Endor Labs

Senior Product Security Engineer

Bengaluru, IndiaFull timeSeniorPosted about 10 hours ago
Apply on Endor Labs →

Sign into see who you know at Endor Labs.

Who We Are Endor Labs is building the Application Security platform for the software development revolution. Modern software is complex and dependency-rich, making it increasingly difficult to pinpoint the risks that truly matter. Endor Labs solves this challenge by building a call graph of your entire software estate—enabling teams to clearly identify, prioritize, and fix critical risks faster. Trusted by companies that are one or one hundred years old, Endor Labs secures code whether it was written by humans or AI, and whether it's 40-year-old C++ code or cutting-edge Bazel Monorepos. Endor Labs was founded by serial entrepreneurs Varun Badhwar and Dimitri Stiliadis, and is backed by leading VC firms such as Dell Technology Capital, Lightspeed, and Sierra Ventures. Sound interesting? Let’s talk if you want to be part of the next big leap in security innovation! How You'll Make an Impact This is an early, high-ownership role where you'll be one of the first dedicated members of our Security team and own application security end to end. Your charter is to secure the Endor Labs application from code to artifact to runtime—including the agents driving our AI SDLC and our platform itself. As an Application Security company, you’ll also be customer zero of our product, using it firsthand and helping shape the roadmap in the process. You’ll partner closely with the Head of Security & IT, as well as our engineering and product teams. Own software supply chain security, including defenses against risks from open-source packages, third-party binaries, container base images, build tools, and other software dependencies. Own first-party software security, including code and container scanning, automated security testing in CI, external penetration tests, and the integrity and provenance of software we build and publish. Harden our AI agents by enforcing least-privilege access across MCP, credentials, filesystem, and network resources, while maintaining visibility into agent inventory and activity. Own and run the responsible disclosure program, including triaging external reports, maintaining submission quality standards, and scaling the review process. Partner with engineering teams from concept through implementation to conduct security design reviews, define secure architectures, and ensure security best practices are followed. Help shape and evolve Endor Labs’ application security program as one of its earliest dedicated security team members. What You Bring to the Table If you are excited about building an application security program from the ground up and enjoy working at the intersection of security, engineering, and AI, we would love to talk to you! 5+ years of experience in application security or product security, with strong hands-on experience across application security fundamentals. At least 2 years of experience working with the security implications of agentic software development, with a strong understanding of how to capture its b...