18 Sep
|
HCLSoftware
|
Noida
Title: Product Information Security OfficerBand: E5Location: Noida/BangaloreRole OverviewThe Product Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture.Key Responsibilities1. Product Security Architecture & Design
- Define and maintain product security architecture and threat models
- Conduct threat modeling for new features and systems
- Lead security design reviews during product planning and architecture phases
- Establish secure-by-default principles and baseline security controls
- Review and approve authentication, authorization, and encryption strategies2. Secure Development & Code Review
- Establish secure coding standards and guidelines
- Conduct security code reviews for high-risk features and components
- Manage static application security testing (SAST) and energetic testing (DAST) tools
- Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment)
- Partner with engineering to shift-left security and integrate security earlier in development3. Vulnerability & Risk Management
- Coordinate vulnerability disclosure program
- Manage product vulnerability lifecycle: triage, remediation, patch coordination
- Track and prioritize security debt; negotiate remediation timelines with product & engineering
- Maintain product risk register and escalate critical risks to CISO and executive leadership
- Perform periodic risk assessments and penetration testing4. Compliance & Regulatory
- Interpret compliance requirements (SOC 2, ISO 27001, NIS2, GDPR, CCPA) for product teams
- Build compliance requirements into product roadmap early
- Coordinate security evidence collection and audit readiness
- Advise on data residency,
encryption, and handling requirements
- Partner with Legal and Compliance teams on privacy, data protection, and contractual security obligations5. Security Culture & Engineering Education
- Lead security training and awareness programs for engineering and product teams
- Champion OWASP, CWE, and other security frameworks and best practices
- Foster a culture of shared security responsibility; normalize security discussions
- Mentor security engineers and junior team members6. Incident Response & Post-Mortem
- Lead response to security incidents affecting product
- Coordinate fix validation and accelerated patch deployment
- Conduct blameless security-focused post-mortems and publish lessons learned
- Drive prevention of recurrence through architecture or process changes7. Third-Party & Dependency Management
- Manage vendor security assessments and risk evaluation
- Define and implement software composition analysis (SCA) and dependency scanning
- Establish supply chain security practices (sign, verify, binary authorization)
- Evaluate security implications of new libraries, frameworks, and tools before adoption8. Security Metrics & Reporting
- Define and track product security KPIs (MTTR, vulnerability density, code coverage, etc.)
- Produce monthly/quarterly security dashboards for product, engineering, and leadership
- Report to Product Leadership and CISO organizationRequired QualificationsEducation & Certifications:
- BS in Computer Science, Information Security, or equivalent skilled experience
- CISSP, CCSK, or equivalent security certificationExperience:
- 10+ years in information security, with 5+ years in product security or application security roles
- Demonstrated experience shipping secure SaaS products at scale
- Experience with threat modelling, secure SDLC, and vulnerability management
- Hands-on experience with security testing tools (SAST, DAST, IAST, SCA)
- Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, etc.)Technical Skills:
- Deep understanding of application security, network security, and cryptography
- Proficiency with secure coding practices (OWASP Top 10, CWE, etc.)
- Familiarity with modern development practices (CI/CD, containerization, microservices, cloud platforms)
- Ability to read and understand code; ideally hands-on codingability in common languages
- Experience with security architecture and design patternsSoft Skills:
- Excellent communication; ability to explain security concepts to non-technical audiences
- Ability to influence without authority; strong stakeholder management
- Collaborative mindset; comfortable working with product, engineering, and business teams
- Strategic thinker with attention to detail and strong project management skills
- Comfort with ambiguity and competing priorities; ability to prioritize ruthlesslyPreferred Qualifications
- OSCP (Offensive Security Certified Professional) or similar hands-on penetration testing cert
- Background in product management or start-up/scaling experience
- Published security research, conference talks, or open-source security contributions Security-Focused KPIs & MetricsVulnerability & Risk Management:
- Mean Time To Remediate (MTTR) for critical vulnerabilities
- Mean Time To Remediate (MTTR) for high vulnerabilities
- Number of vulnerabilities discovered post-release
- Active security debt items tracked and prioritized in roadmap
- Security architecture improvements: # of systems transitioned to secure-by-design patterns
📌 Product Information Security Officer (Noida)
🏢 HCLSoftware
📍 Noida