Staff Security Engineer II

Confluent Confluent · Data AI · India · Remote · Engineering

Staff Application Security Engineer responsible for shaping and advancing the application security strategy across Confluent's on-premises products and cloud services. This role involves defining the long-term security posture, leading the design and evolution of application security architecture, and ensuring security is embedded throughout the product lifecycle. The engineer will act as a strategic partner to Engineering and Product leadership, influence architectural direction, proactively mitigate risks, and architect and oversee security automation and tooling.

What you'd actually do

  1. Partner closely with Engineering, Product, and Platform teams to identify security risks early, influence architectural decisions, and drive adoption of secure-by-design practices across the organization.
  2. Define and standardize threat modeling frameworks and security design standards, and lead security design reviews for complex, distributed systems, providing actionable architectural guidance to engineers and product managers.
  3. Serve as the subject matter expert (SME) for product security implementation reviews, overseeing security code reviews and API security testing while providing definitive remediation guidance.
  4. Architect and drive the roadmap for security automation, building scalable software security tooling to transform product security operations and vulnerability management practices.
  5. Design and lead the deployment of automation and orchestration frameworks that integrate security seamlessly into the cloud-native deployment pipeline.

Skills

Required

  • 10–12 years of hands-on Application Security experience
  • Comprehensive knowledge of security fundamentals as applied to modern web applications and cloud-native platforms including secure software design and architecture, secure coding practices, common vulnerability classes.
  • Ability to partner as a trusted peer with Engineering and Product leadership to embed security into the core architecture of the organization.
  • Ability to lead technical investigation and response to application security incidents while driving preventive improvements through architecture and automation.
  • Proven experience evolving the software development lifecycle to embed security by default, from securing CI/CD pipelines and build systems to implementing automated security guardrails in cloud-native deployment workflows.
  • Experience in Go, Python, or Java, with the ability to design and build scalable security automation frameworks.
  • Experience in leading cross-functional initiatives in distributed environments, translating security requirements into clear, executable technical roadmaps.
  • A data-driven decision-maker who can balance security requirements with business velocity and engineering trade-offs to deliver outcomes.
  • Ability to raise the organization’s security bar through architectural reviews, advanced technical guidance, and the development of engineers across all levels.

Nice to have

  • Passion for applying AI and LLMs to automate complex security workflows, reduce manual toil, and drive measurable improvements in security outcomes.

What the JD emphasized

  • security automation
  • secure-by-design practices
  • security design reviews
  • API security testing
  • automation and orchestration frameworks
  • security automation
  • AI and LLMs to automate complex security workflows