Description
Job Location
The primary work location for this role is Trivadnrum with a hybrid or remote work model.
About Envestnet
Envestnet is an adaptive WealthTech company that is redefining the future of wealth management by helping advisors meet the moment with its comprehensive technology, actionable insights, and industry leading support. Backed by over 25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.
For a deeper look at how Envestnet is shaping the future of financial advice, visit www.envestnet.com.
The Team You’ll Join
You will join Envestnet’s Technology team, where we design, build, and maintain scalable, secure, and robust WealthTech solutions that power the future of financial advice. The team collaborates closely with product, operations, and business stakeholders to drive innovation, enhance efficiency, and enable sustainable growth. Guided by modern engineering practices and a commitment to domain excellence, technical rigor, and collaboration, the Technology team ensures our platforms remain resilient, adaptable, and aligned with evolving business needs making it a core driver of Envestnet’s long term success.
How You’ll Contribute
The Lead Product Security Engineer serves as the primary security partner for assigned products and platforms, ensuring security is embedded throughout product lifecycle. This role works closely with Product, Engineering, DevOps, and Cybersecurity teams to reduce security risk, drive secure-by-design practices and strengthen the overall security posture of Envestnet products.
The role combines hands-on security assessment, penetration testing, security review, vulnerability management and AI security expertise with technical leadership responsibilities. As a trusted security advisor and key point of contact, the individual supports day-to-day security operations across assigned product portfolio.
Key Responsibilities:
Product Security Operation and collaboration:
- Serve as the Product Security point of contact for assigned products and platforms.
- Partner with Product, Engineering and Architecture teams to embed security throughout the product life cycle.
- Monitor and oversee day-to-day security operations of assigned products and platform.
- Provide security review findings, remediation guidance, and risk-based recommendations to engineering teams.
- Coordinate within Cybersecurity team, Cloud Security, IAM, Security Operations, and Compliance teams address product security risks.
- Support adoption of established security standards, secure coding practices, and product security requirements.
Security reviews and assessments
- Conduct application security reviews and security design assessments.
- Perform hands-on penetration testing of web applications, APIs, cloud-native applications, and AI-enabled systems.
- Lead and perform security reviews for product releases and ensure Critical and High-risk findings are addressed before production deployment.
- Identify security weaknesses, validate remediation efforts, and drive vulnerability remediation initiatives.
- Participate in and support threat modeling and security design reviews.
Vulnerability Management and DevSecOps.
- Drive vulnerability management efforts across assigned products and platforms.
- Partner with engineering teams to prioritize and remediate findings from SAST, SCA, IAST, DAST, penetration testing, and cloud security assessments.
- Ensure security tooling is effectively integrated into CI/CD pipelines and development workflows.
- Monitor remediation SLAs, track security posture improvements, and reduce recurring security issues.
- Provide vulnerability matrix and other KPI data points to reporting team and other stakeholders in regular cadence.
AI Security
- Assess security risks associated with AI, LLM, Agentic AI, and RAG implementations.
- Conduct security reviews of Generative AI and Agentic AI applications, including LLM integrations, RAG pipelines, AI agents, MCP/tool integrations, orchestration frameworks, and third-party AI services.
- Validate AI security controls, guardrails, and secure-by-design implementations.
- Identify and drive remediation of risks including prompt injection, data leakage, excessive agent privileges, insecure tool execution, unsafe autonomy, and model misuse.
- Review AI-assisted development, coding agents, and AI-enabled software delivery workflows for security risks and required controls.
- Support AI security testing and secure adoption across assigned products and platforms.
Security Enablement
- Promote secure coding and secure-by-design practices across engineering teams.
- Support Security Champion and developer enablement programs.
What You’ll Need to Bring
- Bachelor’s/Master’s in Computer Science, Cybersecurity, or related field.
- Strong experience conducting product security reviews, threat modeling, security assessments, and secure design reviews within modern application environments.
- Hands on experience with threat modeling, security architecture reviews, and secure system design including AI-enabled systems.
- Solid understanding of modern application architectures, including microservices, APIs, and cloud native platforms.
- Working knowledge of AI/LLM concepts, including model integration patterns, RAG architecture, and agentic workflows.
- Knowledge of identity and access management, encryption standards, and secure integration patterns.
- Familiarity with industry frameworks such as OWASP, NIST, and security requirements for regulated environments including emerging AI governance practices.
- Strong communication skills to influence design decisions without direct ownership of delivery teams.
- Ability to translate security risks into actionable remediation guidance for product and engineering teams.
Nice-to-Haves
- Experience working within fintech, wealth management, banking, payments, or other highly regulated financial services environments.
- Hands-on experience testing APIs, microservices, cloud-native platforms, and AI-enabled applications.
- Familiarity with AI security testing methodologies, including prompt injection testing, LLM red teaming, agent and tool abuse testing, and AI-enabled software delivery workflows for security risks and required controls.
- Hands-on experience with application security and vulnerability management tools, including SAST, SCA, DAST, IAST, ASPM, cloud security, and penetration-testing platforms.
- Threat modeling and security design reviews.
Certifications (optional): CISSP, CSSLP, CCSP
-
Why You’ll Enjoy Working at Envestnet
Help shape the future of WealthTech. At Envestnet you’ll gain hands-on experience and collaborate with some of the industry’s brightest minds to deliver meaningful, innovative solutions that make a real difference.
We value flexibility in how and where work gets done, and we recognize strong performance with meaningful rewards—because your contributions should drive both business success and your own personal growth. If you’re looking for a place where your work has impact, your development is supported, and your contributions are truly valued, Envestnet is where you can build your future.
The opportunity is now!
Our Investment in You
At Envestnet, our total rewards philosophy is designed to attract, motivate, and grow exceptional talent. We offer competitive, market-aligned compensation complemented with performance-linked incentives and rewards programs that recognize and reward impact.
In addition, we provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well-being, including medical insurance for you and your family, annual health check-ups, free online doctor consultations and telemedicine services, subsidized health club memberships, and an employee assistance program. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us.
Our Commitment to Inclusion & Belonging
Envestnet is an Equal Employment Opportunity employer and does not discriminate in employment on the basis of religion, race, color, caste, sex, gender, gender identity or expression, pregnancy, age, disability, medical condition, nationality, ethnic origin, marital status, or any other status protected under applicable Indian law. This commitment is in accordance with the Constitution of India and applicable labor and employment laws. All employment decisions are made solely based on merit, qualifications, performance, and business needs.
We strive to provide an inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation, please contact us at [email protected]. Please include your full name, the title of the role you are applying for, and the accommodation necessary to assist you with the recruiting process.
Recruitment Fraud
At Envestnet, safeguarding the trust and safety of job seekers is a top priority. We are aware that scammers may impersonate Envestnet recruiters or create fake job opportunities to deceive candidates. Review the information on our recruitment fraud awareness page to help you recognize and avoid recruitment fraud.