19 Sep
|
HCLSoftware
|
Noida
Job Description
Title: Product Information Security Officer
n
Band: E5
n
Location: Noida/Bangalore
n
Role Overview
n
The Product Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture.
n
Key Responsibilities
n
1. Product Security Architecture & Design
n
n
- Define and maintain product security architecture and threat models
n
- Conduct threat modeling for new features and systems
n
- Lead security design reviews during product planning and architecture phases
n
- Establish secure-by-default principles and baseline security controls
n
- Review and approve authentication, authorization, and encryption strategies
n
n
2. Secure Development & Code Review
n
n
- Establish secure coding standards and guidelines
n
- Conduct security code reviews for high-risk features and components
n
- Manage static application security testing (SAST) and dynamic testing (DAST) tools
n
- Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment)
n
- Partner with engineering to shift-left security and integrate security earlier in development
n
n
3. Vulnerability & Risk Management
n
n
- Coordinate vulnerability disclosure program
n
- Manage product vulnerability lifecycle: triage, remediation, patch coordination
n
- Track and prioritize security debt; negotiate remediation timelines with product & engineering
n
- Maintain product risk register and escalate critical risks to CISO and executive leadership
n
- Perform periodic risk assessments and penetration testing
n
n
4. Compliance & Regulatory
n
n
- Interpret compliance requirements (SOC 2, ISO 27001, NIS2, GDPR, CCPA) for product teams
n
- Build compliance requirements into product roadmap early
n
- Coordinate security evidence collection and audit readiness
n
- Advise on data residency, encryption, and handling requirements
n
- Partner with Legal and Compliance teams on privacy, data protection, and contractual security obligations
n
n
5. Security Culture & Engineering Education
n
n
- Lead security training and awareness programs for engineering and product teams
n
- Champion OWASP, CWE, and other security frameworks and best practices
n
- Foster a culture of shared security responsibility; normalize security discussions
n
- Mentor security engineers and junior team members
n
n
6. Incident Response & Post-Mortem
n
n
- Lead response to security incidents affecting product
n
- Coordinate fix validation and accelerated patch deployment
n
- Conduct blameless security-focused post-mortems and publish lessons learned
n
- Drive prevention of recurrence through architecture or process changes
n
n
7. Third-Party & Dependency Management
n
n
- Manage vendor security assessments and risk evaluation
n
- Define and implement software composition analysis (SCA) and dependency scanning
n
- Establish supply chain security practices (sign, verify, binary authorization)
n
- Evaluate security implications of new libraries, frameworks, and tools before adoption
n
n
8. Security Metrics & Reporting
n
n
- Define and track product security KPIs (MTTR, vulnerability density, code coverage, etc.)
n
- Produce monthly/quarterly security dashboards for product, engineering, and leadership
n
- Report to Product Leadership and CISO organization
n
n
Required Qualifications
n
Education & Certifications:
n
n
- BS in Computer Science, Information Security, or equivalent skilled experience
n
- CISSP, CCSK, or equivalent security certification
n
n
Experience:
n
n
- 10+ years in information security, with 5+ years in product security or application security roles
n
- Demonstrated experience shipping secure SaaS products at scale
n
- Experience with threat modelling, secure SDLC, and vulnerability management
n
- Hands-on experience with security testing tools (SAST, DAST, IAST, SCA)
n
- Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, etc.)
n
n
Technical Skills:
n
n
- Deep understanding of application security, network security, and cryptography
n
- Proficiency with secure coding practices (OWASP Top 10, CWE, etc.)
n
- Familiarity with modern development practices (CI/CD, containerization, microservices, cloud
n
n
platforms)
n
n
- Ability to read and understand code; ideally hands-on coding ability in common languages
n
- Experience with security architecture and design patterns
n
n
Soft Skills:
n
n
- Excellent communication; ability to explain security concepts to non-technical audiences
n
- Ability to influence without authority; strong stakeholder management
n
- Collaborative mindset; comfortable working with product, engineering, and business teams
n
- Strategic thinker with attention to detail and strong project management skills
n
- Comfort with ambiguity and competing priorities; ability to prioritize ruthlessly
n
n
Preferred Qualifications
n
n
- OSCP (Offensive Security Certified Professional) or similar hands-on penetration testing cert
n
- Background in product management or start-up/scaling experience
n
- Published security research, conference talks, or open-source security contributions
n
n
Security-Focused KPIs & Metrics
n
Vulnerability & Risk Management:
n
n
- Mean Time To Remediate (MTTR) for critical vulnerabilities
n
- Mean Time To Remediate (MTTR) for high vulnerabilities
n
- Number of vulnerabilities discovered post-release
n
- Active security debt items tracked and prioritized in roadmap
n
- Security architecture improvements: # of systems transitioned to secure-by-design patterns
n
📌 Product Information Security Officer (Noida)
🏢 HCLSoftware
📍 Noida