Head - Security & Compliance (Faridabad)

Head - Security & Compliance (Faridabad)

03 Sep
|
Novelvox
|
Faridabad

03 Sep

Novelvox

Faridabad

We are looking for a hands-on security leader who owns practical security execution, not paperwork. This role exists to ensure that product releases, delivery practices, and customer interactions consistently meet security expectationsespecially in regulated industries like healthcare and banking.

This is not a CISO role. This is an execution-first security leadership role with authority, accountability, and direct access to executive leadership.

Core Objective Prevent avoidable security incidents caused by:

- Tool misuse (e.g., Postman, file sharing) • Poor release hygiene • Delivery shortcuts under customer pressure And when something does happen:
- Act as the single authoritative face to customers • Drive root cause analysis • Implement permanent preventive controls Key Responsibilities 1.

Security

Governance (Practical, Not Bureaucratic) • Define non-negotiable security standards for: o API testing tools o File sharing o Source code handling o Release artifacts • Convert policies into enforceable controls, not guidelines • Maintain a explicit allowed / disallowed tools list 2. Product &
- Release Security • Own the security gate for all product releases: o Mandatory VAPT / SAST / DAST artifacts o Verification that no test code, debug flags, or credentials are included • Work with product engineering to: o Define release checklists o Automate scans where possible • Periodically review legacy components for risk exposure 3.

Delivery

Security &

• Field Discipline • Define secure delivery playbooks for: o Customer testing o Data exchange o Temporary access • Eliminate ad-hoc practices (e.g., Dropbox, personal tools)



• Train delivery teams on what is never allowed, regardless of customer pressure 4.

Incident

Response &

• Customer Trust • Act as the single point of leadership during: o Security findings o Ethical hacking disclosures o Customer audits or security reviews • Lead: o Root cause analysis o Corrective and preventive actions (CAPA) • Prepare executive-ready and customer-ready incident reports 5. Compliance &
- External Readiness • Support security requirements for: o Healthcare (HIPAA) o Banking / Financial institutions • Coordinate: o External security consultants o Penetration testing vendors • Maintain audit-ready documentation without slowing delivery 6.

Internal

Enablement (Not Just Training) • Design short, practical security training for: o Delivery teams o Product teams • Focus on real scenarios, not theoretical security • Continuously reinforce expectations through process and tooling Required Experience Must-Have • 8–15 years in application security, product security, or delivery security • Hands-on experience with: o API security o Web applications o SaaS platforms • Prior experience supporting: o Enterprise customers o Regulated industries (healthcare, banking, financial services)



• Proven ability to push back on customers without damaging relationships Strongly Preferred • Background as: o Senior architect o Principal engineer o Security consultant • Experience working in: o Product companies (not just IT services) • Exposure to: o SOC2, HIPAA, ISO 27001 (certification not mandatory) Skills &

Competencies Technical • API security &

- OAuth concepts • Secure SDLC • Vulnerability scanning (VAPT, SAST, DAST) • Secure file transfer mechanisms • Cloud security fundamentals (AWS preferred) Leadership &
- Judgment (This Matters More) • Strong decision-making under pressure • Willingness to say “No, this is not allowed” • Calm, authoritative communication with customers • Zero tolerance for shortcuts disguised as urgency Best Fit Profile This role is NOT for:
- Policy-only security people • Audit-only professionals • Compliance checkbox specialists This role IS ideal for someone who:
- Has seen security failures caused by human shortcuts • Understands how delivery teams actually behave • Can balance speed with discipline • Is comfortable being unpopular when needed Reporting &
- Authority • Reports directly to the CEO • Has authority to: o Block releases on security grounds o Enforce delivery security standards o Escalate non-compliance immediately Success Metrics (First 12 Months) • Zero repeat incidents from the same root cause • Clear reduction in customer-flagged security findings • Consistent, audit-ready release process • Increased customer confidence during security reviews

📌 Head - Security & Compliance (Faridabad)
🏢 Novelvox
📍 Faridabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: head - security & compliance (faridabad) / faridabad

Subscribe to this job alert:

Get the latest job offers by email for: head - security & compliance (faridabad) / faridabad