27 Sep
|
HCLSoftware
|
Noida
Title: Product Information Security Officer Band: E5 The Product Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture.
Lead security design reviews during product planning and architecture phases • Establish secure coding standards and guidelines • Conduct security code reviews for high-risk features and components • Manage static application security testing (SAST) and dynamic testing (DAST) tools • Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment)
- Partner with engineering to shift-left security and integrate security earlier in development Vulnerability & Risk Management • Maintain product risk register and escalate critical risks to CISO and executive leadership • Perform periodic risk assessments and penetration testing Compliance & Regulatory • Coordinate security evidence collection and audit readiness • Advise on data residency, encryption, and handling requirements • Partner with Legal and Compliance teams on privacy, data protection,
and contractual security obligations Lead security training and awareness programs for engineering and product teams • Coordinate fix validation and accelerated patch deployment • Manage vendor security assessments and risk evaluation • Define and implement software composition analysis (SCA) and dependency scanning • Report to Product Leadership and CISO organization BS in Computer Science, Information Security, or equivalent professional experience • Experience:
- 10+ years in information security, with 5+ years in product security or application security roles • Demonstrated experience shipping secure SaaS products at scale • Experience with threat modelling, secure SDLC, and vulnerability management • Hands-on experience with security testing tools (SAST, DAST, IAST, SCA)
- Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, etc.) Deep understanding of application security, network security, and cryptography • Proficiency with secure coding practices (OWASP Top 10, CWE, etc.)
- Familiarity with modern development practices (CI/CD, containerization, microservices, cloud ideally hands-on coding ability in common languages • Experience with security architecture and design patterns ability to explain security concepts to non-technical audiences • Strategic thinker with attention to detail and strong project management skills • OSCP (Offensive Security Certified Skilled) or similar hands-on penetration testing cert • Background in product management or start-up/scaling experience • Vulnerability & Risk Management: •
📌 Information Security Manager, hibrido (Noida)
🏢 HCLSoftware
📍 Noida