22 Sep
|
HCLSoftware
|
India
Title: Product Information Security Officer
Band: E5
Location: Noida/Bangalore
Role Overview
The Product Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture.
Key Responsibilities
Product Security Architecture & Design
Define and maintain product security architecture and threat models
Conduct threat modeling for recent features and systems
Lead security design reviews during product planning and architecture phases
Establish secure-by-default principles and baseline security controls
Review and approve authentication, authorization, and encryption strategies
Secure Development & Code Review
Establish secure coding standards and guidelines
Conduct security code reviews for high-risk features and components
Manage static application security testing (SAST) and agile testing (DAST) tools
Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment)
Partner with engineering to shift-left security and integrate security earlier in development
Vulnerability & Risk Management
Coordinate vulnerability disclosure program
Manage product vulnerability lifecycle: triage, remediation, patch coordination
Track and prioritize security debt;
negotiate remediation timelines with product & engineering
Maintain product risk register and escalate critical risks to CISO and executive leadership
Perform periodic risk assessments and penetration testing
Compliance & Regulatory
Interpret compliance requirements (SOC 2, ISO 27001, NIS2, GDPR, CCPA) for product teams
Build compliance requirements into product roadmap early
Coordinate security evidence collection and aud
📌 Information Security Lead Noida (India)
🏢 HCLSoftware
📍 India