Product Security Engineer, Senior

TraceLink
TraceLink

Product

Pune, Maharashtra, India

Posted on Sep 22, 2026

Company overview:

TraceLink is the world’s largest Agentic Business Network, enabling life sciences and healthcare companies to build and manage a scalable digital workforce of governed, no-code AI agents that execute and coordinate mission-critical supply chain operations alongside human teams. Powered by the Integrate-Once™ OPUS platform, TraceLink links more than 300,000 network participants, enabling multi-enterprise processes at global scale.

Founded in 2009 with the simple mission of protecting patients, today Tracelink has 5 global offices, over 800 employees and more than 1700 customers in over 60 countries around the world. Our expanding product suite continues to protect patients and now also enhances multi-enterprise collaboration through innovative new applications such as MINT.

Tracelink is recognized as an industry leader by Gartner and IDC, and for having a great company culture by Comparably.

As part of the Product Security team, you will help secure and advance TraceLink's products and internal application development. Working closely with Product Managers, Architects, Software Engineers, and Security and continually improve how security is built into the software development lifecycle, including AI aspects.


This is a senior individual contributor role. You will take on our hardest and least-defined product security problems, act as the security technical lead on major products and initiatives, and work with a high degree of autonomy. You are trusted to scope your own work, decide how a problem should be approached, and deliver with minimum supervision. You will remain deeply hands-on running assessments, reading and writing code, building the tooling and patterns that other engineers reuse.


It increasingly also means securing AI-enabled product capabilities and the agentic tooling inside our own development pipeline, an area where the right answers are still being written and where we expect you to help work them out.


What you will do:


Partner with Engineering across the SDLC


  • Serve as senior security SME for engineering by supporting secure architecture, security requirements, and design reviews
  • Lead threat modeling including abuse and misuse cases for AI-enabled and agentic features
  • Secure coding guidance for Java and JavaScript, manual and automated code review, including review of AI-assisted and agent-generated code
  • Triage and validate findings from SAST, SCA, DAST and secrets scanning, separating signal from noise and driving fixes to closure and tuning or retiring rules that produce more noise than value
  • Hands-on security assessments and white-box testing of services, APIs, and multi-tenant boundaries
  • Author the secure design patterns, guidance, and reusable components that engineering teams build against by default

Build the paved road


  • Build and improve automation and guardrails in our CI/CD pipelines including pre-merge checks, policy-as-code, and golden paths that make secure the default rather than a gate
  • Use AI and LLM tooling to scale security work by finding triage, code review, test generation, remediation guidance — with human verification of the output
  • Maintain and tune the existing security toolchain, evaluate and pilot new tooling, bringing a clear technical recommendation when it is time to adopt or drop something
  • Drive innovation and maturity in the SDLC with new toolsets and automation
  • Track coverage, false-positive rate, time to remediate, and act on what they show

Secure our AI features and AI supply chain


  • Review LLM and agent-backed features for prompt injection, excessive agency and data leakage
  • Maintain clear security guidelines and controls for agentic code contributions, ensuring code review standards, proper attribution, and appropriate access safeguards
  • Implement safeguards that detect and block unapproved or malicious changes introduced by AI agents
  • Apply references such as the OWASP Top 10 for LLM Applications and MITRE ATLAS as practical engineering checklists against real attack paths and write our own guidance wherever necessary

Software supply chain and vulnerability management


  • Maintain supply chain integrity through SBOM accuracy, build provenance, and artifact signing
  • Drive risk-based vulnerability prioritization using reachability, exploitability, and EPSS against agreed SLAs
  • Serve as technical lead during PSIRT response for significant product vulnerabilities
  • Support customer-facing vulnerability communications and drive the systemic fixes that prevent recurrence

Grow the practice, inside and out


  • Develop and deliver training, run office hours and threat modeling workshops, and support security champions program
  • Maintain expertise in application security, emerging threat vectors, and attacker tradecraft and improve standards accordingly
  • Represent TraceLink's security practice externally through customer conversations, written content, and conference or community participation

Skills and Requirements:


  • 7+ years in application or product security or software engineering with substantial security ownership
  • Hands-on experience applying threat modeling or other risk identification techniques
  • Strong knowledge of application security testing tools across SAST, SCA, DAST, secrets, IaC and a clear-eyed view of what each one does and doesn't catch
  • Deep understanding of the OWASP Top 10 for web, APIs and AI/LLM, including avoidance and remediation techniques, and the ability to explain real exploitability to an engineer
  • Strong knowledge of secure coding practices in Java and/or JavaScript able to read code fluently and submit remediation pull requests
  • Experience remediating complex enterprise-level security issues end to end
  • Working knowledge of cloud environments (ideally AWS and Azure) and CI/CD pipelines
  • A working understanding of how LLM-based features and AI coding assistants change the risk picture and the curiosity to go deeper
  • Strong analytical and problem-solving skills
  • Strong verbal and written communication skills, with both engineering and non-engineering audiences

Preferred Skills:


  • Familiarity with AWS and Azure services
  • Knowledge of microservices, event-driven architecture and multi-tenant SaaS isolation
  • Experience with ASPM platforms and reachability-based vulnerability prioritization
  • Experience securing or red teaming AI, ML, or agentic systems
  • Penetration testing, CTF experience, a hacker's mindset
  • Bachelor's degree or equivalent experience in Computer Science, Information Systems Security, or a related field

Please see the Tracelink Privacy Policy for more information on how Tracelink processes your personal information during the recruitment process and, if applicable based on your location, how you can exercise your privacy rights. If you have questions about this privacy notice or need to contact us in connection with your personal data, including any requests to exercise your legal rights referred to at the end of this notice, please contact Candidate-Privacy@tracelink.com.