Jobs on TAL
All jobsOnsiteEngineeringb2b saas3-7 yearsowasp top 10
OnsiteMid Levelb2b saas

Product Security Engineer

WhatfixBengaluru, Karnataka, IndiaPosted 20 May 2026

Whatfix is a global B2B SaaS leader seeking a Product Security Engineer to secure applications across the SDLC. The role involves performing VAPT, threat modeling, and integrating automated security testing into CI/CD pipelines. Candidates must have expertise in application security, SAST/DAST tools, and proficiency in languages like Java or Python. This position involves collaboration with engineering and GRC teams to maintain compliance with SOC 2 and FedRAMP standards.

Matched by TAL

50k new jobs listed every day. Install TAL to find more jobs like this.

Install TAL

Experience

3-7 years

Function

Engineering

Work mode

Onsite, India

Company

Tier 1

What you will work on

Whatfix is a global B2B SaaS leader seeking a Product Security Engineer to secure applications across the SDLC. The role involves performing VAPT, threat modeling, and integrating automated security testing into CI/CD pipelines. Candidates must have expertise in application security, SAST/DAST tools, and proficiency in languages like Java or Python. This position involves collaboration with engineering and GRC teams to maintain compliance with SOC 2 and FedRAMP standards.

TAL's take

Quality 75/1005/5 clarityTier 1 company

Strong Tier 1 company with a clearly defined product security role and well-articulated technical requirements.

The JD is highly specific regarding security responsibilities, required stack, and team collaboration goals.

Salaries at Whatfix

28.3 LPA average

Based on 36 Grapevine salary entries for Whatfix.

View all salaries

Engineering

2 - 4 years | D2

20 LPA average

Range: 16 - 24 LPA

Engineering

6 - 8 years | E5

36 LPA average

Range: 36 - 36 LPA

Engineering

8 - 10 years | Lead

36 LPA average

Range: 36 - 36 LPA

Sales

0 - 2 years | D2

9 LPA average

Range: 9 - 9 LPA

Must haves

  • 3-7 years of experience in product security
  • Strong knowledge of OWASP Top 10 and CWE Top 25
  • Hands-on experience with SAST, DAST, SCA, and secret scanning
  • Proficiency in Java, .NET, or Python
  • Experience with DevSecOps and CI/CD pipelines

Tools and skills

owasp top 10cwe top 25sastdastscasecret scanning toolsrest apisoauth 2.0openid connectdevsecopsci/cdjenkinsgitjava.netpython

Nice to have: docker, kubernetes, threat modeling, checkmarx, burp suite, nuclei, ai penetration testing tools.

About the company

Recognized unicorn, Series E funded, strong B2B SaaS product footprint, and multiple industry awards/leader status.

Posts mentioning Whatfix

Everstage raising 30mil @ 150mil valuation🚀

Everstage, a SaaS startup, is in advanced stages to raise $30 million from new investor Eight Roads Ventures, valuing the company at $150 million. Existing backers like 3one4 Capital and Elevation Capital will also participate in the round. - What do they do? Everstage, founded in 2020, is a sales performance management platform designed to automate sales commissioning processes for companies. It counts PopMenu, Whatfix, Chargebee, and Alphasense among its customers. - Trends: Investors are increasingly focusing on SaaS startups, with reports of other companies in the space, such as Whatfix and HighPerformr, also securing significant funding rounds. - Market Outlook: The investment into Everstage reflects the growing interest in vertical platforms within the SaaS space, with various investors setting aside funds to invest in B2B SaaS startups. Scoop: Money Control

Indian Startups221

Ultimate Companies List

# Companies in India with highest pay ## Good WLB - Linkedin - Microsoft - Google - Atlassian - Adobe - Salesforce - Intuit - Apple - Twitter - Indeed - Expedia - Nvidia - VMWare - Intel - Flipkart - Inmobi - Nutanix - Morgan Stanley - JP Morgan ## Bad WLB - Uber - Tower Research - Amazon - Goldman Sachs - Codenation - Zomato - DE Shaw - Sprinklr - Arcesium - Harness - Coinbase ## Unknown WLB (Didn't find much data) - Rippling - Rubrik - Udaan - Sumologic - Cure Fit - Swiggy - Ola - Directi - ServiceNow - Stripe - Sharechat - Postman - Oracle (OCI) - Compass - HealthifyMe - Aviso - Target - Palo Alto Networks - Compass - Vizury - Qubole - Practo - Whatfix - World Quant - Alphonso - App Dynamics - Citrix - Cohesity - MotorQ - Hasura - Quadeye - Bloomreach - Instabase - AirBnB ------------------------------------------------ # Lower paying companies (AFAIK; please let me know if I am wrong) ## Good WLB - Cisco - Samsung - Walmart - Slack - Blackbuck - Oracle (other than OCI) - Visa - Intel - Qualcomm - ARM - Broadcom - Texas Instruments - Mentor Graphics ## Unknown WLB - Cred - Upgrad - Paypal - Dunzo - Unacademy - Oyo - BigBasket - Cloudera - Twilio - Box8 - MyGate - Jio - MakeMyTrip - Dream11 - BrowserStack - Razorpay - Juniper Networks - SanDisk - Redhat - Chowbotics (DoorDash) ## Bad WLB - Hotstar - Paytm - Wissen ------------------------------------------------ # Unknown compensation - Groupon - Gojek - Zoom - Grab - Truecaller - Snowflake (Should be high considering it pays well in US?) ------------------------------------------------ # Visa-sponsors outside US - Facebook London - Yelp London - Booking Amsterdam - Databricks Amsterdam - Spotify Stockholm - Zalando Berlin - ByteDance Singapore - Plenty of other options on Stackoverflow jobs. ------------------------------------------------ # Remote-first companies - Atlassian - Slack - Stackoverflow - Facebook - Datadog - Twitter - Square - Shopify - Github - Gitlab - Auth0 - Coinbase

Software Engineers27987

[For whatfix employees] What % of your vested ESOP were bought back by the company?

https://thearcweb.com/article/software-whatfix-warburg-pincus-softbank-khadim-batti-tjg14y9xU2ji4ENQ The post claims 40% of employees participated in ESOP buyback. Would be great what % of ESOPs were bought back, will also be great to know how much they made post tax!

Indian Startups40