09 Oct
|
Grant Thornton
|
Kolkata
09 Oct
Grant Thornton
Kolkata
About Grant Thornton INDUS:
Grant Thornton INDUS is the in-house offshore center for Grant Thornton US, with offices in Bangalore and Kolkata. Our professionals specialize in Tax, Audit, Advisory, Operations, and Enabling functions, delivering exceptional client service and driving excellence across domains. We are committed to building a high-trust, high-performance culture.
Role & responsibilities
- Product Security Lead Security-by-Design practices across product strategy, architecture, development, release, and operational lifecycles.
- Conduct and oversee threat modeling, security architecture reviews, and product risk assessments for applications, APIs, cloud-native platforms, and AI-enabled solutions.
- Establish product-security standards, governance processes, security requirements, threat-modeling practices, and security metrics across the product portfolio.
- Drive risk-based decisions regarding vulnerabilities, product-security incidents, software-supply-chain security, and secure product operations in partnership with Product and Engineering leadership.
2. Security Assurance & Testing Governance
- Define and govern the organizations application and product-security assurance strategy, including SAST, DAST, SCA, API security testing, penetration testing, and AI security assessments.
- Establish risk-based testing requirements, onboarding standards, security-coverage models, and secure-development assurance processes across products and platforms.
- Review, challenge, and communicate security-assessment results to Product, Engineering, and executive stakeholders, ensuring security risks are understood and prioritized.
- Drive remediation planning, risk-treatment decisions, exception management, and accountability with product teams through closure.
3. Security Tooling, Vulnerability & Risk Governance
- Establish governance and operating models for application-security tooling, vulnerability management, security metrics, and risk reporting.
- Oversee vulnerability identification, prioritization, remediation strategies, compensating controls, and risk-acceptance processes across the product portfolio.
- Partner with Product, Engineering, and Security teams to communicate findings, coordinate remediation activities, remove blockers,
and improve security outcomes.
- Analyze vulnerability trends, recurring control gaps, and systemic risks while driving long-term improvements across products and development practices.
4. Product Security & Secure SDLC
- Partner with Product, Engineering, Architecture, and DevOps teams to embed security requirements throughout the Software Development Lifecycle.
- Conduct application and product-security risk assessments, architecture reviews, and security-design evaluations for new and existing products.
- Define security requirements, standards, reference architectures, and secure-development practices that enable scalable and secure product delivery.
- Communicate security findings, recommendations, and risk decisions while driving remediation and Secure-by-Design adoption across engineering teams.
5. AI Security & Agentic AI Security
- Lead security assessments and threat evaluations for AI-enabled products, AI-native platforms, foundation-model integrations, and agentic AI solutions.
- Review AI architectures, data flows, access controls, model interactions, tool integrations, agent permissions, and autonomous capabilities to identify risks and control gaps.
- Define AI-security requirements, governance standards, and mitigation strategies addressing AI, ML, GenAI, and agentic-technology risks.
- Communicate AI-security findings and remediation requirements to Product, Engineering, Data, and AI teams while ensuring appropriate ownership and risk treatment.
Preferred Skills
- Strong expertise across Product Security, Application Security, Security Architecture, Cloud Security, AI Security, Technology Risk, and related disciplines.
- Demonstrated ownership of product or application-security risk across the full lifecycle, from concept and architecture through release, operation, vulnerability response, and material change.
- Expertise in strategic risk assessments, architecture and design reviews, threat modeling, and risk-based release-readiness decisions.
- Sound understanding of modern SaaS, cloud-native, API-led, microservices, data-platform, and distributed architectures.
- Practical knowledge of SAST, DAST, SCA, API security testing, penetration testing, vulnerability management, CI/CD security, and software-supply-chain controls.
- Experience securing AI-enabled systems or depth in AI-security architecture, AI-risk assessment, agentic security, model and data controls, and AI evaluation.
- Ability to translate complex technical conditions into clear business risk, decision options, and accountable actions for senior stakeholders.
- Experience influencing Product and Engineering organizations and coordinating specialists across multiple security and risk domains.
Qualification/Experience
- 12+ years of relevant experience across Product Security, Application Security, Security Architecture, Cloud Security, AI Security, Technology Risk, or related disciplines, including leadership of complex cross-functional security outcomes.
- Bachelors degree in Computer Science, Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
Grant Thornton INDUS (Full-Time Employee) Benefits:
Insurance: Group Health, Accidental, and Term Life Insurance for employees and dependents, as applicable.
Wellness: Employee Assistance Program, corporate health plans, gym access in Bangalore, wellness webinars, and health-month initiatives.
Work-Life Balance: Hybrid work model and flexible work options for returning mothers.
Parental Support: Maternity and paternity leave, daycare facilities, and flexible work arrangements.
Mobility: Secondment opportunities, relocation benefits, and internal job postings.
Retirement: Provident Fund, Gratuity, Leave Encashment, and National Pension Scheme.
Extra benefits: Womens-security transport arrangements, home-office setup allowance, certification reimbursements, meal cards, appreciation holidays, and service awards.
Learning: Multi-channel in-house learning platform, LinkedIn Learning, and certification programs.
📌 Product, Application & AI Security (Kolkata)
🏢 Grant Thornton
📍 Kolkata