Principal Engineer — Product & Application Security
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, AI Engineer (Applied/Software)
Job Description
We are looking for a Principal Engineer — Product & Application Security to be the top technical authority for how Freshworks builds secure software. As an IC6 Principal, you set the multi-year security technical vision for our products and platform, make the calls on our hardest security‑architecture problems, and are the person the company relies on when the stakes are highest — across a multi‑tenant SaaS estate serving 72,000+ customer accounts and hundreds of integrations.
As Freshworks evolves from a suite of service products into an AI‑first system of business intelligence — with autonomous agents, a Knowledge and Context Graph, and a growing agentic surface — the security bar must rise with it. This role goes beyond leading individual reviews and remediations: you define the secure‑by‑design paradigms, reference architectures, and organization‑wide standards that determine how thousands of engineers ship, and you drive the strategic bets (AI/agent security, supply‑chain integrity, zero‑trust data protection) that keep Freshworks ahead of the threat curve.
You will operate as a company‑wide force multiplier — writing code and reference implementations, setting technical direction that outlives any single project, mentoring Staff and Senior Staff security engineers, and partnering directly with VP Engineering, the CISO organization, and product leadership to make security a durable competitive advantage.
Key Responsibilities Security Technical Vision & Strategy- Own the multi‑year technical vision and architecture strategy for product and application security across all Freshworks products (Freshdesk, Fresh service, and the shared Platform), and drive alignment on it across engineering and the CISO organization
- Define the secure‑by‑design reference architectures, paradigms, and organization‑wide standards (authN/authZ, tenant isolation, data protection, secrets, API security) that thousands of engineers build against
- Set the strategic security agenda for the AI‑first platform — securing the AI Agent Platform, Knowledge/Context Graph, and agentic workflows — anticipating threat classes before they reach production
- Act as the final technical decision‑maker and tie‑breaker on the hardest, highest‑risk security‑architecture trade‑offs
- Lead threat modeling and security design reviews for the most critical, cross‑cutting, and highest‑risk systems — including identity and access, the integrations/connector framework (300+ apps), and the agent runtime
- Set the standard for secure code review, manual and AI‑assisted penetration testing, and vulnerability analysis; drive root‑cause remediation strategies that eliminate whole vulnerability classes across the estate, not one bug at a time
- Architect and harden multi‑tenant security controls: strict tenant isolation, authentication/authorization models, secrets management, data protection, and API gateway security
- Own the security design for AI/agentic features — prompt injection defense, tool‑invocation authorization, non‑human identity, and permission‑scoped context access
- Define the organization‑wide, AI‑assisted left‑shift strategy: how SAST, DAST (e.g., Snyk), SCA/dependency scanning, secret detection, and IaC scanning are embedded across every CI/CD pipeline to catch issues before production
- Set the direction for security tooling, automation, and paved‑road frameworks and libraries that make the secure path the default path — including code‑component asset inventory (API/SBOM/RBAC/secrets/integrations) and secure‑by‑default product hardening
- Own the software supply‑chain security strategy: centralized software artifact repository management (e.g., Sonatype Nexus), code artifact repository guardrails, and CI/CD pipeline hardening
- Establish secure coding standards, golden patterns, and guardrails; operationalize threat modeling and maturity models (SAMM) across the product portfolio; and define the security quality gates the whole org is measured against
- Serve as the top technical escalation point for the most severe security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).