Job DescriptionWhy Mizuho NAt Mizuho, we provide thestability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone. NnIt’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who share the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest banks in the world. NnSummary: NnMizuho is seeking a senior, hands-on Product Security Lead to drive security strategy across enterprise applications, platforms, cloud services, and software delivery ecosystems. This role is responsible for embedding secure-by-design and secure-by-default principles throughout the software development lifecycle while enabling engineering teams to deliver secure, resilient, and compliant solutions at scale. NnWorking closely with Engineering, Product, Cloud, Architecture, and Risk teams, you will lead security architecture, DevSecOps, cloud security, and software supply chain initiatives that reduce risk and strengthen cyber resilience. NnKeyResponsibilities: Nnn Define and execute Product & Platform Security strategy, standards, governance, and roadmaps across applications, APIs, cloud-native services, SaaS platforms, and shared technology ecosystems. N Lead security architecture reviews, threat modeling, secure SDLC practices, and risk-based security decision-making to ensure secure-by-design product development. N Establish secure engineering patterns and guardrails covering identity, access management, encryption, secrets management, logging, resilience, and cloud-native architectures. N Drive DevSecOps maturity by integrating automated security controls into CI/CD pipelines, application development, cloud platforms, containers, APIs, and infrastructure-as-code workflows. N Strengthen software supply chain security through governance of dependencies, artifacts, SBOMs, code provenance,
vulnerability management, and secure development practices. N Partner with Engineering, Cloud, Platform Security, and Vulnerability Management teams to reduce security risk, improve remediation outcomes, and operationalize security controls at scale. N Mentor security engineers and security champions while providing strategic guidance on security risks, technical debt, investment priorities, and emerging threats. NnnRequired Qualifications: Nnn 12+years of experience in Product Security, Application Security, Security Architecture, Cloud Security, DevSecOps, or related security engineering disciplines. N Demonstrated experienceleading Product Security, Application Security, or Secure Development programs across large-scale engineering organizations and complex technology environments. N Deep expertise in secure SDLC, threat modeling, application security, cloud security, software supply chain security, and security architecture. N Advise on security considerations for AI-enabled applications, generative AI solutions, machine learning platforms, and emerging technologies. N Strong knowledge of OWASP Top 10, OWASP API Security Top 10, distributed application security, modern attack techniques, and secure software engineering practices. N Experience reviewing application architectures, APIs, cloud platforms, Kubernetes environments, CI/CD pipelines, and Infrastructure-as-Code implementations. N Ability to assess implementations developed in Java, Python, Go, JavaScript, TypeScript, or similar modern programming languages. N Proven ability to influence engineering, architecture, and product teams to drive secure development practices and risk reduction without direct authority. N Strong leadership,
stakeholder management, risk assessment, communication, and influence skills. N Experience with contemporary Application Security, DevSecOps, Cloud Security, API Security, Software Supply Chain Security, Container Security, Kubernetes Security, Infrastructure-as-Code Security, and Security Testing technologies. NnnPreferred Qualifications: Nnn CISSP, CSSLP, CCSP, OSCP, OSWE, AWS Certified Security – Specialty, AZ-500, or equivalent N Experience supporting financial services or other highly regulated industries. N Experience implementingsecure-by-design programs, security champion initiatives, cloud-native security architectures, and developer security enablement programs. N Familiarity with NIST, CIS Controls, software supply chain frameworks, and cybersecurity regulatory requirements. NnnCompany Overview: NnMizuho Puneis an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, Mizuho Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions. NnMizuho Puneplays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control. NnMizuho Puneoffers competitive compensation and benefits package aligned with industry standards and local market practices. NnMizuho Puneis an equal opportunity employer and is committed to fostering an inclusive and diverse workplace. NnEmployment is subject to applicable background verification checks in accordance with Indian laws and company policies. Nnhttps://www.Mizuhogroup.Com/asia-pacific/mizuho-global-services/careers
📌 Senior Product Security Lead (Pune)
🏢 Mizuho
📍 Pune