Role snapshot Accops is hiring a hands-on Head of Product Security to own the security of every product we ship from source code to customer incident response. India (remote-friendly;
Experience: 10+ years total, including 5+ years in hands-on security research / pen testing Background: Former software engineer turned security researcher Reports to CEO / CTO Leads the product security testing team Our customers trust us to sit at the edge of their networks, so the security of our own code is the product.
You will be the single owner of product security: you decide what gets tested, find the hard bugs before attackers do, lead the response when something goes wrong, and speak for Accops to customers when they ask how secure we are. Lead the security testing team Build, mentor and manage the product security / pen testing team; set hiring bar, career paths and quality standards. Own the security testing plan for every release across gateway, client (Windows, macOS, Linux, mobile), web portals and cloud services.
Secure code review and white-box testing Review source code personally (C/C++, .Net, Go, Python, JavaScript and others) for high-risk areas: authentication, crypto, VPN/tunnel handling, session management, privilege boundaries. Run white-box pen tests with full code and design access
- Embed SAST, DAST, SCA, fuzzing and secrets scanning into CI/CD, and tune them so engineers trust the results. Lead technical investigation of security incidents involving Accops products, in-house and at customer sites. Perform log, memory, disk and network forensics
- Vulnerability management and disclosure Own CVE assignment, security advisories and coordinated disclosure. Be the trusted security voice of Accops to customers: CISOs, bank and government security teams, and auditors. Write and present clear advisories,
incident reports and root-cause analyses for both technical and executive audiences. Answer security questionnaires, join customer calls during incidents, and handle tough conversations with calm and transparency. Brief the leadership team regularly on product security posture and risk. 10+ years of experience, starting as a software engineer who shipped production code, followed by 5+ years focused on security research and penetration testing. ~ Deep hands-on skill in source code review and white-box testing
- Solid command of network and application security: TLS/PKI, VPN and tunnelling, SSO (SAML, OIDC, OAuth), MFA, OWASP Top 10, API security. ~ Experience with exploit development and PoC writing
- Practical incident response and forensics experience: log analysis, memory and disk forensics, attacker timeline reconstruction. ~ Proven record of leading or mentoring a security testing team. ~ Excellent written and spoken English; has handled customer-facing security discussions, advisories or incident calls with senior stakeholders. ~ Background in ZTNA, VPN, VDI, identity or endpoint security products.
Experience with Windows kernel/driver, macOS or Linux client internals. Familiarity with Indian regulatory expectations (RBI, SEBI, CERT-In) and secure SDLC frameworks (OWASP SAMM, NIST SSDF). First 90 days: a clear map of the attack surface across all products, a prioritised risk backlog, and a team operating on agreed severity SLAs.
A public vulnerability disclosure policy and advisory process in place. Customers and auditors see Accops product security as a strength in deals and renewals. Own product security end to end at a company whose products protect critical enterprise and government access.
Work directly with the founders, with real authority to block a release on security grounds. Remote-friendly within India, with competitive pay.
📌 Head of Product Training (Pune)
🏢 Accops
📍 Pune