Talent.com
▷ [High Salary] Director of Application Security

▷ [High Salary] Director of Application Security

HCLSoftwareBengaluru, Karnataka, India
15 days ago
Job description

HCLSW seeks a Director, Head of Product & Application Security. The successful candidate will lead the end to end Product Security portfolio within HCL Software. Maintains and strengthens the risk posture across the organization through discovery and remediation of product security vulnerabilities and supply chain security. Establishes and communicates strategic vision for the programs, and ensures they align with development goals and opportunities. Leads a dynamic group of Application Security professionals worldwide, with expectations to expand team over time.

This individual is also expected to contribute to additional tasks in a cross-functional security team, especially assisting the Threat Management team; network and operating system vulnerability management; continuous monitoring and reporting; security incident handling, and participation in vendor and third-party application security reviews.

Key Responsibilities :

  • Develop and execute secure software development strategy in the form of Secure SDLC for the enterprise, including policies, standards and governance
  • Advance and execute a software supply chain security development strategy to include Identify security risk and vulnerabilities across client's supply chain partners as well and track implementation of corrective action plans by supply chain partners
  • Identify and manage risks involved with use the of AI within products and within the development of products
  • Manage Product Risk management and risk profiling
  • Lead the updating of the Secure Engineering Framework.
  • Manage the Vulnerability and Penetration Testing Team
  • Manage relationships with multiple 3rd party penetration testing vendors
  • Oversee the security portion of release management
  • Manage Product Security incident response program and team
  • Make data-based decisions and considers measurable metrics as part of the initiative
  • Consult with Development, Operations and Product groups on technical security issues.
  • Closely partner with PISOs, Development Leads to integrate security tool automation such as SAST, DAST, Container Analysis and other security tools
  • Directly engage development leaders to understand their challenges, roll-up sleeves when needed and understand / address their issues at a technical level
  • Lead Comprehensive Penetration Testing Activities, to include both staff and vendor relationships
  • Manage Delivery of Developer Security Training

Key Skills :

  • Proven ability to define strategic visons and lead team through execution.
  • Strong understanding of AI, LLMs and other AI technology
  • Strong planning, organizational, and leadership skills, including the ability to motivate teams, set strategic vision and approach, and resolve conflict.
  • Proven ability to learn, evaluate, and adapt to new technologies and tools.
  • SecDevOps, or DevSecOps, process framework experience.
  • Ability to build a strong network, both inside and outside the organization.
  • Excellent written and verbal communication skills, and ability to present ideas to all organizational levels.
  • Ability to work in a dynamic environment, managing multiple initiatives and commitments simultaneously with tight deadlines and changing priorities.
  • Flexibility to contribute as needed, even in areas not tightly mapped to stated responsibilities.
  • Mandatory Qualifications

  • Experienced people manager with 5-10+ years’ combined experience in application development, application security, vulnerability management, and / or network security.
  • Strong working knowledge of secure coding principles, practices, and frameworks such as OWASP Top Ten and SANS 20 Critical Security Controls.
  • Hands-on experience with application security and vulnerability management tools.
  • Working knowledge of comprehensive information security principles and practices.
  • Bachelor of Science in Computer Science or related field required. Master of Science in Information Security or related field preferred.
  • Desirable Certifications

  • CISSP, CSSLP, CISM, CISA, CEH, GPEN, GWAPT, Hyperscaler certifications
  • Create a job alert for this search

    Application Security • Bengaluru, Karnataka, India

    Related jobs
    • Promoted
    Lead Plant Security

    Lead Plant Security

    Tata ElectronicsHosur, Tamil Nadu, India
    Head of Security (Corporate) TEPL.Electronics Manufacturing Services, Semiconductor Assembly & Test, Semiconductor Foundry, and Design Services. Established in 2020 as a greenfield venture of the Ta...Show moreLast updated: 20 days ago
    Cyber Security Architect

    Cyber Security Architect

    Saaki Argus & Averil ConsultingBangalore Rural, Karnataka, India
    Quick Apply
    Hiring for Cyber Security Architect.A minimum of 12 + years of professional experience in software development.Sound understanding of security technologies / techniques like Cryptography, Algorithms,...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security GRC Leader

    Information Security GRC Leader

    SagilityBengaluru, Karnataka, India
    Sagility is a tech-enabled BPM services provider, a thought partner providing a broad spectrum of transformational services, to enable our clients provide efficient and hi-quality care across the h...Show moreLast updated: 20 days ago
    • Promoted
    Pixis - Head - Information Security

    Pixis - Head - Information Security

    PixisBangalore, India
    Pixis is a global AI technology company transforming how brands plan, create, and optimize marketing.Our flagship marketing operating system, Prism, sits at the core of the Pixis platform, using AI...Show moreLast updated: 30+ days ago
    • Promoted
    Linfox - Site Security Manager

    Linfox - Site Security Manager

    LinfoxChikkaballapura, India
    Description : Job Title : Site Security Manager Location : Chikkaballapura, Karnataka Department : Security & SafetyShow moreLast updated: 20 days ago
    • Promoted
    Sr SAP Security and GRC Architect

    Sr SAP Security and GRC Architect

    DanaherBengaluru, Karnataka, India
    This job is with Danaher, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.The Sr SAP Secur...Show moreLast updated: 4 days ago
    Senior Manager - Information Security Trust & Compliance (Bangalore)

    Senior Manager - Information Security Trust & Compliance (Bangalore)

    First AdvantageBangalore, Karnataka, IN
    Quick Apply
    The role will own, lead, and scale large, multi-client GRC programs across diverse industries.This role will own the strategy and execution of a risk-based GRC approach that identifies, measures, m...Show moreLast updated: 30+ days ago
    Product Security - Practice Head

    Product Security - Practice Head

    Saaki Argus & Averil ConsultingBangalore Rural, Karnataka, India
    Quick Apply
    Our client is a leading Engineering & R&D company, having presence globally.Product Security - Practice Head.Bangalore, Pune (Work from Office). Understand client pain points and provide pro...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    ArcanaBangalore, IN
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show moreLast updated: 30+ days ago
    Information Security Engineer

    Information Security Engineer

    Epergne SolutionsBangalore Rural, Karnataka, India
    Quick Apply
    Job Roles & Responsibilities : .Docker, Kubernetes), databases, and web services.Qualys to identify and assess security risks. Analyze vulnerability scan results, validate.Identify root causes for...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Architect

    Senior Security Architect

    DautomBengaluru, IN
    Role : Senior Security Architect.Location : Offshore, India (Remote).You’ll drive end-to-end security design across platforms, lead threat modeling and control gap assessments, oversee IT security r...Show moreLast updated: 9 days ago
    • Promoted
    Application Security Architect

    Application Security Architect

    YASH TechnologiesGreater Bengaluru Area, India
    Role : Application Security Architect.This role is responsible for architecting, designing security controls for applications. The successful candidate will lead efforts to establish and improve secu...Show moreLast updated: 20 days ago
    • Promoted
    Principal Security Architect

    Principal Security Architect

    Standard Chartered BankBengaluru, Karnataka, India
    This job is with Standard Chartered Bank, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly....Show moreLast updated: 7 days ago
    Senior Information Security Engineer

    Senior Information Security Engineer

    Epergne SolutionsBangalore Rural, Karnataka, India
    Quick Apply
    Senior Information Security Engineer.Job Roles & Responsibilities : .Docker, Kubernetes), databases, and web services.Create and maintain comprehensive documentation including.SOPs, technical rep...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Analyst

    Senior Security Analyst

    Softcell Technologies Global Pvt. Ltd.Bengaluru, Karnataka, India
    Job Title : Senior Security Analyst.Location – Mumbai, Hyderabad & Bangalore.Softcell Global Technologies Pvt.Senior Security Analyst with strong offensive security capabilities across the Web, Netw...Show moreLast updated: 30+ days ago
    • Promoted
    Principal Security Engineer

    Principal Security Engineer

    EthosBangalore
    About the role : As a member of Ethos Trust and Safety team, you'll be responsible for building various security services a...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Lead

    Information Security Lead

    Narayana HealthBengaluru, Karnataka, India
    The Information Security Lead will be responsible for developing and implementing the organization’s information security framework to safeguard patient data, clinical systems, and enterprise IT in...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Lead

    Information Security Lead

    TalentOyeBangalore
    Information Security Lead Location : Bangalore, India Experience : 6 to 15 years <...Show moreLast updated: 30+ days ago