CodeRabbit
Posted 1mo ago

Security Engineer

CodeRabbit
Bengaluru, Karnataka, India
OnsiteFull Time
Responsibilities
  • owning roadmap
  • hardening infrastructure
  • leading incidents
Requirements
  • 8+ years security engineering/incident response experience
  • Deep expertise in threat modeling
  • Pen testing
  • CI/CD and cloud security
  • Incident response, and building security tooling. Leadership and hiring experience preferred
Technical tools mentioned
SASTDASTSIEMEDRCI/CDSDK

Job description

About CodeRabbit

CodeRabbit is an innovative research and development company focused on building extraordinarily productive human-machine collaboration systems. Our primary goal is to create the next generation of Gen AI-driven code reviewers: a symbiotic partnership between humans and advanced algorithms that significantly outperforms individual engineers. We combine language models with human ingenuity to push the boundaries of software development efficiency and quality.

Role Overview:

CodeRabbit is on a mission to empower developers with lean, high-performance tools—they move fast, and so do the threats. That's why we're looking for a battle-tested Lead Security Engineer who’s been in the trenches and can architect, harden, and defend our infrastructure, tooling, and ecosystem.

As our Lead Security Engineer, you’ll lead security engineering at CodeRabbit, infusing security into every layer of our product and infrastructure. You become the steward of resilience, incident response, and proactive defense at scale.

 

Responsibilities:

  • Own the security roadmap — craft and execute a strategic security engineering plan that aligns with CodeRabbit’s fast-paced engineering cadence.

  • Boost resilience — champion defence-in-depth tactics: threat modeling, secure design reviews, hardening, CI/CD integration.

  • Be Incident Commander — spearhead security incident response and recovery: triage, resolve, root cause, and turn those learnings into stronger systems.

  • Tools & automation — build or integrate security tooling (SAST, DAST, SIEM, EDR, monitoring) into the developer workflow without slowing delivery.

  • Embed security fluently — partner with engineering and product teams to bring secure practices early into planning and daily workflows.

  • Talent & culture — help to hire, coach, and mentor a scrappy, resilient security engineering team; elevate security awareness across the company.

  • Compliance & policy — establish security standards, frameworks, or processes that evolve as we scale—but remain lean and developer-friendly.

     

Qualifications:

  • Battle-tested experience: 8+ years in security engineering, incident response, or correlated fields—bonus if you've led through a major production breach or targeted attack.

  • Technical depth: Extensive experience with security across software and infrastructure—threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.

  • Strategic mindset: Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.

  • Praxis over theory: You’ve taken production systems down (intentionally or unintentionally) and built them back stronger.

  • Security in chaos: Experience in pressure situations—with clarity, direction, and calm.

  • Developer‑centric approach: You can speak fluent dev-tools, empathise with fast-moving teams, and secure them without slowing them down.

 

Bonus Points:

  • You’ve implemented DevSecOps tooling and orchestrated shift‑left security in developer pipelines.

  • You’ve recovered from (or prevented) a critical security event, and turned that into an engineering culture improvement.

  • Experience in a dev‑tools, SDK, or platform-heavy company.

  • Hacker mindset + operational discipline - pentests, disaster recovery, threat hunting, tooling, cloud environments.

  • Certifications like CISSP, CISM, CEH, or relevant cloud security certs.

 

Why Join Our Engineering Culture?

  • CodeRabbit is building the next generation of AI-native developer tooling — starting with code review. We combine large language models with deep software engineering context to help teams ship faster, catch more bugs, and make better architectural decisions at scale.

  • We are a high-ownership engineering culture. That means no passive execution, no waiting for perfect tickets, and no narrowly defined task boundaries. Engineers here find problems before they're assigned, use AI as a core part of how they build, ship with judgment, and own outcomes from proposal to production.

  • Our operating philosophy: bias toward action, ship the smallest necessary coherent slice, validate proportional to risk, watch what happens, and make the system better. AI drafts; humans decide. Speed matters, but so does understanding what you ship.

  • This opportunity will be energising for people who want real ownership, pace, and high standards. It's uncomfortable for people who prefer slow consensus or heavily managed workflows.

  • If you want to build tools that are changing how software gets written, and be held to the standard that the best engineers thrive under; we'd love to talk.

 

Our Values

  • 🤝 Collaborative Humans: Prioritizing collective intelligence

  • 🚀 Fearless Innovators: Turning obstacles into growth opportunities

  • 💪 Persistent, Passionate Developers: Thriving on complex, long-term challenges

  • 🎯 Impact-Driven Creators: Crafting intuitive tools for developers

  • 🧠 Rapid Learners and Un-learners: Adapting quickly in our fast-paced technological world

About CodeRabbit

AI-powered platform for automated code reviews and pull requests.

Year founded
2023
Employees
138
Organization type
Private
Latest investment
Raised $60.00M Series B (2025) — led by Scale Venture Partners
Headquarters
US

Similar jobs

Security Engineer roles near Bengaluru, Karnataka
2d
Save
Mark Applied
Hide
Engineering-L2-Bengaluru-Associate-Security Engineering
Bengaluru, Karnataka, India
OnsiteFull Time
Goldman Sachs
Goldman SachsNYSE: GS: Global investment banking, securities, and investment management firm.
3+ YOERequires 3+ years of cybersecurity experience, Python and PowerShell scripting, security frameworks knowledge, threat intelligence, automation strategies, analytical skills, and strong technical communication.
SOAR, MITRE ATT&CK, NIST, Python, PowerShell
3d
Save
Mark Applied
Hide
Senior Security Engineer - Product Security
Bangalore, Karnataka, India
OnsiteFull Time
Ecolab
EcolabNYSE: ECL: Provides water, hygiene, and infection prevention solutions and services.
6+ YOEBachelor’s degree in computer science, information technology, or related field; 6–8 years in product security; expertise in application security, penetration testing, secure code review, DevSecOps, AI security, and cloud environments.
OWASP Top 10, CWE Top 25, SAST, DAST, Python, JavaScript, TypeScript, Java, C#, .NET, Apex, CI/CD, DevSecOps, WAF, Fastly, Cloudflare, Akamai, Snyk, Qualys, Burp Suite, Wiz, Postman, MobSF, Elastic, Agentic Scanner, Azure, AWS, GCP, ADO, GitHub
4d
Save
Mark Applied
Hide
Senior Security Engineer
Bangalore or Chennai or Hyderabad or Kochi or Noida or Pune or Thiruvananthapuram
OnsiteFull Time
UST
UST: Global provider of digital transformation and IT services.
5+ YOERequires 5–7 years of security engineering experience, hands-on Splunk, Microsoft Sentinel, Cribl, log parsing, detection engineering, and a bachelor's degree in computer science, IT, or information security.
Splunk, Microsoft Sentinel, Cribl Stream, Cribl Edge, SPL, KQL, MITRE ATT&CK, CIM, ASIM, Python, PowerShell, EDR, IAM, DLP
4d
Save
Mark Applied
Hide
Senior Security Engineer
Bangalore, Karnataka, India
OnsiteFull Time
Commonwealth Bank
Commonwealth BankASX: CBA: Provides comprehensive retail, business, and institutional financial services.
Experience in security engineering or architecture, threat modeling, risk assessment, DevSecOps, automation, cloud platforms, IaC, CI/CD, containers, Python or TypeScript, APIs, and security frameworks. Bachelor's or master's degree in engineering required.
DevSecOps, Software Development Lifecycle, CI/CD, Infrastructure as Code, Python, TypeScript, MITRE ATT&CK, OWASP, NIST, STRIDE, APIs, GenAI
6d
Save
Mark Applied
Hide
Senior Security Engineer
Bengaluru, Karnataka, India
HybridFull Time
SmartStream
SmartStream: Provides AI-powered financial transaction lifecycle management software.
7+ YOERequires 7+ years in application or product security, offensive and defensive security experience, programming in at least two listed languages, SAST/DAST/SCA expertise, web security knowledge, and mentoring experience.
Java, Python, JavaScript, TypeScript, Go, C#, SAST, DAST, SCA, OWASP Top 10, SANS Top 25, ASVS, SBOM, TLS, HSMs
1w
Save
Mark Applied
Hide
Security Engineer – Security Operations (SecOps)
Bengaluru, Karnataka, India
OnsiteFull Time
Creative ITC
Creative ITC: Provides managed cloud infrastructure and cybersecurity for complex IT environments.
3+ YOEBachelor's degree in a related field, Security+ or ISC2 CC, English proficiency, and 3+ years of technical security experience; Microsoft Security Stack, Proofpoint, DNS filtering, and incident response experience preferred.
Microsoft Security Stack, Proofpoint, Cisco Umbrella, Zscaler, ServiceNow, Jira Service Management, CyberArk, Entra, SailPoint, Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview, Microsoft Entra ID, Data Loss Prevention (DLP), Microsoft E5
1w
Save
Mark Applied
Hide
Expert Security Engineer - Offensive Security
Bengaluru or Pune
OnsiteFull Time
Finastra
Finastra: Develops software for global retail and transaction banking.
5+ YOE5+ years offensive security experience including red/purple team, penetration testing, detection engineering, exploit development, cloud and application security; strong Python skills and technical writing.
Python, MITRE ATT&CK, EDR, SIEM, XDR, AWS, Azure, CI/CD
1w
Save
Mark Applied
Hide
Security Engineer III
Bengaluru, Karnataka, India
HybridFull Time
Zuora
Zuora: Cloud software for managing subscription billing and revenue recognition.
4+ YOE4+ years in application security or related engineering, experience with secure SDLC, threat modeling, code reviews, OWASP, security tooling; strong communication and mentoring skills.
Java, Spring, Rest API, Microservices, Kafka, Spark, NodeJS, AWS, Kubernetes, Terraform, AngularJS, SAST, DAST, SCA, Python, JavaScript, Go