Head of Application Security & DevSecOps
IncubXperts TechnoConsulting Pvt Ltd Pune City Subdistrict, Maharashtra, India
Software Development · 51-200 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Head of Application Security & DevSecOps is responsible for integrating security into the software development lifecycle and managing application security practices. This role involves implementing security controls, managing vulnerabilities, and partnering with engineering teams to improve security awareness.
What they look for
Requirements
Candidates must have 7+ years of experience in application security, DevSecOps, or software engineering. A strong understanding of modern application, API, and cloud architectures, along with hands-on experience in CI/CD and security tooling, is required.
Full description
Role Overview
The Head of Application Security & DevSecOps is responsible for integrating security into the organization's software development and technology delivery processes. This role partners directly with Engineering to build security into the development lifecycle rather than relying primarily on post-development security reviews.
Key Responsibilities
- Own application and API security
practices.
- Establish and mature the Secure
SDLC.
- Conduct and facilitate threat
modeling.
- Implement and manage SAST, DAST,
SCA and secrets scanning capabilities.
- Integrate security controls into
CI/CD pipelines.
- Manage application vulnerabilities
and remediation.
- Address open-source, dependency
and software supply-chain risk.
- Establish secure coding standards
and developer security practices.
- Define security requirements for
production access and deployments.
- Partner directly with U.S. and
offshore Engineering teams.
- Improve developer security
awareness and adoption.
- Automate application security
testing and remediation workflows.
- Establish meaningful application
security metrics and reporting.
Requirements
Candidate Requirements
- 7+ years of application security,
DevSecOps, software engineering or cybersecurity experience.
- Strong understanding of modern
application, API and cloud architectures.
- Hands-on experience with CI/CD and
application security tooling.
- Experience working directly with
software engineering teams.
- Strong understanding of software
supply-chain and dependency risk.
- Ability to translate security
requirements into practical engineering solutions.
- Financial services, fintech or
regulated-industry experience preferred.
- Remote- US Shift
Similar roles
-
Information Systems Security Engineer
MANTECH Crane, Indiana, United States
-
Business Developer:in Defence (Naval & Cybersecurity) (m/w/d) | Deutschland
CONCAPE Germany
-
Telematics Cybersecurity
Daimler Truck Sriperumbudur, Tamil Nadu, India
-
Network & Security Engineer (Fortinet) (REF5857V)
Deutsche Telekom IT Solutions Budapest, Central Hungary, Hungary
-
Cybersecurity Threat Researcher (Position located in Cheltenham, United Kingdom)
KnowBe4 Cheltenham, England, United Kingdom
-
Expert Application Security Specialist (IAM)
OPTIVEUM sp. z o.o. Łódź, Łódź Voivodeship, Poland · PLN 293K/yr