IncubXperts TechnoConsulting Pvt Ltd

Head of Application Security & DevSecOps

IncubXperts TechnoConsulting Pvt Ltd Pune City Subdistrict, Maharashtra, India

Software Development · 51-200 employees

Oct 01
Remote security Senior (5-10 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Head of Application Security & DevSecOps is responsible for integrating security into the software development lifecycle and managing application security practices. This role involves implementing security controls, managing vulnerabilities, and partnering with engineering teams to improve security awareness.

What they look for

Application Security DevSecOps Secure SDLC Threat Modeling SAST DAST SCA Secrets Scanning CI/CD Vulnerability Management Software Supply-chain Security Secure Coding Standards Cloud Architecture API Security Automation Security Metrics

Requirements

Candidates must have 7+ years of experience in application security, DevSecOps, or software engineering. A strong understanding of modern application, API, and cloud architectures, along with hands-on experience in CI/CD and security tooling, is required.

Full description

Role Overview

The Head of Application Security & DevSecOps is responsible for integrating security into the organization's software development and technology delivery processes. This role partners directly with Engineering to build security into the development lifecycle rather than relying primarily on post-development security reviews.

Key Responsibilities

  • Own application and API security

practices.

  • Establish and mature the Secure

SDLC.

  • Conduct and facilitate threat

modeling.

  • Implement and manage SAST, DAST,

SCA and secrets scanning capabilities.

  • Integrate security controls into

CI/CD pipelines.

  • Manage application vulnerabilities

and remediation.

  • Address open-source, dependency

and software supply-chain risk.

  • Establish secure coding standards

and developer security practices.

  • Define security requirements for

production access and deployments.

  • Partner directly with U.S. and

offshore Engineering teams.

  • Improve developer security

awareness and adoption.

  • Automate application security

testing and remediation workflows.

  • Establish meaningful application

security metrics and reporting.

Requirements

Candidate Requirements

  • 7+ years of application security,

DevSecOps, software engineering or cybersecurity experience.

  • Strong understanding of modern

application, API and cloud architectures.

  • Hands-on experience with CI/CD and

application security tooling.

  • Experience working directly with

software engineering teams.

  • Strong understanding of software

supply-chain and dependency risk.

  • Ability to translate security

requirements into practical engineering solutions.

  • Financial services, fintech or

regulated-industry experience preferred.

  • Remote- US Shift

Similar roles