Senior Software Engineer (Security Domain)
NetApp, Inc. · Bangalore, Karnataka, IN · India · On-site
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Job Summary
Join the Security Engineering team as Senior Software Engineer and help secure NetApp's flagship storage operating system, ONTAP. As a Cybersecurity Development Engineer, you will design, develop, and enhance security capabilities that protect critical customer data across enterprise, cloud, and AI environments.
You will work on technologies spanning authentication, authorization, encryption, key management, secure communications, vulnerability mitigation, and security hardening. You will collaborate closely with kernel, networking, cloud, storage, and product security teams to build secure-by-design solutions while helping ONTAP meet evolving regulatory and customer security requirements.
This role combines deep systems software engineering with modern cybersecurity practices, including vulnerability discovery, threat modeling, secure development, incident response support, and AI-assisted security analysis.
Job Requirements
Design and develop security features including:
Authentication and authorization
RBAC and privilege management
TLS/mTLS and secure communications
IPsec and secure networking
PKI and certificate management
Encryption and key management
Data-at-rest and data-in-transit protection
Cryptographic services
Conduct security architecture reviews, threat modeling, risk assessments, and attack-tree analysis for administrative operations, credential paths, and role boundaries.
Translate security findings and threat models into product requirements, actionable test plans, and automated security tests.
Investigate vulnerabilities affecting ONTAP and third-party components; assess exploitability and customer impact; and drive remediation, validation, release readiness, and regression test coverage.
Develop AI-assisted security automation for vulnerability discovery, triage, detection, validation, remediation, suspicious-behavior investigation, and security response.
Partner with Product Security and PSIRT teams to improve security assessment workflows and respond to customer-reported vulnerabilities, security disclosures, emerging threats, and technical escalations.
Support compliance and certification programs including FIPS 140-3, Common Criteria, NIST security standards, and the EU Cyber Resilience Act (CRA).
Translate regulatory and security requirements into product capabilities, engineering controls, security evidence, and release criteria.
Participate in customer security reviews and incident response activities.
Mentor junior engineers and contribute to technical excellence across the organization.
Required Qualifications
Strong programming skills in C, C++, and Python.
Solid knowledge of:
Operating systems
Computer architecture
Data structures and algorithms
Networking fundamentals
Concurrency and multithreaded programming
Experience with security assessment methodologies and tools, including static and dynamic analysis, fuzzing, dependency…