09 Aug
|
InMobi
|
Bengaluru
What will you be doing
This role combines technical leadership and hands-on execution: you will spend ~60% of your time performing application security testing, vulnerability assessments and penetration testing, code reviews, AI/ML security testing, and automation, and ~40% of your time managing the AppSec domain, leading the team, defining strategy, and coordinating with stakeholders.
- Lead the Application Security program across products, platforms, and engineering teams, defining strategy, roadmap, and measurable KPIs for AppSec and AI security maturity.
- Manage and mentor a team of AppSec engineers, ensuring effective prioritization, workload management, and continuous skill development.
- Perform hands-on SAST, DAST, manual code review, penetration testing, and vulnerability validation across web, mobile (Android and iOS), API, and cloud platforms.
- Perform security assessments of AI/ML and GenAI systems, including LLM applications, model endpoints, RAG pipelines, and agentic workflows.
- Partner with Engineering, Product, Cloud, DevOps, and Data Science teams to embed security controls early in the SDLC and ML/AI development lifecycle through automation, guardrails, and secure-by-design principles.
- Drive remediation governance: triage, track, and report on vulnerabilities with accountability across stakeholders; ensure closure within defined SLAs.
- Conduct security architecture and design reviews for new applications, APIs, integrations, and AI/ML systems to ensure alignment with enterprise security standards.
- Define and enforce secure coding guidelines, threat modeling practices (including AI/LLM threat models), and application and model hardening standards.
- Collaborate with the GRC and Incident Response teams to ensure audit readiness, compliance evidence and support during incidents.
- Research and adopt emerging AppSec and AI security technologies, frameworks, and practices to continuously strengthen defenses and developer experience.
- Drive metrics and reporting to senior leadership on AppSec performance, risk posture, and progress against roadmap goals.
What is expected of you
- 10 to 14 years of experience.
- Proven leadership experience in Application Security, DevSecOps, or Software Security Engineering, with the ability to lead a high-performing team while staying technically hands-on.
- Deep hands-on understanding of SAST, DAST, and secure SDLC integration; prior experience implementing and scaling security testing automation.
- Working knowledge of AI/ML and LLM security, threat modeling and testing against frameworks such as the OWASP Top 10 for LLM Applications, OWASP ML Security Top 10, and MITRE ATLAS; familiarity with securing GenAI/agentic applications and AI pipelines.
- Solid stakeholder management skills to influence and collaborate with product, engineering, cloud, and data science teams for timely triage and remediation.
- Experience managing AppSec tooling stack like Checkmarx, Burp Suite Enterprise, OWASP ZAP, MobSF, and open-source frameworks; exposure to AI security testing tooling (e.g., Garak, PyRIT, or equivalent) is a plus.
- Solid grasp of secure coding, vulnerability exploitation, and mitigation techniques across web, mobile, API, and AI/ML layers.
- Familiarity with CI/CD automation, scripting (Python, Bash, PowerShell), and container security (Docker/Kubernetes).
- Strong understanding of OWASP Top 10, SANS Top 25, OWASP LLM Top 10, and industry best practices.
- Excellent communication, reporting, and presentation skills for technical and executive audiences.
- Certifications such as OSCP, GWAPT, GPEN, or equivalent are preferred; AI security certifications (e.g., CAISP) are a plus.
- Prior experience in building or scaling AppSec or AI security programs and driving measurable security improvements is a strong plus.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Manager- Application Security (Bengaluru)
🏢 InMobi
📍 Bengaluru