hirly

Apply with hirly

Product Security Engineer

Zenskar · Bengaluru, India

Upload your resume to see how well you match this job — free, in seconds, no account needed.

Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.

About Zenskar Zenskar is an AI-native revenue automation platform built to handle real-world complexity. It sits between your CRM and ERP automating everything in between: billing, revenue recognition, collections, usage metering, and analytics. Across any pricing model, any entity structure, any currency. Our vision: Zero-Touch Finance. Agents execute. Humans supervise. Finance teams set the rules. Zenskar runs them. Founded by Apurv Bansal and Saurabh Agarwal , second-time founders whose previous startups were acquired by Snapdeal and Gaana. The team brings experience from Google, Deutsche Bank, Elevation Capital, IIT Bombay, IIT Delhi, and Harvard Business School. We have 5x'd revenue in the past year. We are default alive . Funding We raised $15M in Series A funding in April 2026, led by Susquehanna Venture Capital, Bessemer Venture Partners, Shine Capital, and Rho, with participation from Rocketship, J-Ventures, Future Back Ventures by Bain & Company, and Converge. The funding is being used to expand our Agents Marketplace and scale operations, not headcount. 📰 Read the announcement → See how Zenskar automates the full order-to-cash cycle, from contract to cash, without spreadsheets, workarounds, or engineering tickets.* The Problem We're Solving Finance teams aren't struggling because they lack AI tools. They're struggling because the systems underneath those tools were built for a simpler world. These systems label real-world complexity as edge cases and force teams into costly, error-prone workarounds: revenue leakage, delayed collections, audit risk, and finance teams buried in grunt work. Bolting AI onto these broken foundations is as good as a Ferrari engine on a horse-drawn carriage. Zenskar is purpose-built from the ground up: the architecture handles complexity natively, so AI actually works. It combines foundational flexibility + deterministic calculation + purpose-built AI agents to deliver end-to-end automation across the order-to-cash cycle

  • without workarounds, without engineering tickets. The B2B billing and revenue automation market is $2B today, projected to reach $10B by 2030 . What Customers Say "We're saving 200+ hours/quarter on invoicing and receivables by completely automating our recurring billing."
  • Noy Kalansky, Finance Controller, Pontera "Zenskar automates revenue recognition accurately for our value-based billing: agents reducing manual hours by 70%."
  • Matt Barnard, VP Finance, Vertice "Zenskar’s agents automated 90% of our billing, integrated with our CRM, and accelerated revenue collection by a month."
  • Ming Lui, VP Finance, Yembo "Sardine had spent 4 years running billing in-house for high-volume, usage-based pricing. Zenskar took care of it all."
  • Sardine team "We launched our product 4 months faster instead of building an in-house system for our usage-based pricing."
  • Kshitij Gupta, CEO, 100ms About the role Security looks like a checklist until it's a customer's revenue data on the line. We're a multi-tenant system holding our customers' contracts, invoices and usage data, along with their credentials to Stripe, QuickBooks and other systems. Every enterprise buyer asks the same question: can we trust you with this? We're past product-market fit. Customers are live, running real money and real contracts through the system, and enterprise security reviews and audits now shape what we can sell. Early architectural decisions compound, and a security miss here is a financial miss for someone else. The Product Security Engineer owns whether the product can be trusted with other people's money and data, and whether we can prove it. You're accountable for three questions: is this system safe to hand a customer's revenue data to, would we know if it wasn't, and can we evidence that to an auditor or an enterprise buyer without inventing anything. This role fails when one tenant's data appears in another tenant's export and nobody notices for a quarter, or when an auditor asks for evidence of a control we told them we had, and there isn't any. This is a hands-on individual contributor role with no direct reports. You'll read and write code, review PRs, and write tooling and detections. You'll also run our security and compliance program day to day: SOC 2 Type 2 and ISO 27001 surveillance, GDPR and DPA work, the DPDPA and CERT-In build-out,

Pci Saq

A, and customer security reviews. The IT Manager and the CISO stay accountable and review your work. You'll review infrastructure owned by people you work with closely, and you'll find things wrong with it. What you'll do

  • Threat model the paths that matter before code exists: webhook receivers, integrations, and AI agent access to customer data. Turn a feature into trust boundaries, actors, abuse cases and an authorisation model, and name what must never cross a tenant line
  • Find real, exploitable bugs in real code (broken authorisation, IDOR, injection, SSRF, replay, races on money paths), write the request that proves it, and separate it from scanner noise
  • Treat tenant isolation as a system property, not a filter someone remembered to add. Know where it silently degrades (caches, exports, analytics paths, background jobs) and build a way to prove it still holds
  • Own the lifecycle of third-party credentials we store on customers' behalf: encryption, rotation, blast-radius limits, and detection when a credential is misused
  • Tighten AWS IAM, network boundaries, secrets and CI/CD, and add guardrails such as policy checks in CI so a class of issue can't ship again. We do not want good intentions; we want reliable mechanisms
  • Own identity and access end to end: session lifecycle, token issue and revoke, SSO and SCIM, service-to-service auth, API keys and their rotation, and the authorisation model behind them
  • Lead security incidents. Build the logging and detections that let us find out sooner, and run a postmortem that actually changes something
  • Decide what not to fix this quarter, and record the decision with an owner, a rationale and a date instead of leaving it in a backlog nobody reads
  • Change how engineers work without any authority to make them: secure defaults, design reviews that engineers seek out rather than route around
  • Carry SOC 2 Type 2 and ISO 27001 through real audit cycles: control design, evidence, auditor Q&A, and remediation of findings. Build controls that produce evidence, not quarterly screenshots
  • Handle customer security reviews, DPAs and subprocessor lists with Sales, Customer Success, Legal and Finance, whose incentives genuinely differ from security's, without putting anything untrue on a questionnaire
  • Stay current through real people and sources, and tie a recent shift in the threat landscape to a decision you actually changed Who you are
  • 3 to 7 years of experience in product or application security, with real, first-person evidence for everything below
  • Turn a feature into trust boundaries, actors, abuse cases and an authorisation model, and review designs before code exists
  • Have found real exploitable bugs and can write the request that proves it, and can tell a scanner finding from something an attacker can actually use
  • Reason about tenant boundaries as a first-class property, and know where isolation silently degrades. Comfortable with data classification, encryption, key management, retention and deletion
  • Have personally implemented and lived with least privilege in AWS, across IAM, network boundaries, secrets, and CI/CD and supply chain integrity
  • Can reason about an authorisation model, not just an authentication one: token lifecycle, SSO and SCIM, service-to-service auth, API key rotation
  • Have led a real security incident, know what would have had to be logged to find out sooner, and ran a postmortem that changed something
  • Have decided what not to fix and recorded it with an owner, a rationale and a date, and have formall
Apply: Product Security Engineer at Zenskar