Application Security Engineer at Autodesk in Bengaluru
- Company: Autodesk
- Location: Bengaluru, IND
- Job type: full time
- Workplace: onsite
- Posted: 2026-10-01
Job description
Job Requisition ID # 26WD100819 Position Overview Our team of security experts helps Autodesk design, build, deploy, and maintain secure products. We embed security throughout the product development lifecycle, from inception, design, development, and testing to cloud operations and our response to existing and emerging threats. Our goal is to stay ahead of evolving security threats by combining deep expertise, technology, and automation to protect Autodesk products and the environments in which they operate. We maintain a strong focus on protecting customer data and investments by strengthening our applications, underlying services, and networks. As part of this team, you will help Autodesk build and deliver Artificial Intelligence (AI)-powered products securely. You will partner with Product and Platform teams to threat model new features and systems, with a particular focus on applications that use Large Language Models (LLMs), AI agents, and AI-assisted workflows. You will also develop code and automation to scale security practices, using modern AI-assisted development tools as part of your daily workflow. This is an opportunity to develop your product security expertise at the forefront of AI while helping Autodesk stay ahead of emerging security threats. Responsibilities Conduct and facilitate threat modeling sessions with Engineering teams to identify assets, trust boundaries, attack paths, security risks, and appropriate mitigations for new and evolving product capabilities Threat model AI and Large Language Model (LLM)-powered systems, including agentic workflows, Retrieval-Augmented Generation (RAG) pipelines, tool and plugin integrations, and Model Context Protocol (MCP) servers Evaluate AI systems for security risks such as prompt injection, data leakage, excessive agency, insecure output handling, and inappropriate data access Develop and maintain Autodesk's AI security guidance, reference architectures, and secure design patterns using established frameworks such as the Open Worldwide Application Security Project (OWASP) Top 10 for Large Language Model Applications and MITRE Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS) Perform security reviews and hands-on testing of AI capabilities, including adversarial prompt testing and validation of security guardrails, permissions, and data access controls Develop automation and tooling that scale threat modeling and AI security reviews, including templates, intake workflows, analysis scripts, and LLM-assisted tools Use AI-assisted development tools such as Cursor, GitHub Copilot, and Claude Code to accelerate security tooling development while helping teams adopt these technologies securely Track findings from threat models and security reviews through remediation, partnering with Product and Engineering teams to implement practical, risk-based solutions Contribute to technical documentation, training, and security best practices that help developers design and build secure AI-enabled products Collaborate with developers, security professionals, and cross-functional stakeholders to continuously improve Autodesk's product security practices Minimum Qualifications Foundational understanding of application security principles and secure software design Familiarity with threat modeling concepts and methodologies such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE), data flow diagrams, and attack trees Working knowledge of how Large Language Model (LLM)-based applications are designed and developed, including an understanding of their unique security risks Ability to develop automation and security tooling using Python, Go, or an equivalent programming language Hands-on experience using AI-assisted Integrated Development Environments (IDEs) or coding agents as part of a software development workflow Familiarity with modern software development practices, including Git-based version
Application Security Engineer on JobPost.