02 Sep
|
Pine Labs
|
Ghaziabad
02 Sep
Pine Labs
Ghaziabad
Remote: Hybrid
We're Hiring | Senior Manager – Application Security (AppSec) Location: Noida Sector 62 (Pine Labs) Work Mode: 5 Days Work from Office (No Remote/Hybrid)Role OverviewWe are looking for an experienced Senior Manager – Application Security to lead and strengthen our Application Security, AI Security, API Security, Mobile Security, and Secure Code (SAST) programs.This leadership role will drive secure engineering practices across the organization by embedding security into every stage of the software development lifecycle. You will partner closely with Engineering, Product, Infrastructure, and Compliance teams to build scalable, cloud-native, and secure applications.The ideal candidate brings deep expertise in Application Security, Secure SDLC, AI Security, DevSecOps, Cloud Security, API Security, Mobile Security, Secure Code Reviews, and Security Automation, along with proven experience leading high-performing security teams.Key ResponsibilitiesApplication SecurityDefine, implement, and continuously improve Secure SDLC practices across the organization.Conduct security architecture reviews, secure design assessments, and threat modeling exercises.Perform application security assessments for web, cloud-native, and microservices-based applications.Drive vulnerability management and remediation programs.Establish secure coding standards and security requirements.Partner with engineering teams to remediate security vulnerabilities throughout the software lifecycle.AI SecurityEstablish enterprise-wide AI/LLM security standards and governance.Conduct security reviews and threat modeling for AI, GenAI, LLM, Agentic AI, and RAG-based applications.Assess risks related to:Prompt InjectionInsecure Output HandlingData LeakageModel ManipulationAI Supply Chain RisksEvaluate security controls for MCP-based solutions and third-party AI integrations.Enable secure adoption of AI technologies across the organization.API SecurityDefine API Security governance aligned with the OWASP API Security Top 10.Perform API security assessments and threat modeling.Review authentication, authorization, encryption, and access control mechanisms.Ensure secure implementation of OAuth 2.0, OpenID Connect, JWT,
and API Gateway security controls.Maintain API inventory and assess third-party API risks.Mobile Application SecurityLead Android and iOS application security assessments.Establish mobile security standards aligned with OWASP MASVS.Review:Secure StorageEncryptionCertificate PinningAnti-Tampering ControlsRoot/Jailbreak DetectionManage mobile penetration testing and remediation programs.SAST & Secure Code ReviewOwn the organization's Secure Code (SAST) strategy.Deploy and manage SAST solutions across engineering teams.Integrate SAST into CI/CD pipelines.Perform secure code reviews.Validate remediation of identified vulnerabilities.Define vulnerability management SLAs.Optimize SAST rules to reduce false positives.Coach developers on secure coding best practices.DevSecOps & Security AutomationIntegrate security controls into CI/CD pipelines.Implement and manage:SASTDASTSCASecrets ScanningContainer SecurityInfrastructure as Code (IaC) SecurityAutomate security testing and compliance validation.Implement security gates and risk-based approval workflows.Drive Shift-Left Security practices across engineering teams.Governance & ComplianceDevelop and maintain application security policies and standards.Track AppSec KPIs and security posture metrics.Support compliance with:PCI DSSISO 27001RBI GuidelinesDPDPOther regulatory frameworksParticipate in audits and enterprise risk assessments.Drive Security Champion and developer awareness programs.Leadership & Stakeholder ManagementLead and mentor Application Security Engineers and Security Analysts.Collaborate with Product, Engineering, Infrastructure, Architecture, and Compliance teams.Present security risks, remediation plans,
and KPIs to senior leadership.Define and execute the Application Security roadmap and maturity initiatives.Required Skills & ExpertiseApplication SecuritySecure SDLCThreat ModelingSecure Design ReviewsSecure Coding PracticesOWASP Top 10Vulnerability Assessment & Penetration TestingSAST & Code SecurityCheckmarxGitHub Advanced Security (CodeQL)API SecurityOWASP API Security Top 10OAuth 2.0OpenID ConnectJWTAPI Gateway SecurityAPI Testing & Security ValidationMobile SecurityAndroid SecurityiOS SecurityMobile Application HardeningMobile Penetration TestingAI SecurityGenAI SecurityLLM SecurityPrompt Injection PreventionRAG SecurityAI Threat ModelingAI Risk AssessmentMCP Security ReviewsRequired ExperienceBachelor's or Master's degree in Computer Science, Information Technology, Cyber Security, or a related field.12+ years of overall Information Security experience.Minimum 10 years of experience in Application Security or Product Security leadership roles.Proven experience leading enterprise Application Security programs in cloud-native environments.Strong understanding of modern software engineering practices and DevSecOps.What We're Looking For✔ Passion for building secure software at scale.✔ Ability to influence engineering teams and embed security into product development.✔ Solid leadership, stakeholder management, and communication skills.✔ Experience driving security transformation in fast-paced technology organizations.What You Should Be Comfortable WithWorking from the office 5 days a week.Challenging conventional thinking and driving innovation.Taking ownership of large-scale security initiatives.Working in a fast-paced, high-impact engineering environment.What We Value You Take the ShotYou make decisions with confidence and execute with speed. You Own ItYou act like the CEO of your work, taking complete ownership and accountability. You Craft with PrideYou continuously learn, strive for excellence, and take pride in building secure, world-class products.If you're passionate about building secure engineering ecosystems and shaping the future of Application & AI Security, we'd love to hear from you.This version is optimized for LinkedIn with clear headings, concise bullets, recruiter-friendly keywords, and improved readability while preserving all of the technical depth.
📌 Senior Manager - Application Security & AI Security (Ghaziabad)
🏢 Pine Labs
📍 Ghaziabad