Full-Time

Senior product security engineer

Posted on 11/23/2025

TIBCO Software

TIBCO Software

1,001-5,000 employees

Real-time data integration & analytics platform

No salary listed

Bengaluru, Karnataka, India

In Person

Category
IT & Security (1)
Required Skills
.NET
C#
Cryptography
C/C++
Requirements
  • Have at least 6 years of experience in Security Engineering
  • You have a Full-time degree in Engineering (Preferably Computer Science related)
  • Must have good verbal and written communication skills; ability to communicate optimally and clearly with different stakeholders in engineering teams
  • You are an expert in at least three of these areas in security –Web, Network, Cloud, Cryptography
  • You are capable of writing exploits for vulnerabilities identified in those respective areas
  • Deep understanding of application architecture and design principles
  • Experience in design review and threat modelling activities
  • Enthusiasm for staying up to date with the latest updates about security threats and solutions
  • You have solid understanding of most common software vulnerabilities and standard secure coding practices
  • Have excellent capabilities to identify security vulnerabilities and root cause analysis
  • Have proficiency in programming language(s) like C++, C#, .NET
  • Have experience in analysing security mechanisms of browser and associated extensions
  • Have working knowledge wrt different cryptographic schemes including but not limited to key generation , rotation , revocation,etc
  • You also have proficiency in windows system Internals
  • You have demonstrated understanding of Computer Science fundamentals (OS, Networks).
  • Good to have certifications such as OSCP, OSCE, GPEN, CRTP etc
  • Working knowledge of AI based tools for conducting security reviews
Responsibilities
  • You will be responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness
  • You will lead a team of security engineers for diverse types of product security related projects and workstreams
  • You will drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development models
  • You will create and deliver advanced security training and guidance to product engineers
  • You will guide product development teams on design changes as per security requirements
  • You will perform manual code review activities
  • You will communicate technical issues within scope of assignment
  • You will drive negotiation in the interest of security.
  • You will conduct comprehensive reviews of specific security fixes, as necessary.
  • You will conduct product penetration test in a non-disruptive way for IT/Cloud deployments, including exploit creation to demonstrate a proof of concept.
  • You will validate the efficacy of defensive mechanisms, as well as the engineering adherence to security policies

TIBCO Software provides a platform for real-time data integration and analytics that helps businesses connect, unify, and analyze data to improve decision-making and operational efficiency. Its tools are used by healthcare providers, financial institutions, and large enterprises. The company earns money from software licensing, subscriptions, and professional services, and its platform can be deployed on-premises, in the cloud, or in hybrid environments. It emphasizes high performance, reliability, and scalability for mission-critical applications. Unlike many competitors, TIBCO combines comprehensive data integration with analytics across flexible deployment models, serving large organizations that need real-time data flows. The goal is to help organizations manage their data more effectively to support faster, better decisions and smoother operations.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$4.3B

Headquarters

Palo Alto, California

Founded

1997

Simplify Jobs

Simplify's Take

What believers are saying

  • TIBCO Cloud Integration launches in AWS Marketplace, expanding enterprise reach.
  • Flogo MCP reduces MTTR by 35% for P1 incidents via AI root-cause analysis.
  • Model Context Protocol enhances SRE workflows with structured data logging.

What critics are saying

  • Cloud Software Group lays off 1,000 TIBCO employees in September merger.
  • CSG CEO Tom Krause cuts mid-tier clients, losing to MuleSoft competitors.
  • Databricks Lakehouse captures Spotfire's real-time analytics market share.

What makes TIBCO Software unique

  • TIBCO Flogo 2.26.0 introduces MCP Connector for AI-driven incident response.
  • Smart Incident Response Assistant automates triage with PagerDuty integration.
  • Hyperconverged Analytics in Spotfire enables action triggering from insights.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
TIBCO
Apr 2nd, 2026
How to automate Smart Incident Response with TIBCO Flogo(R) and Model Context Protocol(MCP).

How to automate Smart Incident Response with TIBCO Flogo(R) and Model Context Protocol(MCP). April 2, 2026 TIBCO Flogo(R) automates incident response by combining Model Context Protocol (MCP) tools for interactive data collection, real-time logging, and AI-driven root-cause analysis. Using the Smart Incident Response Assistant, Site Reliability Engineers can collect structured incident data, generate an LLM-powered remediation report, and establish a transparent audit trail within a single TIBCO Flogo workflow. TIBCO Flogo's new Smart Incident Response Assistant showcases how the Model Context Protocol (MCP) integrates with advanced AI agents. This workflow eliminates manual triage overhead by acting as an intelligent bridge between production systems and your Site Reliability Engineering (SRE) team. For a foundational look at these capabilities, see its full guide on TIBCO Flogo(R) Model Context Protocol(MCP) Showcase Sample - Smart Incident Response Assistant. How does the TIBCO Flogo Incident Response architecture work? * Initial Trigger: An engineer prompts the AI with a symptom like "Payment system down". * MCP Elicitation: The ElicitIncidentDetails activity renders a native form to collect structured data. * Real-time Visibility: The LogIntakeComplete activity emits structured log messages back to the client. * AI Analysis: The SampleRootCause activity uses the LLM Sampling Gateway to diagnose the issue. * External Orchestration: The workflow triggers automatic ticket creation in PagerDuty or ServiceNow. Automating Incident Response triage with the TIBCO Flogo MCP Connector. The assistant implements three key capabilities within a single workflow to ensure high "Information Gain" and machine readability: * MCP Elicitation: Interactive intake forms via the ElicitIncidentDetails activity collect affected system and severity data. * MCP Logging: Structured log messages from LogIntakeComplete and LogAnalysisComplete provide an instant audit trail directly to the engineer's client. * MCP Sampling: Complex diagnostics are delegated to an LLM via the SampleRootCause activity to rank likely root causes. Why is ai-driven root-cause analysis critical for SRE teams? Manual diagnosis remains the primary bottleneck in production incidents. AI-powered sampling removes this guesswork by automating initial log forensics, a practice supported by DORA (DevOps Research and Assessment) standards for high-performing teams. Internal benchmarks show this assistant reduced Mean Time to Resolution (MTTR) by 35% for P1 incidents. "In the fast-paced realm of automated system discovery, if the machine can't parse it in 200 milliseconds, the human will never see it." Frequently asked questions. How does TIBCO Flogo automatically create tickets? The workflow includes an automated exit strategy where the final triage report triggers a "Build & Return" activity to interface with PagerDuty or ServiceNow. What is the role of LLM Sampling? LLM Sampling through the SampleRootCause activity delegates diagnostics to an LLM mid-flow to rank root causes and suggest remediation. What are the prerequisites for the Flogo MCP Connector? Flogo MCP connector is available in Flogo 2.26.0 release onwards. You can download it from here. Key takeaways. * Automated Intake: TIBCO Flogo uses MCP Elicitation for structured reports. * Instant Diagnostics: AI-powered MCP Sampling diagnoses root causes instantly. * Zero-Lag Compliance: MCP Logging provides a transparent audit trail. Qinghai Kong is a Lead QA Engineer for TIBCO Flogo at Cloud Software Group, within the TIBCO Business Unit. He leads quality engineering efforts across the Flogo team, with deep expertise in the Flogo MCP Connector and emerging AI capabilities. He is passionate about building high-quality, scalable integration solutions and collaborates closely with cross-functional teams to drive innovation.

Secondaries Investor
May 28th, 2024
Vista eyes large-scale continuation fund for Cloud Software

The transaction is in the early stages and could reach $2bn in size, sources have told Secondaries Investor.

EIN News
Feb 6th, 2024
The Top Master Data Management Software Vendors According to the FeaturedCustomers Winter 2024 Customer Success Report

Market Leaders - Boomi, Pimcore, Reltio, and Stibo Systems were given the highest "Market Leader" award.

Purchasing Network
May 31st, 2023
Thread Launches In AWS Marketplace To Expand Solutions And Simplify Customer Procurement Process

TIBCO Software Inc., a global leader in integration, API management, and analytics, announced availability of TIBCO Cloud™ Integration on Amazon Web Services Marketplace.

TechTarget
Mar 14th, 2023
Tibco Spotfire targets efficiency of triggering actions | TechTarget

Tibco first introduced Hyperconverged Analytics in September 2020.

INACTIVE