Product Security Lead
incred financial services- Posted 13 hours ago
- Be among the first 10 applicants
Job Description
Job Title: Product Security Lead
Experience Level: 8–10 Years
Location: Bangalore
About the Role
We are seeking a Product & Cloud Security Lead with 8 to 10 years of experience to own and drive the end-to-end security strategy for our cloud systems and SaaS platform. In this leadership role, the candidate will bridge technical security engineering with strategic governance—architecting resilient cloud environments, embedding security into every phase of the software development lifecycle (SDLC), and mentoring a high-performing engineering team.
Key Responsibilities
● Strategic Security Leadership: Define and execute the product and cloud security roadmap, setting technical standards across engineering, product, and cloud operations.
● Cloud Architecture & Engineering: Architect and enforce security controls for AWS cloud infrastructure, container ecosystems (Kubernetes, Docker), and Infrastructure-as-Code (Terraform/CloudFormation).
● Application Security & Threat Modelling: Conduct comprehensive threat modelling (STRIDE/PASTA), secure architecture reviews, and automated SAST/DAST/IAST coverage across application pipelines.
● DevSecOps Integration: Embed security tooling directly into CI/CD workflows, establishing automated guardrails for secret scanning, dependency vulnerability management, and policy-as-code enforcement (OPA).
● Incident Response & Operations: Lead cloud incident response efforts, execute root-cause post-mortems, and manage vulnerability disclosure programs (Bug Bounty, penetration testing governance).
● Compliance & Stakeholder Alignment: Partner with Compliance teams to ensure infrastructure and product architecture satisfy RBI, SEBI, ISO 27001, DPDPA requirements.
Required Qualifications
● Experience: 8–10 years in Application/Product Security, Cloud Security Engineering, or DevSecOps, with demonstrated experience and hands-on with security initiatives or engineering.
● Cloud & Infrastructure Expertise: Deep, hands-on knowledge of cloud IAM, network isolation, key management (KMS), zero-trust architecture, and CSPM/CWPP platforms (e.g., Wiz, Orca, GuardDuty, Prisma Cloud).
● Application & API Security: Strong grasp of OWASP Top 10, API security standards, secure coding practices, and identity protocols (OAuth 2.0, OIDC, SAML).
● Automation & Coding: Proficiency in Python, Go, or Bash to write automated security policies, custom integrations, and remediation scripts.
● Soft Skills: Excellent risk communication skills—able to translate complex security risks into clear business impacts for executives, product managers, and developers.
Preferred Certifications
● Certified Information Systems Security Professional (CISSP)
● Certified Cloud Security Professional (CCSP)
● Offensive Security Certified Professional (OSCP)
More Info
Key Skills
OPA
Prisma Cloud
Wiz
OAuth 2.0
IAST
zero-trust architecture
CWPP
STRIDE
PASTA
GuardDuty
network isolation
OIDC


