Information Technology & Software
16 Sept
Manager Product Security Specialist
PURPOSE AND SCOPE:The Manager of Product Security will support the Global Product Security Program in leading and advancing the organization’s product security program in India. This role is responsible for driving secure-by-design principles across the product lifecycle, strengthening application and platform security capabilities, and enhancing the overall security posture and resilience of the company’s products and services.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
Assist in the day-to-day management of the Product Security program, providing secure development and application security services across multiple product and engineering teams. This includes secure SDLC implementation, application security monitoring, vulnerability management, threat modeling, and security policy enforcement.Define and track key program metrics, including Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs), to measure the effectiveness of the Product Security program and assess product and application security risks across the organization.
Partner with engineering, architecture, DevOps, cloud, and business stakeholders to embed security controls, automate policy enforcement, and identify opportunities for secure technology integrations within product ecosystems.
Collaborate with third-party vendors and internal teams to conduct application security assessments, penetration testing, secure code reviews, and red team exercises across products and platforms.
Support and coordinate Product Security incident response activities, including triage, investigation, remediation guidance, and escalation management for application and product-related security incidents.
Lead and mentor Product Security engineers and analysts by establishing clear goals, deliverables, development plans, performance feedback, coaching, and operational metrics.
Oversee the planning and execution of vulnerability assessments, penetration testing, threat modeling, and security reviews for products, applications, APIs, and cloud-native platforms. Drive remediation and risk reduction strategies for identified vulnerabilities across product lines.
Manage the execution of tactical and strategic Product Security initiatives through effective coordination of cross-functional teams, with accountability for deliverables, timelines, resource planning, and operational outcomes.Stay current with industry best practices, emerging threats, secure developmentframeworks, cloud security standards, and regulatory guidance related to product and application security.
Lead the development and enhancement of Product Security policies, standards, procedures, and secure engineering guidelines to address evolving application, API, cloud, and software supply chain threats.
Lead and/or contribute to Product Security transformation initiatives, security tooling enhancements, DevSecOps integrations, compliance activities, and other strategic projects assigned by leadership.
PHYSICAL DEMANDS AND WORKING CONDITIONS:
The physical demands and work environmental characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
SUPERVISION:
Will be responsible for the direct supervision of various levels of Product Security team members.
EDUCATION:
Bachelor’s degree in Cybersecurity, Information Technology, or a related field
EXPERIENCE AND REQUIRED SKILLS:
15+ years of experience working in the Security Operations and/or other Cybersecurity domain.
Direct people management experience is a must
Understanding of product security concepts including SDLC practices, threat modeling, vulnerability management, and application security governance.
Ability to operate as a pro-active and result-driven problem solver with excellent analytical and interpersonal skills.
Ability to understand IT and business management objectives, organizational risk appetite, and risk tolerance levels, and evaluate the impact of evolving business and technology changes on the organization’s risk profile.Strong client services orientation and communication skills coupled with a high sense of urgency to keep appropriate partners informed, including solutions to overcome obstacles to deliver to expectation.
Strong understanding of risk management, integration with enterprise risk management and business strategy.
Relevant certifications such as CompTIA Security+, CISSP, CISM are preferred.
Experience in IT governance, risk, and controls, including governance frameworks.
Demonstrated technical writing, communication, and presentation skills.
Proven record to deliver results.