Hyderabad, Telangana, India · Engineering · Posted 2 hours ago
Already have an account? Login to Apply
Application Security Engineer
About the Job
Company: Trida Labs
Location: Hyderabad, Telangana, India
Work Model: On-site
Employment Type: Full-time
Experience: 3–5 Years
About Trida Labs
Trida Labs builds products for enterprise data, analytics, and intelligent applications.
Our products include:
TridaPad — A platform for querying, analyzing, and visualizing enterprise data.
AgentSQL — A natural-language interface for working with enterprise data and generating SQL.
TridaPad MCP Server — Connects AI assistants and MCP-compatible clients with TridaPad capabilities.
About the Role
We're looking for an Application Security Engineer to improve the security of Trida Labs applications, APIs, data workflows, and AI-powered features.
You'll work across authentication, authorization, API keys, data-source credentials, AI-agent access, security testing, and application security controls.
What You'll Do
Application & API Security
Review TridaPad's authentication flows: SAML, LDAP, Google OAuth, and JWT.
Review authorization and access-control boundaries across users, groups, organizations, queries, dashboards, and APIs.
Review per-user API keys, per-query sharing keys, and keys used for shared dashboards.
Test web applications and REST APIs for OWASP Top 10 vulnerabilities, access-control issues, injection risks, and insecure data exposure.
Review security headers (Flask-Talisman), rate limiting (Flask-Limiter), and CSRF protection (Flask-WTF).
Perform vulnerability assessments using Burp Suite, OWASP ZAP, or similar tools.
Define secure implementation patterns and security requirements for new features.
AI & Agent Security
Review how AgentSQL and the MCP Server act on a user's behalf, and keep their access within that user's permissions.
Review generated SQL execution, tool calls, and agent workflows for unauthorized data access and unsafe operations.
Test prompt injection, indirect prompt injection, sensitive-data leakage, and unauthorized tool usage.
Define security controls for AI-generated queries, tool calls, and access to enterprise data.
Data & Connector Security
Review how TridaPad stores and uses data-source credentials.
Review the security of data-source connectors, especially those that run code or fetch URLs.
Work with Database and Backend engineers on secure PostgreSQL access and data isolation.
Cloud, Containers & Secrets
Review security configurations across Render, Docker Hub, and Netlify deployments.
Assess Docker images and application dependencies for known security vulnerabilities.
Improve handling of environment variables, API keys, credentials, and other secrets.
Production Security
Investigate security-related production issues, identify root causes, and recommend remediation.
Work with engineers to resolve vulnerabilities, verify fixes, and track security findings through remediation.
Ownership
You will own application security activities from security review and testing through remediation and production verification. You'll work closely with Backend, Frontend, AI, Database, QA, and DevOps engineers to improve the security of Trida Labs products.
What You'll Bring
3–5 years of experience in application security, product security, cybersecurity, or a related engineering role.
Strong understanding of web application security, authentication, authorization, SSO, and access control.
Strong understanding of OWASP Top 10 and common application vulnerabilities.
Experience with security testing and vulnerability assessment.
Working knowledge of Python and application frameworks such as Flask.
Strong understanding of SQL and database security concepts.
Experience reviewing application code for security issues.
Understanding of Docker, cloud environments, secrets, and secure configuration.
Ability to work directly with developers to identify and fix security issues.
Preferred Qualifications
Experience with SAML, LDAP, OAuth 2.0, JWT, and API-key-based authentication.
Experience with Burp Suite, OWASP ZAP, or similar security-testing tools.
Experience with dependency and container vulnerability scanning.
Experience with AI/LLM application security, prompt injection, or agent security.
Familiarity with MCP security and tool-access controls.
OSCP or other relevant security certifications are a plus.
Why Join Trida Labs?
A typical workflow starts with a user asking a question in natural language. AgentSQL generates SQL, TridaPad executes it against the customer's data source, and the results are returned for analysis and visualization.
As an Application Security Engineer, you'll secure each step, from data-source credentials to the AI agent acting on a user's behalf.
Equal Opportunity
Trida Labs is an equal opportunity employer. We value diversity and are committed to creating an inclusive workplace where everyone can contribute and grow.
You do not need to match every requirement listed above to apply. If you have strong experience in some areas and are motivated to learn the rest, we'd still like to hear from you.
About Trida Labs
Trida Software Labs Private Limited is an enterprise technology and software development company focused on modern data analytics and agentic AI tools.
Already have an account? Login to Apply