Search by job, company or skills

Senior Manager Product Application & AI Security

Senior Manager Product Application & AI Security

Grant Thornton
12-14 Years
Not Disclosed
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

Summary:

We are looking for an experienced Product & Application Security Senior Manager to lead Product Security and Application Security initiatives, with an additional focus on AI Security, Secure SDLC, DevSecOps, vulnerability management, third-party security, and M&A integration.

The role partners with Product, Engineering, DevOps, Architecture, AI, Third-Party Risk Management, Infrastructure, and Security teams to embed security from design and development through deployment and production. The Senior Manager acts as the primary security advisor to Product and Engineering leadership, influencing product strategy, release decisions, technology adoption, and risk acceptance while balancing security, customer trust, regulatory obligations, and business objectives.

The ideal candidate combines strong hands-on Product and Application Security expertise with the ability to drive secure architecture, threat modeling, security testing, vulnerability remediation, and risk-based security decisions while effectively influencing technical and executive stakeholders.

Location: Bangalore/Kolkata, India.

Responsibilities:

1. Product Security

  • Lead Security-by-Design practices across product strategy, architecture, development, release, and operational lifecycles.
  • Conduct and oversee threat modeling, security architecture reviews, and product risk assessments for applications, APIs, cloud-native platforms, and AI-enabled solutions.
  • Grant Thornton INDUS | Product, Application & AI Security
  • Establish product-security standards, governance processes, security requirements, threat-modeling practices, and security metrics across the product portfolio.
  • Drive risk-based decisions regarding vulnerabilities, product-security incidents, software-supply-chain security, and secure product operations in partnership with Product and Engineering leadership.

2. Security Assurance & Testing Governance

  • Define and govern the organization's application and product-security assurance strategy, including SAST, DAST, SCA, API security testing, penetration testing, and AI security assessments.
  • Establish risk-based testing requirements, onboarding standards, security-coverage models, and secure-development assurance processes across products and platforms.
  • Review, challenge, and communicate security-assessment results to Product, Engineering, and executive stakeholders, ensuring security risks are understood and prioritized.
  • Drive remediation planning, risk-treatment decisions, exception management, and accountability with product teams through closure.

3. Security Tooling, Vulnerability & Risk Governance

  • Establish governance and operating models for application-security tooling, vulnerability management, security metrics, and risk reporting.
  • Oversee vulnerability identification, prioritization, remediation strategies, compensating controls, and risk-acceptance processes across the product portfolio.
  • Partner with Product, Engineering, and Security teams to communicate findings, coordinate remediation activities, remove blockers, and improve security outcomes.
  • Analyze vulnerability trends, recurring control gaps, and systemic risks while driving long-term improvements across products and development practices.

4. Product Security & Secure SDLC

  • Partner with Product, Engineering, Architecture, and DevOps teams to embed security requirements throughout the Software Development Lifecycle.
  • Conduct application and product-security risk assessments, architecture reviews, and security-design evaluations for new and existing products.
  • Define security requirements, standards, reference architectures, and secure-development practices that enable scalable and secure product delivery.
  • Communicate security findings, recommendations, and risk decisions while driving remediation and Secure-by-Design adoption across engineering teams.

5. AI Security & Agentic AI Security

  • Lead security assessments and threat evaluations for AI-enabled products, AI-native platforms, foundation-model integrations, and agentic AI solutions.
  • Review AI architectures, data flows, access controls, model interactions, tool integrations, agent permissions, and autonomous capabilities to identify risks and control gaps.
  • Define AI-security requirements, governance standards, and mitigation strategies addressing AI, ML, GenAI, and agentic-technology risks.
  • Communicate AI-security findings and remediation requirements to Product, Engineering, Data, and AI teams while ensuring appropriate ownership and risk treatment.

6. AI Security Review & Governance

  • Serve as a key security advisor within AI governance and review processes, providing risk-based guidance on AI initiatives and use cases.
  • Assess proposed AI solutions against security, privacy, regulatory, and data-protection requirements while identifying required controls and mitigations.
  • Collaborate with business, legal, privacy, data-protection, technology, and risk stakeholders to support informed approval and governance decisions.
  • Track material AI-security risks, action items, remediation commitments, and approval conditions through completion.

7. Third-Party Product & SaaS Security

  • Lead security assessments of third-party SaaS platforms, AI-service providers, technology products, APIs, and strategic vendor solutions.
  • Identify material security risks, communicate findings and recommendations, and drive remediation discussions with vendors and internal owners.
  • Partner with Third-Party Risk Management, Procurement, Legal, and Technology teams to support risk-based onboarding, ongoing assessments, and third-party security assurance.
  • Grant Thornton INDUS | Product, Application & AI Security

8. Security Governance, Risk & Reporting

  • Establish and maintain Product, Application, and AI Security governance frameworks, standards, policies, operating procedures, and risk-management processes.
  • Develop executive reporting and metrics covering product-security posture, application-security risk, AI-security exposure, remediation effectiveness, and program maturity.
  • Represent Product Security in governance forums, architecture reviews, technology initiatives, release discussions, and executive risk conversations.
  • Communicate security risks, recommendations, and business impacts while driving accountability, remediation actions, and continuous improvement across the portfolio.

Education / Professional Experience / Skills:

  • Strong expertise across Product Security, Application Security, Security Architecture, Cloud Security, AI Security, Technology Risk, and related disciplines.
  • Demonstrated ownership of product or application-security risk across the full lifecycle, from concept and architecture through release, operation, vulnerability response, and material change.
  • Expertise in strategic risk assessments, architecture and design reviews, threat modeling, and risk-based release-readiness decisions.
  • Sound understanding of modern SaaS, cloud-native, API-led, microservices, data-platform, and distributed architectures.
  • Practical knowledge of SAST, DAST, SCA, API security testing, penetration testing, vulnerability management, CI/CD security, and software-supply-chain controls.
  • Experience securing AI-enabled systems or depth in AI-security architecture, AI-risk assessment, agentic security, model and data controls, and AI evaluation.
  • Ability to translate complex technical conditions into clear business risk, decision options, and accountable actions for senior stakeholders.
  • Experience influencing Product and Engineering organizations and coordinating specialists across multiple security and risk domains.
  • Education / Professional
  • 12+ years of relevant experience across Product Security, Application Security, Security Architecture, Cloud Security, AI Security, Technology Risk, or related disciplines, including leadership of complex cross-functional security outcomes.
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

About Company