21 Aug
|
Smartstream
|
Bengaluru
21 Aug
Smartstream
Bengaluru
The Security Engineering Manager leads day-to-day operations of the Smartstream Security Engineering organisation - a Centre of Excellence team, that closely collaborates with embedded Security Engineers aligned to product lines, and a Security Champions community across engineering and business applications - owning execution of Secure SDLC, AppSec, and product-side cloud security across the product portfolio.
This is a player-manager role: set strategy and run the team but also engage personally with the most complex security initiatives, customer audits, regulatory exchanges, and incident escalations.
- Team leadership. Lead and grow a multi-disciplinary Security Engineering team across the Centre of Excellence and embedded engineer pods. Own hiring, performance, and career development; inspire and actively mentor the team.
- Secure SDLC governance Own and govern the Secure SDLC framework across the product portfolio, including security policies, standards, controls, and integration of security requirements throughout the software development lifecycle.
- Drive adoption of secure engineering practices, including SAST, SCA, AI-assisted code reviews, LLM-driven vulnerability scanning, and threat modelling, while advancing security maturity aligned with OWASP SAMM / BSIMM practices.
- Threat modelling & risk assessment. Sponsor early-stage architectural evaluations and threat-modelling reviews for new features, products, and material design changes - identifying and mitigating risks before code ships.
- VulnOps. Oversee the unified vulnerability-operations function - a single risk-scored backlog consolidating findings from SAST, DAST, SCA, container/IaC, secret scanning, CSPM, and pen testing. Drive remediation through ASPM/RBVM-powered prioritisation (exploitability, reachability, business impact), deduplication, automated fixes, and SLA-driven cadence with engineering - reducing noise to engineering and bringing down mean-time-to-remediate.
- Supply chain security. Establish and drive the software supply chain security strategy, including dependency management, SBOM governance, and third-party component risk management. Provide security oversight and remediation guidance while Product teams are responsible for implementing approved actions.
- Customer Security Assurance (Technical SME).
Act as the technical security-controls SME for financial-institution customer security audits, vendor risk questionnaires, and contractual evidence requests - covering Secure SDLC, AppSec, VulnOps, threat modelling, pen testing, cloud security, supply-chain security, and incident response.
- External pen testing & regulatory evidence. Scope and drive third-party (external) penetration testing engagements requested by financial-institution customers. Maintain the technical evidence base for product alignment with SOC 2, ISO 27001, PCI DSS, DORA, and applicable data-protection laws (e.g., GDPR).
- Incident response. Own product-security incident command - direct remediation, internal triage, and customer communication for product CVEs and security incidents.
- Programme reporting. Run program dashboards for AppSec/cloud posture, finding burndown, SLA breach, MTTR, coverage, and pen-test status. Present to CISO, CTO, engineering leadership, and Board sub-committees.
- Security evangelism & mentorship. Educate engineering, product, and QA teams on secure coding, threat modelling, and secure-by-design. Sponsor and govern the Security Champions network (BSIMM Satellite model).
- Vendor & tooling ownership. Own the AppSec and product-security toolchain across SAST, DAST, SCA, ASPM/RBVM, SBOM, secret scanning, LLM-assisted code scanning, and CSPM.
- Engineering partnership. Partner with engineering leads and business operations; ensure embedded SEs are integrated into sprint planning, release gating, and change management.
Required qualifications• 10+ years in application / product and cloud security, including 4+ years leading AppSec or Security Engineering teams.
- Direct experience running secure SDLC programs for a B2B software vendor selling into regulated financial services.
- Hands-on familiarity with at least two of the following security frameworks and maturity models: OWASP SAMM, BSIMM,
OWASP DSOMM, AWS Security Reference Architecture (AWS SRA), or equivalent cloud security frameworks.
- Solid knowledge of AWS cloud security and cloud vulnerability management, including S3 bucket misconfigurations, IAM risks, and CVE remediation. Working knowledge of DORA, PCI DSS v4.0.1, ISO 27001, SOC 2 Type 2, and GDPR and how each translates into engineering controls.
- Proven experience integrating security tooling into CI/CD pipelines at scale, and coaching engineers through threat-modelling methodologies (STRIDE, PASTA, LINDDUN, or equivalent).
- Practical knowledge of the OWASP Top 10 for LLM Applications and OWASP AI Security & Privacy, with hands-on experience securing GenAI/LLM features against prompt injection, insecure output handling, data poisoning, and excessive agency.
- Understanding of Model Context Protocol (MCP) security - server/client auth, scoped tool permissions, secret handling, tool poisoning, and indirect prompt injections.
- Demonstrated ability to lead financial-institution customer audit responses and engage with customer security teams and regulators.
- Strong grounding in modern AppSec tooling (SAST, DAST, SCA, ASPM, SBOM, secret-scanning) and cloud security posture management.
- Excellent written and verbal communication; comfortable presenting to CISO, engineering leadership, and external auditors.
Preferred qualifications• CISSP, CISM, CSSLP, GIAC GSLC, or equivalent.
- Experience operating a Security Champions / BSIMM Satellite model.
- Experience with LLM-assisted threat modelling and code scanning at scale.
- Working knowledge of AI/ML security frameworks (NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, Google SAIF)
Key SkillsAppSec, Secure SDLC, BSIMM, OWASP SAMM, DORA, ISO 27001, SOC 2, PCI DSS, Threat Modelling, SAST, DAST, SCA, ASPM, RBVM, CSPM, SBOM, Vulnerability Management, CI/CD Security, Supply-Chain Security, AWS Cloud Security, IAM, Security Hub, GuardDuty, Cloud & Container Security, IaC Security, FSI / Financial Services, Incident Response, Team Leadership, Security Champions.
Desired SkillsCISSP, CISM, CSSLP, GIAC GSLC, LLM-assisted Security, AI Agent Security, Agentic Remediation, BSIMM Satellite Model, Cloud Security Posture Management, GDPR.
📌 Security Engineering Manager (Bengaluru)
🏢 Smartstream
📍 Bengaluru