29 Sep
|
HCLSoftware
|
Faridabad
29 Sep
HCLSoftware
Faridabad
Job DescriptionTitle: Product Information Security Officer NBand: E5 NLocation: Noida/Bangalore NRole OverviewnTheProduct Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture. NKey Responsibilitiesn1. Product Security Architecture & Design Nn Define and maintain product security architecture and threat models N Conduct threat modelingfor new features and systems N Lead security design reviews during product planning and architecture phases N Establish secure-by-default principles and baseline security controls N Review and approve authentication, authorization, and encryption strategies Nn2. Secure Development & Code Review Nn Establish secure coding standards and guidelines N Conduct security code reviews for high-risk features and components N Manage static application security testing (SAST) and dynamic testing (DAST) tools N Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment) N Partner with engineering to shift-left security and integrate security earlier in development Nn3. Vulnerability &Risk; Management Nn Coordinate vulnerability disclosure program N Manage product vulnerability lifecycle: triage, remediation, patch coordination N Track and prioritize security debt; negotiate remediation timelines with product & engineering N Maintain product risk register and escalate critical risks to CISO and executive leadership N Perform periodic risk assessments and penetration testing Nn4. Compliance & Regulatory Nn Interpret compliance requirements (SOC 2, ISO 27001, NIS2, GDPR, CCPA)
for product teams N Build compliance requirements into product roadmap early N Coordinate security evidence collection and audit readiness N Advise on data residency, encryption, and handling requirements N Partner with Legal and Compliance teams on privacy, data protection, and contractual security obligations Nn5. Security Culture & Engineering Education Nn Lead security training and awareness programs for engineering and product teams N Champion OWASP, CWE, and other security frameworks and best practices N Foster a culture of shared security responsibility; normalize security discussions N Mentor security engineers and junior team members Nn6. Incident Response & Post-Mortem Nn Lead response to security incidents affecting product N Coordinate fix validation and accelerated patch deployment N Conduct blameless security-focused post-mortems and publish lessons learned N Drive prevention of recurrence through architecture or process changes Nn7. Third-Party & Dependency Management Nn Manage vendor security assessments and risk evaluation N Define and implement software composition analysis (SCA) and dependency scanning N Establish supply chain security practices (sign, verify, binary authorization) N Evaluate security implications of new libraries, frameworks, and tools before adoption Nn8. Security Metrics & Reporting Nn Define and track product security KPIs (MTTR, vulnerability density, code coverage, etc.) N Produce monthly/quarterly security dashboards for product, engineering, and leadership N Report to Product Leadership and CISO organization NnRequired Qualifications NEducation & Certifications: Nn BS in Computer Science, Information Security, or equivalent professional experience N CISSP, CCSK, or equivalent security certification NnExperience:
Nn 10+ years in information security, with 5+ years in product security or application security roles N Demonstrated experienceshipping secure SaaS products at scale N Experience with threat modelling, secure SDLC, and vulnerability management N Hands-on experience with security testing tools (SAST, DAST, IAST, SCA) N Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, etc.) NnTechnical Skills: Nn Deep understanding of application security, network security, and cryptography N Proficiency with securecoding practices (OWASP Top 10, CWE, etc.) N Familiarity with moderndevelopment practices (CI/CD, containerization, microservices, cloud Nnplatforms)n N Ability to read and understand code; ideally hands-on codingability in common languages N Experience with security architecture and design patterns NnSoft Skills: Nn Excellent communication; ability to explain security concepts to non-technical audiences N Ability to influence without authority; strong stakeholder management N Collaborative mindset; comfortable working with product, engineering, and business teams N Strategic thinker with attention to detail and solid project management skills N Comfort with ambiguity and competing priorities; ability to prioritize ruthlessly NnPreferred Qualifications Nn OSCP (Offensive Security Certified Professional) or similar hands-on penetration testing cert N Background in product management or start-up/scaling experience N Published security research, conference talks, or open-source security contributions NnSecurity-Focused KPIs & Metrics NVulnerability & Risk Management: Nn Mean Time To Remediate (MTTR) for critical vulnerabilities N Mean Time To Remediate (MTTR) for high vulnerabilities N Number of vulnerabilities discovered post-release N Active security debt items tracked and prioritized in roadmap N Security architecture improvements: # of systems transitioned to secure-by-design patterns N
📌 Product Information Security Officer (Faridabad)
🏢 HCLSoftware
📍 Faridabad