01 Oct
|
HCLSoftware
|
Faridabad
01 Oct
HCLSoftware
Faridabad
Job DescriptionTitle: Product Information Security Officer
NBand: E5
NLocation: Noida/Bangalore
NRole Overview
nTheProduct Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture.
NKey Responsibilities
n1. Product Security Architecture & Design
N
n
- Define and maintain product security architecture and threat models
N
- Conduct threat modelingfor recent features and systems
N
- Lead security design reviews during product planning and architecture phases
N
- Establish secure-by-default principles and baseline security controls
N
- Review and approve authentication, authorization, and encryption strategies
N
n2. Secure Development & Code Review
N
n
- Establish secure coding standards and guidelines
N
- Conduct security code reviews for high-risk features and components
N
- Manage static application security testing (SAST) and dynamic testing (DAST) tools
N
- Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment)
N
- Partner with engineering to shift-left security and integrate security earlier in development
N
n3. Vulnerability &Risk; Management
N
n
- Coordinate vulnerability disclosure program
N
- Manage product vulnerability lifecycle: triage, remediation, patch coordination
N
- Track and prioritize security debt;
negotiate remediation timelines with product & engineering
N
- Maintain product risk register and escalate critical risks to CISO and executive leadership
N
- Perform periodic risk assessments and penetration testing
N
n4. Compliance & Regulatory
N
n
- Interpret compliance requirements (SOC 2, ISO 27001, NIS2, GDPR, CCPA) for product teams
N
- Build compliance requirements into product roadmap early
N
- Coordinate security evidence collection and audit readiness
N
- Advise on data residency,
encryption, and handling requirements
N
- Partner with Legal and Compliance teams on privacy, data protection, and contractual security obligations
N
n5. Security Culture & Engineering Education
N
n
- Lead security training and awareness programs for engineering and product teams
N
- Champion OWASP, CWE, and other security frameworks and best practices
N
- Foster a culture of shared security responsibility;
normalize security discussions
N
- Mentor security engineers and junior team members
N
n6. Incident Response & Post-Mortem
N
n
- Lead response to security incidents affecting product
N
- Coordinate fix validation and accelerated patch deployment
N
- Conduct blameless security-focused post-mortems and publish lessons learned
N
- Drive prevention of recurrence through architecture or process changes
N
n7. Third-Party & Dependency Management
N
n
- Manage vendor security assessments and risk evaluation
N
- Define and implement software composition analysis (SCA) and dependency scanning
N
- Establish supply chain security practices (sign, verify, binary authorization)
N
- Evaluate security implications of new libraries, frameworks, and tools before adoption
N
n8. Security Metrics & Reporting
N
n
- Define and track product security KPIs (MTTR, vulnerability density, code coverage, etc.)
N
- Produce monthly/quarterly security dashboards for product, engineering, and leadership
N
- Report to Product Leadership and CISO organization
N
nRequired Qualifications
NEducation & Certifications:
N
n
- BS in Computer Science, Information Security, or equivalent qualified experience
N
- CISSP, CCSK, or equivalent security certification
N
nExperience:
N
n
- 10+ years in information security, with 5+ years in product security or application security roles
N
- Demonstrated experienceshipping secure SaaS products at scale
N
- Experience with threat modelling, secure SDLC, and vulnerability management
N
- Hands-on experience with security testing tools (SAST, DAST, IAST, SCA)
N
- Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, etc.)
N
nTechnical Skills:
N
n
- Deep understanding of application security, network security, and cryptography
N
- Proficiency with securecoding practices (OWASP Top 10, CWE, etc.)
N
- Familiarity with moderndevelopment practices (CI/CD, containerization, microservices, cloud
N
nplatforms)
n
N
- Ability to read and understand code;
ideally hands-on codingability in common languages
N
- Experience with security architecture and design patterns
N
nSoft Skills:
N
n
- Excellent communication;
ability to explain security concepts to non-technical audiences
N
- Ability to influence without authority;
strong stakeholder management
N
- Collaborative mindset;
comfortable working with product, engineering, and business teams
N
- Strategic thinker with attention to detail and strong project management skills
N
- Comfort with ambiguity and competing priorities;
ability to prioritize ruthlessly
N
nPreferred Qualifications
N
n
- OSCP (Offensive Security Certified Professional) or similar hands-on penetration testing cert
N
- Background in product management or start-up/scaling experience
N
- Published security research, conference talks, or open-source security contributions
N
nSecurity-Focused KPIs & Metrics
NVulnerability & Risk Management:
N
n
- Mean Time To Remediate (MTTR) for critical vulnerabilities
N
- Mean Time To Remediate (MTTR) for high vulnerabilities
N
- Number of vulnerabilities discovered post-release
N
- Active security debt items tracked and prioritized in roadmap
N
- Security architecture improvements: # of systems transitioned to secure-by-design patterns
N
📌 Product Information Security Officer (Faridabad)
🏢 HCLSoftware
📍 Faridabad