Security Engineer III, Product Security-Senior Vulnerability Remediation Engineer
Anaplan · Gurugram
Anaplan · Gurugram
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market. What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture. Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform. Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small. Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together! Senior Vulnerability Remediation Engineer P R O D U C T S E C U R I T Y · A N A P L A N Reports to: Senior Manager, Platform Security Working model: Hybrid Location: Gurugram Experience range-5-7 years relevant Why this role matters Identifying vulnerabilities is the initial step; however, the true value lies in the relentless and well-instrumented remediation efforts, as well as in preventing new issues from entering releases. This position is responsible for managing that operational engine: reducing the time to remediate, automating patch processes, and enhancing the release gates that prevent known vulnerabilities from reaching production. The work directly underpins the trust that enterprise customers place in the platform. This is a hands-on role with ownership of outcomes. Success will be evaluated based on whether the metrics improve and whether engineers successfully implement fixes, rather than merely logging findings. You will collaborate closely with engineering teams on the actual remediation process, not just the tracking of vulnerabilities. Why Anaplan Anaplan is not merely a straightforward SaaS application. The platform facilitates highly dimensional, enterprise-scale modeling with responsive recalculation and rigorous correctness expectations. The technical landscape encompasses the legacy Hyperblock engine, the newer Polaris engine, and an expanding array of AI-powered products, including CoModeler for AI-assisted model building and CoPlanner for conversational, analyst-style planning support. AI is broadening both the capabilities and the attack surface of the platform: generating more code, creating more autonomous decision paths, and increasing supply-chain risk to manage. This is why this role is of significant importance. Product Security is closely integrated with engineering and platform decisions, and the team is sufficiently small that you will own a substantial domain rather than merely a segment of the process. What you'll do • Drive remediation to closure: triage, prioritize, and pursue vulnerabilities across the platform until they are resolved, not just assigned. • Enhance patch-management SLAs: reduce time-to-remediate and ensure visibility and reportability. • Automate patching: eliminate manual steps in patch processes so that coverage can scale through tooling rather than relying solely on headcount. • Fortify release gates: prevent known vulnerabilities from entering releases by shifting detection and enforcement to earlier stages. • Minimize attack surface: promote the adoption of hardened container images, maintain strong secrets hygiene, and ensure a clean external surface. • Support supply-chain integrity: assist in enforcing dependency and package policies and maintain a controlled, trusted repository pathway. • Prioritize by risk: implement risk-based prioritization to ensure the team addresses the most critical issues, rather than merely those that score highest. • Collaborate with engineering on remediation: work alongside product teams on genuine remediation efforts, negotiating outcomes under delivery pressure. What we're looking for • Hands-on experience in vulnerability management within a cloud or SaaS environment, demonstrating ownership of outcomes rather than merely findings. • Proficiency in the scanner ecosystem, including SAST, DAST, SCA, container, and IaC scanning, with the discernment to differentiate signal from noise. • The capability to automate processes through scripting and pipeline work, rather than solely operating tools manually. • Strong foundational knowledge of container and cloud security, particularly with Docker, Kubernetes, and at least one of AWS, GCP, or Azure. • Pragmatic prioritization skills and the credibility to negotiate fixes with engineers under high delivery pressure. • Clear communication skills that empower engineering teams to take action, rather than simply receiving a list of tasks. Nice to have • Experience with policy-as-code and automated enforcement of remediation gates. • Exposure to supply-chain security, including provenance, signing, and software or model bills of materials. • Experience operating within a regulated enterprise environment, or holding a relevant security certification such as Security+. Our Commitment to Diversity, Equity, Inclusion and Belonging (