Skip to main content
Posted 07 August, 2026

Security Engineer III, Product Security-Senior Vulnerability Remediation Engineer

Anaplan
Gurugram Full Time
Reference: 102_698304_8650328002

Senior Vulnerability Remediation Engineer

P R O D U C T S E C U R I T Y A N A P L A N

Reports to: Senior Manager, Platform Security
Working model: Hybrid

Location: Gurugram

Experience range-5-7 years relevant

Why this role matters

Identifying vulnerabilities is the initial step; however, the true value lies in the relentless and well-instrumented remediation efforts, as well as in preventing new issues from entering releases. This position is responsible for managing that operational engine: reducing the time to remediate, automating patch processes, and enhancing the release gates that prevent known vulnerabilities from reaching production. The work directly underpins the trust that enterprise customers place in the platform.

This is a hands-on role with ownership of outcomes. Success will be evaluated based on whether the metrics improve and whether engineers successfully implement fixes, rather than merely logging findings. You will collaborate closely with engineering teams on the actual remediation process, not just the tracking of vulnerabilities.

Why Anaplan

Anaplan is not merely a straightforward SaaS application. The platform facilitates highly dimensional, enterprise-scale modeling with responsive recalculation and rigorous correctness expectations. The technical landscape encompasses the legacy Hyperblock engine, the newer Polaris engine, and an expanding array of AI-powered products, including CoModeler for AI-assisted model building and CoPlanner for conversational, analyst-style planning support.

AI is broadening both the capabilities and the attack surface of the platform: generating more code, creating more autonomous decision paths, and increasing supply-chain risk to manage. This is why this role is of significant importance. Product Security is closely integrated with engineering and platform decisions, and the team is sufficiently small that you will own a substantial domain rather than merely a segment of the process.

What you'll do

  • Drive remediation to closure: triage, prioritize, and pursue vulnerabilities across the platform until they are resolved, not just assigned.
  • Enhance patch-management SLAs: reduce time-to-remediate and ensure visibility and reportability.
  • Automate patching: eliminate manual steps in patch processes so that coverage can scale through tooling rather than relying solely on headcount.
  • Fortify release gates: prevent known vulnerabilities from entering releases by shifting detection and enforcement to earlier stages.
  • Minimize attack surface: promote the adoption of hardened container images, maintain strong secrets hygiene, and ensure a clean external surface.
  • Support supply-chain integrity: assist in enforcing dependency and package policies and maintain a controlled, trusted repository pathway.
  • Prioritize by risk: implement risk-based prioritization to ensure the team addresses the most critical issues, rather than merely those that score highest.
  • Collaborate with engineering on remediation: work alongside product teams on genuine remediation efforts, negotiating outcomes under delivery pressure.

What we're looking for

  • Hands-on experience in vulnerability management within a cloud or SaaS environment, demonstrating ownership of outcomes rather than merely findings.
  • Proficiency in the scanner ecosystem, including SAST, DAST, SCA, container, and IaC scanning, with the discernment to differentiate signal from noise.
  • The capability to automate processes through scripting and pipeline work, rather than solely operating tools manually.
  • Strong foundational knowledge of container and cloud security, particularly with Docker, Kubernetes, and at least one of AWS, GCP, or Azure.
  • Pragmatic prioritization skills and the credibility to negotiate fixes with engineers under high delivery pressure.
  • Clear communication skills that empower engineering teams to take action, rather than simply receiving a list of tasks.

Nice to have

  • Experience with policy-as-code and automated enforcement of remediation gates.
  • Exposure to supply-chain security, including provenance, signing, and software or model bills of materials.
  • Experience operating within a regulated enterprise environment, or holding a relevant security certification such as Security+.

Sign up for Job Alerts