--- title: 'Senior Product Security Engineer at Endor Labs' canonical: 'https://feeny.ai/job/senior-product-security-engineer-endor-labs-bengaluru-neqdd04t1r6g' type: 'job' last_seen: '2026-09-12' --- # Senior Product Security Engineer at Endor Labs - **Company:** Endor Labs - **Location:** Bengaluru, India - **Posted:** 2026-08-10 - **Last confirmed live:** 2026-09-12 - **Apply:** https://job-boards.greenhouse.io/endorlabs/jobs/4722197005 ## Job description ## Who We Are Endor Labs is building the Application Security platform for the software development revolution. Modern software is complex and dependency-rich, making it increasingly difficult to pinpoint the risks that truly matter. Endor Labs solves this challenge by building a call graph of your entire software estate—enabling teams to clearly identify, prioritize, and fix critical risks faster. Trusted by companies that are one or one hundred years old, Endor Labs secures code whether it was written by humans or AI, and whether it's 40-year-old C++ code or cutting-edge Bazel Monorepos. Endor Labs was founded by serial entrepreneurs Varun Badhwar and Dimitri Stiliadis, and is backed by leading VC firms such as Dell Technology Capital, Lightspeed, and Sierra Ventures. Sound interesting? Let’s talk if you want to be part of the next big leap in security innovation! ## How You'll Make an Impact This is an early, high-ownership role where you'll be one of the first dedicated members of our Security team and own application security end to end. Your charter is to secure the Endor Labs application from code to artifact to runtime—including the agents driving our AI SDLC and our platform itself. As an Application Security company, you’ll also be customer zero of our product, using it firsthand and helping shape the roadmap in the process. You’ll partner closely with the Head of Security & IT, as well as our engineering and product teams. - Own software supply chain security, including defenses against risks from open-source packages, third-party binaries, container base images, build tools, and other software dependencies. - Own first-party software security, including code and container scanning, automated security testing in CI, external penetration tests, and the integrity and provenance of software we build and publish. - Harden our AI agents by enforcing least-privilege access across MCP, credentials, filesystem, and network resources, while maintaining visibility into agent inventory and activity. - Own and run the responsible disclosure program, including triaging external reports, maintaining submission quality standards, and scaling the review process. - Partner with engineering teams from concept through implementation to conduct security design reviews, define secure architectures, and ensure security best practices are followed. - Help shape and evolve Endor Labs’ application security program as one of its earliest dedicated security team members. ## What You Bring to the Table If you are excited about building an application security program from the ground up and enjoy working at the intersection of security, engineering, and AI, we would love to talk to you! - 5+ years of experience in application security or product security, with strong hands-on experience across application security fundamentals. - At least 2 years of experience working with the security implications of agentic software development, with a strong understanding of how to capture its benefits while managing associated risks. - Strong experience with threat modeling and secure architecture design. - Practical experience securing build systems and CI/CD pipelines at scale; experience with Bazel monorepos is a strong plus. - Hands-on experience running penetration tests end-to-end and triaging bug bounty or responsible disclosure submissions. - Strong ability to investigate, understand, and remediate security issues rather than simply identifying and reporting them. - Comfortable working in ambiguous, fast-moving environments and defining priorities without an established playbook. - Relentlessly curious with an attacker mindset and the ability to dig deep into how systems work and identify root causes. - Strong collaboration and communication skills, with the ability to build trust and work effectively with engineering and product teams. - Willingness to be a customer zero of our security platform, provide thoughtful feedback, and help influence the product roadmap. ## Why Endor Labs We’re building at the intersection of developer productivity and security — one of the fastest-growing spaces in software. Our dev-loved platform has real ROI, strong momentum, and customers who care about doing things right. At Endor Labs, we think big, start small, and learn fast. We take ownership, move with purpose, and always start with the customer’s success. We debate with data, make the complex simple, and challenge each other with kindness and candor. We celebrate wins, learn from misses, and have fun along the way — because when our customers win, we all win. Endor Labs is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment, and we believe in the power of diverse perspectives and experiences. Even if you don't fit every requirement above, we encourage all talented individuals to apply—there's no one-size-fits-all here. ## About Endor Labs ## Company Overview - **One-liner**: Endor Labs provides an agentic application security platform that helps teams find, prioritize, and fix the most critical risks in code—whether written by humans or AI—faster. - **Entity Type**: Private (Series B); total funding $188M - **Headquarters**: Palo Alto, California, United States - **Founded**: 2021 - **Founders**: Varun Badhwar and Dimitri Stiliadis ## Core Business - **Primary industry/industries**: Application security, software supply chain security, AI security - **Target customers**: B2B, enterprise AppSec and development teams (including Fortune 500) - **Mission or purpose statement**: “Eliminating developer frustrations and security risks from the modern software development process” ([endorlabs.com/about](https://www.endorlabs.com/about)) ## Products & Services - **AURI (Agentic AI AppSec Platform)**: Combines agentic reasoning with deterministic program analysis to deliver verifiable, audit-ready security findings across AI-generated and human-written code. Integrates with AI coding agents via Hooks, Skills, MCP, or CLI. - **Secrets Detection**: Detects and validates exposed secrets in code. - **Malware Prevention**: Prevents malware from infiltrating the software supply chain. - **SCA Reachability**: Reachability-based analysis of direct and transitive open-source dependencies. - **Container Reachability**: Reachability-based scanning of container images. - **AI SAST**: AI-native detection, triage, and remediation of flaws in source code. - **AI Security Code Review**: Continuous AI-powered security reviews for pull requests. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: Annual revenue $55.0M (LinkedIn estimate); total funding $188.0M across 4 rounds (Series A $70M in 2024, Series B $93M in 2025) - **Notable Investors/Partners**: DFJ Growth, Lightspeed Venture Partners, Coatue, Dell Technologies Capital, and over 40 industry leading operators and executives - **Growth Signals**: Fastest-growing AppSec company ever (per company); headcount 162 (+32.2% YoY); operates in 10 countries; launched agentic AI platform for the “vibe coding” era; expanded from reachability-based SCA to a full AppSec platform in 2024 ## Competitive Advantages - **Reachability & exploitability analysis** cuts through noise by showing only vulnerabilities that actually affect the codebase. - **Deterministic program analysis + agentic reasoning** provides verifiable, reproducible findings with audit-ready evidence. - **Full-stack reachability** across source code, open-source dependencies, containers, and secrets. - **Integrated but independent security layer** for AI coding agents – enforces policy-as-code across all agents without blocking developer velocity. ## Strategic Focus - Leading security for the “vibe coding” era where most code will be AI-generated. - Continuing to expand the platform beyond software composition analysis into full application security (SAST, secrets, container, malware). - Deepening integrations with AI coding assistants (via Hooks, Skills, MCP, CLI) to embed security without friction. ## Why Work Here - **Culture**: Values include “Be Human,” “Have Fun,” “Own It,” “Think Big, Start Small, Learn Fast.” Described as “smart, funny, nerds.” Global annual offsites, company-wide events, hackathons, and departmental team-buildings. - **Remote/Hybrid/Office**: Globally distributed team with flexibility to work from anywhere. Home office equipment stipend and cell phone/internet reimbursement. Offices in Palo Alto (HQ), Delft (Netherlands), and Bengaluru (India). - **Notable perks**: Competitive medical, dental, vision; Flexible Spending Account and Health Savings Account; 401k; parental leave; flexible PTO; diverse holiday observance; life insurance. - **Engineering culture**: Deep investment in AI, ML, and static analysis research – founders and team hail from Amazon, Cisco, Meta, GitHub, Microsoft, Palo Alto Networks, Splunk, Uber. Research regularly appears in top venues (ICSE, ASE, IEEE TSE). ## Sources 1. [endorlabs.com](https://www.endorlabs.com/) 2. [Endor Labs About Page](https://www.endorlabs.com/about) 3. [Endor Labs Careers](https://www.endorlabs.com/careers) 4. [LinkedIn Company Profile](https://www.linkedin.com/company/endorlabs) 5. [Greenhouse Job Board](http://job-boards.greenhouse.io/endorlabs) ## Other roles at Endor Labs - [Staff Backend Software Engineer](https://feeny.ai/job/staff-backend-software-engineer-endor-labs-palo-alto-50bpr9hbs49v) — Palo Alto, CA - [Enterprise Account Executive - TOLA](https://feeny.ai/job/enterprise-account-executive-tola-endor-labs-texas-q0qq77r54fh0) — Texas - [Senior Quality Engineer(SDET)](https://feeny.ai/job/senior-quality-engineer-sdet-endor-labs-bengaluru-91fbs97mgvjf) — Bengaluru, India - [Security Engineer - Vulnerability Management](https://feeny.ai/job/security-engineer-vulnerability-management-endor-labs-bengaluru-pphhmsbqdyy2) — Bengaluru, India - [IT Engineer](https://feeny.ai/job/it-engineer-endor-labs-bengaluru-dv9gxwkbwkyk) — Bengaluru, India - [Senior Technical Recruiter](https://feeny.ai/job/senior-technical-recruiter-endor-labs-united-states-hahpv5rzt5vp) — United States - [Technical Success Engineer](https://feeny.ai/job/technical-success-engineer-endor-labs-panama-vfh564wgz10y) — Panama - [Technical Success Architect](https://feeny.ai/job/technical-success-architect-endor-labs-united-states-h898w7etqxe2) — United States - [Solutions Architect - East](https://feeny.ai/job/solutions-architect-east-endor-labs-united-states-rv3f5sav9t7j) — United States - [Enterprise Account Executive - Southeast](https://feeny.ai/job/enterprise-account-executive-southeast-endor-labs-atlanta-p45p79ky5dq3) — Atlanta, GA