis; drive root-cause remediation strategies that eliminate whole vulnerability classes across the estate, not one bug at a time
- Own the security design for AI/agentic features - prompt injection defense, tool-invocation authorization, non-human identity, and permission-scoped context access
- Own the software supply-chain security strategy: centralized software artifact repository management (e.g., Sonatype Nexus), code artifact repository guardrails, and CI/CD pipeline hardening
- Set the risk-based prioritization framework for findings from internal testing, bug bounty, third-party pen tests, and researcher disclosures, and drive systemic fixes
- Drive cross-organizational security initiatives to completion through technical credibility and clarity - building consensus across many teams without formal authority
- To create a better experience for their customers and employees.
- Create better or worse experiences.
- Freshworks Inc. builds uncomplicated service software that delivers exceptional employee and customer experiences.
Nice to have
- Deep experience securing ITSM, CX/CRM, or service-management products and their data models
- Recognized external contributions: open-source security projects, published research, CVEs, standards bodies, or conference talks (e.g., Black Hat, DEF CON, OWASP)
- Industry certifications such as OSCP, OSWE, GWAPT, CISSP, or equivalent (valued, not required)
- Experience defining or
- Authoritative grasp of cryptographic and compliance standards relevant to enterprise SaaS - e.g., FIPS 140-2/140-3, PCI, SOC 2, ISO 27001, and Google CASA / TX-RAMP control frameworks
- Deep understanding of securing AI/LLM and agentic systems - including Claude and other LLM security concerns such as prompt injection, insecure tool use, model/data exposure, and non-human identity
- Ability to set technical direction for and influence an entire engineering organization - and senior executives (VP/CISO) - through technical credibility and clear communication
- A genuine service-oriented, "make the secure path the easy path" mindset toward internal developers
Skills
- Shape the strategy for the bug bounty and responsible-disclosure program
Benefits
- With a fresh vision for how the world works.
Company info
- Influence company-level strategy: advise VP Engineering, the CISO organization, and product leadership; represent Freshworks' product-security posture to enterprise customers, auditors, and (where appropriate) the external security community
Apply directly at Freshworks →Create a free account for alerts like thisView Freshworks immigration profile
This listing is sourced directly from Freshworks's careers page and normalized into a canonical job model.