- Experience
- 15+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 hours ago
- Work mode
- In office
- Education
- Any graduate
- Eligibility
- Applicants must have completed any graduate degree.
- Resume
- Required to apply
Where you'll work
Job description
Overview
The role is tasked with leading and advancing the organization's cybersecurity products and solutions. It demands a strategic leader with vast experience in cybersecurity to promote innovation and align security measures with business objectives.
Key Responsibilities
- Lead the direction and execution of application security initiatives aligned with corporate goals and risk mitigation.
- Develop and implement comprehensive lifecycle security strategies—from design to deployment and ongoing management.
- Manage, mentor, and build a team of security engineers and analysts to foster a strong security culture.
- Collaborate closely with senior leadership, development, product, and IT teams to prioritize security efforts.
- Assess application security postures and identify risks such as data breaches and vulnerabilities.
- Proactively detect threats and evaluate architectural risks posed by cyber adversaries.
- Recommend and oversee remediation strategies to reduce exposure.
- Embed security practices across the software development lifecycle, including secure coding, design, testing, and deployment.
- Conduct code reviews, static and dynamic analysis, and penetration tests to uncover vulnerabilities.
- Guide developers on integrating secure coding standards and security controls.
- Supervise security testing including automated scans, vulnerability assessments, and penetration testing.
- Select and manage security tools like SAST, DAST, and Software Composition Analysis to identify weaknesses.
- Track remediation progress of vulnerabilities and ensure timely resolution.
- Ensure application compliance with standards such as GDPR, PCI DSS, HIPAA, and SOC 2.
- Develop and enforce policies, standards, and best practices for secure software development and deployment.
- Conduct regular audits of applications and security controls and report metrics to management and auditors.
- Lead investigation and response to security incidents, identifying root causes and preventing recurrence.
- Stay informed on evolving threat vectors, vulnerabilities, and attack techniques to adapt defenses.
- Coordinate with cybersecurity teams to communicate impact and mitigation among stakeholders.
- Conduct training sessions to raise security awareness among developers, QA, and related teams.
- Promote secure coding principles and increase organizational security culture.
- Work collaboratively with infrastructure security on network, endpoint, and cloud security integration.
- Facilitate red team exercises to test application resilience under real-world attacks.
- Implement automation tools to optimize security testing and vulnerability management workflows.
- Continuously evaluate security practices, tools, and processes for efficiency and coverage improvements.
- Assess and manage security risks of third-party applications and vendors.
- Evaluate supplier and contractor security compliance to ensure organizational protection.
Technical Expertise
- Expertise in application security strategy and secure SDLC leadership.
- Proficiency in DevSecOps processes and integrating security tools.
- Experience with threat modeling and secure architectural design.
- Strong skills in vulnerability management and application security testing.
Qualifications and Experience
- Bachelor's degree in Computer Science, IT, Cybersecurity or related discipline.
- Preferred: Master's degree or certifications in Cybersecurity or Technology Management.
- Industry certifications like CISSP, CISM or equivalents strongly desired.
- Additional credentials in emerging tech and innovation management are a plus.
- Minimum 15 years of proven leadership experience in cybersecurity.
- Demonstrated success driving innovation and technology advancement in cyber product development.
Skills
Strategic Thinking
Penetration Testing
Security Policy Development
Dynamic Application Security Testing (DAST)
Secure Software Development Lifecycle (SDLC)
Incident response management
application security strategy
DevSecOps tools integration
threat modeling techniques
vulnerability assessment and management
static application security testing (SAST)
software composition analysis (SCA)
security compliance (GDPR, PCI DSS, HIPAA, SOC 2)
Work styles they’re looking for
Leadership
Collaboration
Mentoring
Proactive Problem Solving