Product Security Engineer
Whatfix is a global B2B SaaS leader seeking a Product Security Engineer to secure applications across the SDLC. The role involves performing VAPT, threat modeling, and integrating automated security testing into CI/CD pipelines. Candidates must have expertise in application security, SAST/DAST tools, and proficiency in languages like Java or Python. This position involves collaboration with engineering and GRC teams to maintain compliance with SOC 2 and FedRAMP standards.
50k new jobs listed every day. Install TAL to find more jobs like this.

Experience
3-7 years
Function
Engineering
Work mode
Onsite, India
Company
Tier 1
What you will work on
Whatfix is a global B2B SaaS leader seeking a Product Security Engineer to secure applications across the SDLC. The role involves performing VAPT, threat modeling, and integrating automated security testing into CI/CD pipelines. Candidates must have expertise in application security, SAST/DAST tools, and proficiency in languages like Java or Python. This position involves collaboration with engineering and GRC teams to maintain compliance with SOC 2 and FedRAMP standards.
TAL's take
Strong Tier 1 company with a clearly defined product security role and well-articulated technical requirements.
The JD is highly specific regarding security responsibilities, required stack, and team collaboration goals.
Salaries at Whatfix
28.3 LPA average
Based on 36 Grapevine salary entries for Whatfix.
Engineering
2 - 4 years | D2
20 LPA average
Range: 16 - 24 LPA
Engineering
6 - 8 years | E5
36 LPA average
Range: 36 - 36 LPA
Engineering
8 - 10 years | Lead
36 LPA average
Range: 36 - 36 LPA
Sales
0 - 2 years | D2
9 LPA average
Range: 9 - 9 LPA
Must haves
- 3-7 years of experience in product security
- Strong knowledge of OWASP Top 10 and CWE Top 25
- Hands-on experience with SAST, DAST, SCA, and secret scanning
- Proficiency in Java, .NET, or Python
- Experience with DevSecOps and CI/CD pipelines
Tools and skills
Nice to have: docker, kubernetes, threat modeling, checkmarx, burp suite, nuclei, ai penetration testing tools.
About the company
Recognized unicorn, Series E funded, strong B2B SaaS product footprint, and multiple industry awards/leader status.
Posts mentioning Whatfix
Everstage raising 30mil @ 150mil valuation🚀
Everstage, a SaaS startup, is in advanced stages to raise $30 million from new investor Eight Roads Ventures, valuing the company at $150 million. Existing backers like 3one4 Capital and Elevation Capital will also participate in the round. - What do they do? Everstage, founded in 2020, is a sales performance management platform designed to automate sales commissioning processes for companies. It counts PopMenu, Whatfix, Chargebee, and Alphasense among its customers. - Trends: Investors are increasingly focusing on SaaS startups, with reports of other companies in the space, such as Whatfix and HighPerformr, also securing significant funding rounds. - Market Outlook: The investment into Everstage reflects the growing interest in vertical platforms within the SaaS space, with various investors setting aside funds to invest in B2B SaaS startups. Scoop: Money Control
Ultimate Companies List
# Companies in India with highest pay ## Good WLB - Linkedin - Microsoft - Google - Atlassian - Adobe - Salesforce - Intuit - Apple - Twitter - Indeed - Expedia - Nvidia - VMWare - Intel - Flipkart - Inmobi - Nutanix - Morgan Stanley - JP Morgan ## Bad WLB - Uber - Tower Research - Amazon - Goldman Sachs - Codenation - Zomato - DE Shaw - Sprinklr - Arcesium - Harness - Coinbase ## Unknown WLB (Didn't find much data) - Rippling - Rubrik - Udaan - Sumologic - Cure Fit - Swiggy - Ola - Directi - ServiceNow - Stripe - Sharechat - Postman - Oracle (OCI) - Compass - HealthifyMe - Aviso - Target - Palo Alto Networks - Compass - Vizury - Qubole - Practo - Whatfix - World Quant - Alphonso - App Dynamics - Citrix - Cohesity - MotorQ - Hasura - Quadeye - Bloomreach - Instabase - AirBnB ------------------------------------------------ # Lower paying companies (AFAIK; please let me know if I am wrong) ## Good WLB - Cisco - Samsung - Walmart - Slack - Blackbuck - Oracle (other than OCI) - Visa - Intel - Qualcomm - ARM - Broadcom - Texas Instruments - Mentor Graphics ## Unknown WLB - Cred - Upgrad - Paypal - Dunzo - Unacademy - Oyo - BigBasket - Cloudera - Twilio - Box8 - MyGate - Jio - MakeMyTrip - Dream11 - BrowserStack - Razorpay - Juniper Networks - SanDisk - Redhat - Chowbotics (DoorDash) ## Bad WLB - Hotstar - Paytm - Wissen ------------------------------------------------ # Unknown compensation - Groupon - Gojek - Zoom - Grab - Truecaller - Snowflake (Should be high considering it pays well in US?) ------------------------------------------------ # Visa-sponsors outside US - Facebook London - Yelp London - Booking Amsterdam - Databricks Amsterdam - Spotify Stockholm - Zalando Berlin - ByteDance Singapore - Plenty of other options on Stackoverflow jobs. ------------------------------------------------ # Remote-first companies - Atlassian - Slack - Stackoverflow - Facebook - Datadog - Twitter - Square - Shopify - Github - Gitlab - Auth0 - Coinbase
[For whatfix employees] What % of your vested ESOP were bought back by the company?
https://thearcweb.com/article/software-whatfix-warburg-pincus-softbank-khadim-batti-tjg14y9xU2ji4ENQ The post claims 40% of employees participated in ESOP buyback. Would be great what % of ESOPs were bought back, will also be great to know how much they made post tax!