Search by job, company or skills

Product Security Lead

Product Security Lead

incred financial services
8-10 Years
Not Disclosed
  • Posted 13 hours ago
  • Be among the first 10 applicants

Job Description

Job Title: Product Security Lead

Experience Level: 8–10 Years

Location: Bangalore

About the Role

We are seeking a Product & Cloud Security Lead with 8 to 10 years of experience to own and drive the end-to-end security strategy for our cloud systems and SaaS platform. In this leadership role, the candidate will bridge technical security engineering with strategic governance—architecting resilient cloud environments, embedding security into every phase of the software development lifecycle (SDLC), and mentoring a high-performing engineering team.

Key Responsibilities

● Strategic Security Leadership: Define and execute the product and cloud security roadmap, setting technical standards across engineering, product, and cloud operations.

● Cloud Architecture & Engineering: Architect and enforce security controls for AWS cloud infrastructure, container ecosystems (Kubernetes, Docker), and Infrastructure-as-Code (Terraform/CloudFormation).

● Application Security & Threat Modelling: Conduct comprehensive threat modelling (STRIDE/PASTA), secure architecture reviews, and automated SAST/DAST/IAST coverage across application pipelines.

● DevSecOps Integration: Embed security tooling directly into CI/CD workflows, establishing automated guardrails for secret scanning, dependency vulnerability management, and policy-as-code enforcement (OPA).

● Incident Response & Operations: Lead cloud incident response efforts, execute root-cause post-mortems, and manage vulnerability disclosure programs (Bug Bounty, penetration testing governance).

● Compliance & Stakeholder Alignment: Partner with Compliance teams to ensure infrastructure and product architecture satisfy RBI, SEBI, ISO 27001, DPDPA requirements.

Required Qualifications

● Experience: 8–10 years in Application/Product Security, Cloud Security Engineering, or DevSecOps, with demonstrated experience and hands-on with security initiatives or engineering.

● Cloud & Infrastructure Expertise: Deep, hands-on knowledge of cloud IAM, network isolation, key management (KMS), zero-trust architecture, and CSPM/CWPP platforms (e.g., Wiz, Orca, GuardDuty, Prisma Cloud).

● Application & API Security: Strong grasp of OWASP Top 10, API security standards, secure coding practices, and identity protocols (OAuth 2.0, OIDC, SAML).

● Automation & Coding: Proficiency in Python, Go, or Bash to write automated security policies, custom integrations, and remediation scripts.

● Soft Skills: Excellent risk communication skills—able to translate complex security risks into clear business impacts for executives, product managers, and developers.

Preferred Certifications

● Certified Information Systems Security Professional (CISSP)

● Certified Cloud Security Professional (CCSP)

● Offensive Security Certified Professional (OSCP)

More Info

Job Type:
Industry:
Employment Type:

Key Skills

OPA

Prisma Cloud

Wiz

OAuth 2.0

IAST

zero-trust architecture

CWPP

STRIDE

PASTA

GuardDuty

network isolation

OIDC

Similar Jobs

5-10 yrs
Bengaluru, India
Skills:
Application Security, Penetration Testing, Owasp Top 10, Vapt, DAST, SCA, Adversarial Machine Learning, Exploitations, Security Testing Tools, Offensive Security, AI ML Architectures, SAST, AI Security Testing, API Security Testing
6-8 yrs
Bengaluru, India
Skills:
continuous monitoring , Dynamic Application Security Testing (DAST), Azure Web Application Firewall (WAF), Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secure Development Lifecycle (SDL/SSDLC), security automation , Vulnerability Management, Incident Response, Security risk remediation, Microsoft Azure security solutions, Barracuda WAF, Security Monitoring, Microsoft Defender for Cloud, Palo Alto Prisma Cloud, Azure Policy, Azure Security Center, Threat detection, Cloud-native security technologies
5-8 yrs
Bengaluru, India
Skills:
product security , threat modeling , DAST, Cloud Security, Vulnerability Management, Information Security, Confluence, Docker, Application Security, Sonarqube, Agile, Gitlab, Scrum, Azure DevOps, AWS, Cybersecurity, Jira, Burp Suite, Gcp, API Security, Owasp Top 10, Azure, Kubernetes, OWASP Dependency Check, SAST, Secure Architecture Reviews, Snyk, SCA, Container Security