InvestCloud, Inc.

Principal Platform & Application Security Engineer

InvestCloud, Inc.  •  Bengaluru, IN (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

SECURITY ENGINEERING AT INVESTCLOUD

At InvestCloud, we are building an intelligent security response capability that determines what to fix first based on the actual risk to our clients and business, not a scanner's native severity.

Traditional vulnerability management produces disconnected findings and long backlogs. It often misses whether vulnerable code is deployed, reachable by an attacker, connected to a critical service, capable of lateral movement, or already being exploited. We are solving that problem by combining threat intelligence, runtime and deployment evidence, configuration management data, attack path analysis, business criticality, and validation results.

The platform will ingest findings from infrastructure, cloud, application, software supply chain, secrets, containers, infrastructure as code, and adversarial testing. It will reconcile them to a canonical asset and service model, deduplicate them into unique exposures, and rank the remediation actions that remove the most risk.

The product is being built in Python on AWS with source-controlled connectors, deterministic policy code, an AI reasoning layer, human approval gates, complete audit evidence, and closed-loop validation. Large language models (LLMs) can correlate evidence, recommend remediation, and explain decisions. They do not calculate the authoritative priority score.

This is not another scanner or dashboard. It is a security decision and remediation platform that must answer one question reliably: what is the single next action that will remove the most material risk, why is it first, who owns it, and how will we verify the risk is gone? Every engineer on this team will build production software, operate what they build, and own the product after the initial consultant implementation.

THE ROLE

As our Platform & Application Security Engineer, you will own the remediation and validation layer that turns prioritized risk into verified risk reduction. You will translate exposures into precise root cause fixes across code, dependencies, cloud, platform, network, identity, and configuration.

The first production phase is recommend only, with changes executed through InvestCloud's approved change process. You will still build the action library, dry run controls, state capture, tests, and rollback mechanisms required for future controlled automation. You will also ensure the harness itself and InvestCloud's client-facing applications are secured and that every closed item is technically validated.

WHAT YOU WILL OWN

  • Remediation Engineering: Convert prioritized exposures into specific, technically correct fixes, including code changes, dependency upgrades, configuration updates, base image changes, WAF rules, identity controls, network containment, patch workflows, and compensating controls. Provide pull request-ready guidance where possible.
  • Safe Action Framework: Design action contracts with explicit preconditions, scope, approvals, idempotency, dry run output, state capture, canary or staged execution, success criteria, time limits, rollback, and kill switch behavior. Keep executors disabled until the required governance and testing are complete.
  • Application & API Security: Perform secure code review and testing for web, API, service, authentication, authorization, injection, server-side request forgery, deserialization, file handling, secrets, and business logic risks. Use SAST, SCA, DAST, and manual techniques to validate root cause and fix quality.
  • Platform, Cloud & Supply Chain Remediation: Implement or guide hardening across AWS, containers, Kubernetes, infrastructure as code, CI/CD, WAF, network segmentation, identity, secrets, operating systems, and software supply chain components. Understand the operational impact of each change.
  • Validation & Closed Loop: Verify remediation through targeted VVAH or adversarial testing, DAST, scanner rescans, runtime evidence, and control checks. Confirm the exposure is removed, capture residual risk and audit evidence, trigger rollback or reopen when validation fails, and update the source systems.
  • Engineering Partnership & Delivery: Work directly with product, platform, SRE, and service owners to assign accountable actions, protect release velocity, and drive closure. Contribute production Python, tests, APIs, runbooks, documentation, and code reviews to the permanent harness codebase.

WHAT WE ARE LOOKING FOR

  • 7+ years in application security, platform security, product security, cloud security, or security engineering, with strong hands-on remediation and software delivery experience. Finding issues without fixing them is not enough.
  • Production Python plus the ability to read and safely modify enterprise application code. You can build tested integrations, remediation tools, APIs, and pull-request-quality fixes rather than one-off scripts.
  • Deep application and API security knowledge. You can trace exploitability, reproduce high-impact issues, reason through attack chains, review authentication and authorization, and verify that a fix closes the root cause.
  • Broad platform remediation experience across WAF, network, identity, cloud, containers, Kubernetes, operating systems, CI/CD, secrets, dependencies, and infrastructure as code. You can balance security, availability, and client impact.
  • Secure software development lifecycle experience with Snyk, Semgrep, or SonarQube, Burp Suite or OWASP ZAP, SARIF, GitLab CI or equivalent, quality gates, exceptions, and developer workflows.
  • Safe automation engineering, including preconditions, idempotency, dry runs, rollback, state management, canaries, approval gates, evidence, and failure recovery. You understand why reversible does not automatically mean safe.
  • A persistent, self-directed builder who uses AI responsibly to increase quality and speed, explains technical decisions clearly, earns trust with engineering teams, and drives problems to verified closure without creating unnecessary friction.

CORE TOOLING & TECHNOLOGIES

Python · FastAPI · Burp Suite · OWASP ZAP · Snyk · Semgrep / SonarQube · GitLab CI · Jira / JSM · WAF · IAM and network controls · Kubernetes / Docker · Terraform · Ansible · REST APIs · VVAH / DAST · pytest · Datadog

WHY JOIN THIS TEAM

You will own the point where analysis becomes measurable risk reduction. The harness's value isn't that it finds more findings. It gives teams the right fix, executes only within approved boundaries, and proves the risk is gone.

Your work will determine whether remediation is safe, reversible, operationally practical, and credible to product teams, auditors, clients, and senior leadership.

InvestCloud, Inc.

About InvestCloud, Inc.

InvestCloud, a global leader in wealth technology, aspires to enable a smarter financial future. Driving the digital transformation of the wealth management industry, the company serves a broad array of clients globally, including Wealth and Asset Managers, Wirehouses, Banks, RIAs, and Insurers. In terms of scale, the company’s clients represent more than 40 percent of the $132 trillion of total assets globally. As a leader in delivering personalization and scale across advisory programs, including unified managed accounts (UMA) and separately managed accounts (SMA), the company is committed to the success of its clients. By equipping and enabling advisors and their clients with connected technology, enhanced intelligence, and inspired experiences, InvestCloud delivers leading digital wealth management and financial planning solutions, complemented by a dynamic data warehouse, which scale across the complete wealth continuum. In 2024, InvestCloud was named a CNBC World’s Top Fintech Company, a proof point of the company’s commitment to innovation and client success. Headquartered in the United States, InvestCloud serves clients around the world.

Industry
Finance & Insurance
Company Size
1,001-5,000 employees
Headquarters
West Hollywood, CA
Year Founded
Unknown
Social Media