Chief Product Security Specialist

3 weeks ago


Bengaluru, Karnataka, India Infosys Finacle Full time

About Infosys Finacle

We are a global leader in next-generation digital services and consulting, with a product subsidiary dedicated to developing and delivering innovative software products that empower businesses to thrive.

Location Bangalore, India

Job Objective

We seek an experienced Product Security Engineer specializing in the financial domain to ensure the security of our cloud-native products. The successful candidate will oversee vulnerability assessments, penetration testing, and contribute to a secure development lifecycle (SDL) to safeguard our financial products from emerging threats.

Key Responsibilities


• Conduct comprehensive vulnerability assessments and penetration testing on critical financial web applications.

• Leverage SAST and DAST tools to identify and analyze security vulnerabilities, recommending effective remediation strategies.

• Perform security assessments of web services and APIs, focusing on identity and token authentication and authorization mechanisms.

• Design and implement secure software systems, ensuring that security is an integral part of the software design process.

• Collaborate with the development team to apply secure design principles and patterns.

• Identify potential security vulnerabilities during the design phase and propose secure solutions.

• Analyze and assess cryptography implementations, key management practices, and rotation procedures.

• Deep dive into existing codebases to thoroughly assess security posture and identify potential vulnerabilities.

• Collaborate with development teams to implement secure architecture and design principles throughout the SDL.

• Maintain up-to-date knowledge of emerging threats like DDoS, ransomware, supply chain attacks, and implement countermeasures to mitigate risks.

• Stay abreast of industry best practices, including OWASP Top 10, SANS Top 25, BDH, and Palo Alto advisories.

• Ensure adherence to proper security postures and standard processes for both public and private cloud deployments.

Compensation Package

We offer a highly competitive salary in the range of $120,000 - $160,000 per annum, commensurate with experience and qualifications. This includes benefits such as health insurance, retirement savings, and paid time off.

Qualification

• 10 -15 years of experience in production/cloud security, with a focus on the financial domain and product security.

• Thorough understanding of HTTPS, TLS 1.2, TLS 1.3, and public/symmetric key cryptography.

• Proven experience in software design, with a focus on integrating security into the design process.

• Experience with one or more of the following:

• Front-end technologies such as Angular, React, or JavaScript.

• Back-end technologies such as Java, Node.js, TypeScript, Spring, or C.

• Strong understanding of secure design principles and patterns.

• Experience identifying and addressing security vulnerabilities during the design phase.

• Familiarity with security tools and screening/reporting experience is a plus, but the primary focus should be on software design experience.

• Proficiency in security tools like Burp Suite, Nmap, ZAP, Black duck Hub, NVD/CVE/CWEs, and experience managing FOSS CVE tracking.

• Experience in implementing secure coding practices aligned with OWASP Top 10, SANS Top 25, BDH, and Palo Alto advisories.

• Solid understanding of secure deployments on public and private cloud platforms like AWS, Azure, GCP, OpenShift, and VMWare.



  • Bengaluru, Karnataka, India Pocket FM Full time

    Pocket FM is seeking a highly skilled Chief Product Security Architect to lead our product security efforts. As a key member of our team, you will play a pivotal role in championing security throughout the entire product development lifecycle.About the RoleYou will collaborate with engineering, product management, and other stakeholders to identify and...


  • Bengaluru, Karnataka, India Hireologist Full time

    Job Summary:Hireologist is seeking an exceptional Chief Security Engineering Specialist to join our team. This role requires a strong background in DevSecOps, with expertise in security management, infrastructure automation, and development collaboration.About the Role:We are looking for an experienced professional who can ensure data security, identify...


  • Bengaluru, Karnataka, India IntraEdge Full time

    We are seeking a highly skilled Chief Information Security Specialist to join IntraEdge.Estimated salary: 2500000 - 3500000 per annum, depending on location and experience.About the RoleThis is an immediate opportunity, serving as a temporary replacement until the end of the month.Key ResponsibilitiesDemonstrate at least 6-9 years of experience in...


  • Bengaluru, Karnataka, India NETSACH GLOBAL Full time

    Netsach Global is seeking an experienced Chief Cloud Security Specialist to join our team. This is a contract opportunity for 6+ months in Bangalore.We are looking for a highly skilled individual with strong working experience and a deep understanding of cloud security and AWS. The successful candidate will be responsible for setting up the initial security...


  • Bengaluru, Karnataka, India RSA Security Full time

    Company OverviewRSA Security is a leading provider of cybersecurity solutions. Our mission is to help organizations protect themselves against the most sophisticated cyber threats.Estimated Salary: $180,000 - $250,000 per yearJob DescriptionWe are seeking a highly experienced Chief Technology Strategist to lead our hybrid cloud and on-premise product...


  • Bengaluru, Karnataka, India SAP Full time

    About SAPSAP is a leading provider of enterprise software solutions, enabling businesses to run better and make a greater impact on the world.With over 400,000 customers worldwide, we offer a comprehensive portfolio of products and services that help organizations manage their operations, innovate, and grow.Job DescriptionWe are seeking an experienced Chief...


  • Bengaluru, Karnataka, India First Abu Dhabi Bank Full time

    About the RoleWe are seeking a highly skilled and experienced Chief Technology Risk Management Specialist to join our team at First Abu Dhabi Bank.As a key member of our organization, you will be responsible for managing and mitigating technology risks across our operations. Your expertise in IT Security, Risk, and Governance practices will be crucial in...


  • Bengaluru, Karnataka, India Andromeda Security Full time

    Andromeda Security is a pioneering cloud security firm, backed by leading Silicon Valley venture capitalists. Our mission is to empower businesses by effectively managing cloud credentials and preventing security breaches. We pride ourselves on fostering a culture of trust, excellence, humility, grit, and fun. We are seeking dedicated professionals who will...


  • Bengaluru, Karnataka, India Ericsson Full time

    Job OverviewAs a Chief Security Architect at Ericsson, you will play a crucial role in designing and implementing robust security measures to protect our customers' networks and systems. This is an exciting opportunity to leverage your expertise in cybersecurity to drive business growth and innovation.


  • Bengaluru, Karnataka, India Fime Full time

    Company Overview:Fime is a leading provider of consulting and testing services in payments, smart mobility, biometrics, authentication, and open banking. With over 800 experts across 24 locations globally, Fime fosters a diverse and dynamic work environment.Job Description:We are seeking a Chief Security Auditor to join our team. As a security assessor, you...


  • Bengaluru, Karnataka, India State Street Full time

    Job OverviewThe Chief Information Security Compliance Specialist will play a crucial role in supporting the overall corporate information security compliance to State Street internal policies, external regulatory and client requirements.Key ResponsibilitiesMaintain enterprise information security policies, technical standards, guidelines, and procedures...


  • Bengaluru, Karnataka, India Flipkart Full time

    About the role: The Chief Security Architect at Flipkart plays a crucial part in safeguarding digital assets and sensitive information. This position involves developing and implementing comprehensive security strategies, leading incident response efforts, and conducting security assessments to identify vulnerabilities. This individual must promote security...


  • Bengaluru, Karnataka, India MNR Solutions Full time

    Job Title: Chief Information Security OfficerMNR Solutions is seeking a highly skilled Chief Information Security Officer to safeguard our organization's information assets and ensure compliance with security policies and regulations.About the Role:As a key member of our team, you will be responsible for implementing and enforcing robust security measures to...


  • Bengaluru, Karnataka, India HCLTech Full time

    About the RoleHCLTech is seeking a highly skilled Chief Verification Specialist to join our team and play a vital role in ensuring the quality and functionality of our advanced ASICs and SoCs.


  • Bengaluru, Karnataka, India Infosys Full time

    Infosys is seeking a highly skilled Chief Security Governance Officer to join our team.About the RoleThis is a senior leadership position responsible for ensuring the effective governance of security across all aspects of the organization. The successful candidate will have extensive experience in SAP Security and GRC, with a proven track record of...


  • Bengaluru, Karnataka, India Promaynov Advisory Services Pvt. Ltd Full time

    Job Title:Chief Cyber Security Consultant Company Overview:Promaynov Advisory Services Pvt. Ltd is a leading advisory services firm that helps organizations navigate the complex world of cyber security. Estimated Salary:₹ 1,200,000 - ₹ 1,500,000 per annum Job Description:We are seeking a highly skilled Chief Cyber Security Consultant to join our team...


  • Bengaluru, Karnataka, India Ambient Security Full time

    Ambient Security is an innovative cybersecurity startup on a mission to revolutionize enterprise security by reducing the risk of privileged account takeovers and cyber attacks.We're seeking highly skilled software engineers at all levels to lead the design and implementation of cutting-edge technologies in security, large-scale distributed systems, AI, and...


  • Bengaluru, Karnataka, India Ubique Systems Full time

    Job OverviewUbique Systems seeks an experienced Chief Data Security Architect to lead our portfolio of client engagements focused on data security.


  • Bengaluru, Karnataka, India Mphasis Full time

    Job SummaryMphasis is seeking an experienced Chief Cyber Security Strategist to lead our Cyber Security/Technology Risk Governance function. This role involves developing and implementing cyber security strategies, governing cloud security programs, conducting technology risk assessments, and providing support for ongoing technology risk management programs.


  • Bengaluru, Karnataka, India Anthology Inc Full time

    Overview of the RoleWe are seeking a highly skilled Chief Enterprise Security Architect to join our team at Anthology Inc. As a key member of our Information Security team, you will play a critical role in enhancing and ensuring the confidentiality, integrity, and availability of all corporate information systems and products.The successful candidate will...