Skip to Main Content

Job Title


Head of Prod Security


Company : Confidential Careers


Location : Pune, Maharashtra


Created : 2025-06-04


Job Type : Full Time


Job Description

Are you a seasoned application security expert with a passion for safeguarding software applications?Join our team as the Head of Application Security and lead the charge in defining and executing our application security strategy. This leadership role is pivotal in ensuring the security of our software applications through robust DevSecOps practices, threat modeling, secure coding, and compliance with regulatory frameworks such as BSP, PCI-DSS, and ISO 27001.Key Responsibilities:Develop and execute an application security strategy aligned with business and regulatory requirements.Establish security policies, standards, and best practices for application development and deployment.Conduct security assessments, threat modeling, and code reviews to identify vulnerabilities.Implement and oversee security automation tools such as SAST, DAST, and IAST to enhance secure development.Lead and mentor a team of security engineers and analysts to improve security posture.Collaborate with development, DevOps, and infrastructure teams to integrate security into CI/CD pipelines (DevSecOps).Manage security incident response related to application vulnerabilities and breaches.Ensure compliance with regulatory frameworks such as BSP, PCI-DSS, ISO 27001, and NIST standards.Engage in security awareness training and promote secure coding practices across teams.Stay updated on emerging threats, vulnerabilities, and cybersecurity trends.Qualifications:Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.8+ years of experience in application security, with at least 3 years in a leadership role.Strong knowledge of secure software development lifecycle (SSDLC) and DevSecOps practices.Experience with security testing tools such as Burp Suite, OWASP ZAP, Veracode, or similar.Expertise in authentication, authorization, encryption, and identity management principles.Familiarity with cloud security (AWS, Azure, or GCP) and container security (Kubernetes, Docker).Relevant certifications such as CISSP, CISM, OSCP, CEH, or CSSLP are preferred.Excellent problem-solving, communication, and leadership skills.Join us and be a part of a team that prioritizes security and innovation. Apply now to make a significant impact on our application security landscape!