Director of Application Security

4 weeks ago


Bangalore, India HCLSoftware Full time

HCLSW seeks a Director, Head of Product & Application Security. The successful candidate will lead the end to end Product Security portfolio within HCL Software. Maintains and strengthens the risk posture across the organization through discovery and remediation of product security vulnerabilities and supply chain security. Establishes and communicates strategic vision for the programs, and ensures they align with development goals and opportunities. Leads a dynamic group of Application Security professionals worldwide, with expectations to expand team over time. This individual is also expected to contribute to additional tasks in a cross-functional security team, especially assisting the Threat Management team; network and operating system vulnerability management; continuous monitoring and reporting; security incident handling, and participation in vendor and third-party application security reviews. Key Responsibilities: Develop and execute secure software development strategy in the form of Secure SDLC for the enterprise, including policies, standards and governance Advance and execute a software supply chain security development strategy to include Identify security risk and vulnerabilities across client's supply chain partners as well and track implementation of corrective action plans by supply chain partners Identify and manage risks involved with use the of AI within products and within the development of products Manage Product Risk management and risk profiling Lead the updating of the Secure Engineering Framework. Manage the Vulnerability and Penetration Testing Team Manage relationships with multiple 3rd party penetration testing vendors Oversee the security portion of release management Manage Product Security incident response program and team Make data-based decisions and considers measurable metrics as part of the initiative Consult with Development, Operations and Product groups on technical security issues. Closely partner with PISOs, Development Leads to integrate security tool automation such as SAST, DAST, Container Analysis and other security tools Directly engage development leaders to understand their challenges, roll-up sleeves when needed and understand/address their issues at a technical level Lead Comprehensive Penetration Testing Activities, to include both staff and vendor relationships Manage Delivery of Developer Security Training Key Skills: Proven ability to define strategic visons and lead team through execution. Strong understanding of AI, LLMs and other AI technology Strong planning, organizational, and leadership skills, including the ability to motivate teams, set strategic vision and approach, and resolve conflict. Proven ability to learn, evaluate, and adapt to new technologies and tools. SecDevOps, or DevSecOps, process framework experience. Ability to build a strong network, both inside and outside the organization. Excellent written and verbal communication skills, and ability to present ideas to all organizational levels. Ability to work in a dynamic environment, managing multiple initiatives and commitments simultaneously with tight deadlines and changing priorities. Flexibility to contribute as needed, even in areas not tightly mapped to stated responsibilities. Mandatory Qualifications Experienced people manager with 5-10+ years' combined experience in application development, application security, vulnerability management, and/or network security. Strong working knowledge of secure coding principles, practices, and frameworks such as OWASP Top Ten and SANS 20 Critical Security Controls. Hands-on experience with application security and vulnerability management tools. Working knowledge of comprehensive information security principles and practices. Bachelor of Science in Computer Science or related field required. Master of Science in Information Security or related field preferred. Desirable Certifications CISSP, CSSLP, CISM, CISA, CEH, GPEN, GWAPT, Hyperscaler certifications



  • bangalore, India Sphera Full time

    Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability. Our mission is to create a safer, more sustainable and productive world.Sphera is a portfolio company of Blackstone, a U.S.-based alternative asset investment company that focuses on...


  • Bangalore Division, India HCLSoftware Full time

    HCLSW seeks a Director, Head of Product & Application Security. The successful candidate will lead the end to end Product Security portfolio within HCL Software. Maintains and strengthens the risk posture across the organization through discovery and remediation of product security vulnerabilities and supply chain security. Establishes and communicates...


  • bangalore, India beBeeSecurity Full time

    Job Title: Application Security StrategistWe are seeking a seasoned Application Security Strategist to drive the application security function to the next level, ensuring the enhanced security of our products.Responsibilities: Perform design consultation, architecture review, threat modeling, code review, and testing. Assist in the development of test cases,...


  • Bangalore, India Jobted IN C2 Full time

    Role Description: As an Application Security Engineer at Booking.com, you will play a critical role in safeguarding one of the world's largest online travel platforms. This position sits at the intersection of security and software development, focusing on identifying, preventing, and mitigating security vulnerabilities throughout the application development...


  • bangalore, India beBeeSecurity Full time

    **Senior Application Security Test Engineer Role**We are seeking an experienced Application Security Specialist to join our team and drive the security of our applications. The ideal candidate will have a strong background in security testing, CI/CD pipeline integration, and vulnerability remediation.This role is responsible for ensuring seamless integration...


  • Bangalore, India Dezerv Full time

    Dezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...


  • bangalore, India ALLEN Digital Full time

    About ALLEN Digital:At ALLEN Digital, we spearhead a technology-driven approach to education, leveraging top-tier tech talent from leading technology firms. Through our strategic collaboration with Bodhi Tree Systems, a prominent venture capital firm known for building & scaling tech-first brands, we are revolutionizing education with a tech-first...


  • bangalore, India Operlity Full time

    We are hiring an experienced Application Security (AppSec) Engineer to strengthen secure software development across our products and platforms. You will collaborate with development teams, perform secure code reviews, lead threat modeling sessions, orchestrate security testing, and ensure our applications meet the highest security and compliance standards....


  • Bangalore, India Operlity Full time

    We are hiring an experienced Application Security (AppSec) Engineer to strengthen secure software development across our products and platforms. You will collaborate with development teams, perform secure code reviews, lead threat modeling sessions, orchestrate security testing, and ensure our applications meet the highest security and compliance standards....


  • bangalore, India IG Group Full time

    Job TitleApplication Security EngineerJob DescriptionSo, who are we? Hello, we're IG Group. We are a publicly-traded FTSE250 FinTech company who run mobile, web and desktop platforms that help our clients trade stocks & shares, leveraged products, Futures & Options and Crypto.We are ambitious. Over 340,000 people already use our platforms. We're global with...