security incident handling, and participation in vendor and third-party application security reviews. Develop and execute secure software development strategy in the form of Secure SDLC for the enterprise, including policies, standards and governance Advance and execute a software supply chain security development strategy to include Identify security risk and vulnerabilities across client's supply chain partners as well and track implementation of corrective action plans by supply chain partners Identify and manage risks involved with use the of AI within products and within the development of products Manage Product Risk management and risk profiling Manage the Vulnerability and Penetration Testing Team Manage relationships with multiple 3rd party penetration testing vendors Oversee the security portion of release management Manage Product Security incident response program and team Make data-based decisions and considers measurable metrics as part of the initiative Consult with Development, Operations and Product groups on technical security issues. Closely partner with PISOs, Development Leads to integrate security tool automation such as SAST, DAST, Container Analysis and other security tools Manage Delivery of Developer Security Training Strong planning, organizational, and leadership skills, including the ability to motivate teams, set strategic vision and approach, and resolve conflict. SecDevOps, or DevSecOps, process framework experience. Ability to build a strong network, both inside and outside the organization. Experienced people manager with 5-10+ years’ combined experience in application development, application security, vulnerability management, and / or network security. Strong working knowledge of secure coding principles, practices, and frameworks such as OWASP Top Ten and SANS 20 Critical Security Controls. Hands-on experience with application security and vulnerability management tools. Working knowledge of comprehensive information security principles and practices. Bachelor of Science in Computer Science or related field required. Master of Science in Information Security or related field preferred.
Director Consulting • Bengaluru, Republic Of India, IN