VAPT-DevSecops Experts
Job description
About the Role
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market. What unites Anaplanners across teams and geographies is our collective commitment to our customers' success and to our Winning Culture. Our customers rank among the who's who in the Fortune
50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins - big and small. Supported by operating principles of being strategy-led, values-based and disciplined in execution, you'll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let's build what's next - together!
This role, Senior Vulnerability Remediation Engineer, falls under the Products Security - Anaplan division. You will report to the Senior Manager, Platform Security and work within a hybrid model based in Gurugram.
Why This Role Matters
This is an exciting opportunity to make a significant impact at Anaplan! In this role, you will be at the forefront of scaling security through automation and self-service. You'll be the driving force behind transforming security intent into enforced, self-service controls across the SDLC and CI/CD pipelines. Think dependency policy, secrets handling, least-privilege access, and the guardrails that allow engineering teams to innovate rapidly without compromising security.
When done right, this is some of the most high-leverage work in our function. Every control you implement will run continuously for every team, seamlessly integrated into their workflows!
Why Anaplan
Anaplan is not just another SaaS application; it's a powerful platform that performs highly dimensional, enterprise-scale modeling with responsive recalculation and strong correctness expectations. Our technical landscape is rich and varied, featuring the legacy Hyperblock engine, the innovative Polaris engine, and an expanding suite of AI-powered products like CoModeler for AI-assisted model building and CoPlanner for conversational, analyst-style planning support.
With AI revolutionizing software development, we are embracing more generated code and autonomous changes, making the need for encoded, verifiable guardrails more critical than ever. Security is woven into the fabric of how our platform evolves, rather than treated as an afterthought. Join our small, dynamic team where your contributions to automation will set the gold standard!
What You'll Do
- Automate vulnerability remediation workflows across the CI/CD pipeline to reduce mean time to resolution.
- Implement policy-as-code frameworks to enforce dependency and package security rules automatically within build systems.
- Leverage AI and LLM-assisted tooling to accelerate the development and triage of security controls and remediation steps.
- Build and maintain automated detection for secrets and credentials to prevent and respond to leaks proactively.
- Construct controlled repository models that restrict external dependencies and guide engineers toward approved package paths.
- Reduce standing privileges by automating least-privilege access and just-in-time authorization mechanisms.
- Integrate scanner outputs into low-noise, actionable workflows that prioritize remediation and avoid alert fatigue.
- Automate attack-surface hardening through golden image creation and baseline enforcement via code-driven controls.
- Provide self-service security tooling and paved paths so engineering teams can operate securely without manual gates.
- Collaborate with platform teams to embed security checks seamlessly into development, testing, and deployment processes.
- Drive continuous improvement of security automation coverage and effectiveness across the application lifecycle.
- Support the design and implementation of guardrails that protect the integrity of Anaplan's AI-infused modeling platforms.
- Own end-to-end automation projects that demonstrate measurable risk reduction and operational efficiency gains.
- Act as a technical leader for VAPT initiatives, ensuring alignment with industry best practices and evolving threats.
Requirements
- Must have demonstrated experience in building and operating security automation within CI/CD and SDLC environments.
- Possess strong scripting and programming skills to implement security controls as code using modern infrastructure and automation tools.
- Have a deep understanding of vulnerability management, dependency risks, and secure software supply chain practices.
- Show proven ability to work with policy-as-code frameworks and integrate them into automated enforcement workflows.
- Demonstrate experience integrating security scanning tools and normalizing output for automated remediation and tracking.
- Bring knowledge of secrets management and detection mechanisms to prevent unauthorized access and data leakage.
- Understand cloud infrastructure and containerization concepts relevant to building hardened images and runtime protections.
- Commit to following security frameworks and compliance requirements as part of automated enforcement strategies.
Nice to Have
- Experience with AI-assisted security tooling and large language models to enhance vulnerability detection and remediation.
- Familiarity with Anaplan's technology landscape, including the Hyperblock and Polaris engines, as well as AI-powered products like CoModeler and CoPlanner.
- Background in platform security roles within SaaS or high-scale software environments.
- Contributions to open source security tooling or active participation in security automation communities.