Director - Product and Application Security
4 days ago
HCLSW seeks a Director, Head of Product & Application Security. The successful candidate will lead the end to end Product Security portfolio within HCL Software. Maintains and strengthens the risk posture across the organization through discovery and remediation of product security vulnerabilities and supply chain security. Establishes and communicates strategic vision for the programs, and ensures they align with development goals and opportunities. Leads a dynamic group of Application Security professionals worldwide, with expectations to expand team over time.
This individual is also expected to contribute to additional tasks in a cross-functional security team, especially assisting the Threat Management team; network and operating system vulnerability management; continuous monitoring and reporting; security incident handling, and participation in vendor and third-party application security reviews.
Key Responsibilities:
- Develop and execute secure software development strategy in the form of Secure SDLC for the enterprise, including policies, standards and governance
- Advance and execute a software supply chain security development strategy to include Identify security risk and vulnerabilities across client's supply chain partners as well and track implementation of corrective action plans by supply chain partners
- Identify and manage risks involved with use the of AI within products and within the development of products
- Manage Product Risk management and risk profiling
- Lead the updating of the Secure Engineering Framework.
- Manage the Vulnerability and Penetration Testing Team
- Manage relationships with multiple 3rd party penetration testing vendors
- Oversee the security portion of release management
- Manage Product Security incident response program and team
- Make data-based decisions and considers measurable metrics as part of the initiative
- Consult with Development, Operations and Product groups on technical security issues.
- Closely partner with PISOs, Development Leads to integrate security tool automation such as SAST, DAST, Container Analysis and other security tools
- Directly engage development leaders to understand their challenges, roll-up sleeves when needed and understand/address their issues at a technical level
- Lead Comprehensive Penetration Testing Activities, to include both staff and vendor relationships
- Manage Delivery of Developer Security Training
Key Skills:
- Proven ability to define strategic visons and lead team through execution.
- Strong understanding of AI, LLMs and other AI technology
- Strong planning, organizational, and leadership skills, including the ability to motivate teams, set strategic vision and approach, and resolve conflict.
- Proven ability to learn, evaluate, and adapt to new technologies and tools.
- SecDevOps, or DevSecOps, process framework experience.
- Ability to build a strong network, both inside and outside the organization.
- Excellent written and verbal communication skills, and ability to present ideas to all organizational levels.
- Ability to work in a dynamic environment, managing multiple initiatives and commitments simultaneously with tight deadlines and changing priorities.
- Flexibility to contribute as needed, even in areas not tightly mapped to stated responsibilities.
Mandatory Qualifications
- Experienced people manager with years combined experience in application development, application security, vulnerability management, and/or network security.
- Strong working knowledge of secure coding principles, practices, and frameworks such as OWASP Top Ten and SANS 20 Critical Security Controls.
- Hands-on experience with application security and vulnerability management tools.
- Working knowledge of comprehensive information security principles and practices.
- Bachelor of Science in Computer Science or related field required. Master of Science in Information Security or related field preferred.
Desirable Certifications
- CISSP, CSSLP, CISM, CISA, CEH, GPEN, GWAPT, Hyperscaler certifications
-
Security Engineer II
2 days ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Application Security
1 week ago
Bengaluru, Karnataka, India Dezerv Full time ₹ 10,00,000 - ₹ 25,00,000 per yearAbout Dezerv :Dezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global...
-
Director of Product Management
1 week ago
Bengaluru, Karnataka, India JFrog Full time ₹ 20,00,000 - ₹ 25,00,000 per yearAt JFrog, we're reinventing DevOps to help the world's greatest companies innovate -- and we want you along for the ride. This is a special place with a unique combination of brilliance, spirit and just all-around great people. Here, if you're willing to do more, your career can take off. And since software plays a central role in everyone's lives, you'll be...
-
Application Security
4 days ago
Bengaluru, Karnataka, India Pearson Full time ₹ 20,00,000 - ₹ 40,00,000 per yearDescriptionAt Pearson, we are the world's learning company with over 24,000 employees across 70 countries. Our mission is to combine world-class educational content and assessment, powered by services and technology, to enable more effective teaching and personalised learning at scale. We believe that wherever learning flourishes, so do people.In this...
-
Director, Secure Remote Commerce Product
4 days ago
Bengaluru, Karnataka, India Visa Full time US$ 1,20,000 - US$ 1,80,000 per yearCompany DescriptionVisa is a world leader in payments and technology, with over 259 billion payments transactions flowing safely between consumers, merchants, financial institutions, and government entities in more than 200 countries and territories each year. Our mission is to connect the world through the most innovative, convenient, reliable, and secure...
-
Director, Secure Remote Commerce Product
7 days ago
Bengaluru, Karnataka, India Visa Full time ₹ 15,00,000 - ₹ 60,00,000 per yearCompany Description Visa is a world leader in payments and technology, with over 259 billion payments transactions flowing safely between consumers, merchants, financial institutions, and government entities in more than 200 countries and territories each year. Our mission is to connect the world through the most innovative, convenient, reliable, and secure...
-
Application Security
4 days ago
Bengaluru, Karnataka, India Infosys Full time ₹ 6,00,000 - ₹ 12,00,000 per yearKey Responsibilities:Application SecurityNessusSAST DAST PTBurpsuitQulaysInfra VMInfra PTDevescopsContainer SecurityPreferred Skills:Application Security,Application Security->Application Risk Profiling,Application Security->Burpsuite,Application Security->Devsecops,Application Security->Ethical Hacking(CEH),Application Security->Nessus,Application...
-
Application Security Engineer
2 days ago
Bengaluru, Karnataka, India smallcase Full time ₹ 8,00,000 - ₹ 20,00,000 per yearAbout smallcase smallcase is on a mission to change how India & Indians invest. We build products & tools for individuals to invest better in stocks & ETFs and platforms & infrastructure for the industry to offer better investment products. Our user community is 6,50,000+ strong & we work with the largest financial brands in India like HDFC, Kotak,...
-
Application Security
4 days ago
Bengaluru, Karnataka, India ISECURION Full time ₹ 12,00,000 - ₹ 15,00,000 per yearJob Title: - Application SecurityNotice Period: - Immediate JoinersLocation: - Bengaluru (Onsite)Company Description:ISECURION is a leading cybersecurity services provider, ISO 27001:2022 certified and CERT-IN empanelled. We offer innovative solutions and cutting- edge research to address the evolving threats in the cyber landscape. We work with a diverse...
-
Application Security Engineer
7 days ago
Bengaluru, Karnataka, India Clinisys Full time ₹ 15,00,000 - ₹ 25,00,000 per yearIn this role, as an Application Security Engineer, you will work as a part of our security engineering team and you will collaborate with other IT professionals to ensure that data is protected. You will be responsible for suggesting and implementing with best security practices within software development lifecycle (SDLC). You will responsible for setting...