NCR Atleos

Application Security Compliance Lead

NCR Atleos Gurgaon, Haryana, India

Banking · 10,001+ employees

19 h ago
security Senior (5-10 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will govern the secure software development lifecycle and ensure compliance with PCI Software Security Framework standards. This involves interpreting complex security requirements and guiding product teams through assessments and remediation processes.

What they look for

Application Security Compliance PCI SSF Secure SDLC Risk Management Vulnerability Management Security Testing Threat Modelling Cloud Services CI/CD Stakeholder Management Communication Analytical Skills Problem Solving Privacy Audit

Requirements

Candidates should have at least 7 years of experience in application security, compliance, or software assurance. A bachelor's degree in a STEM discipline is required, along with strong knowledge of security frameworks and risk-based decision-making.

Full description

About NCR Atleos

NCR Atleos, headquartered in Atlanta, is a leader in expanding financial access. Our dedicated 20,000 employees optimize the branch, improve operational efficiency and maximize self-service availability for financial institutions and retailers across the globe.

Title: Application Security Compliance Lead

Location: Gurgaon or Hyderabad, India

About NCR Atleos 

NCR Atleos Corporation (NYSE: NATL) is a global technology company that enables financial access and commerce through assisted and self-service solutions and comprehensive support services. NCR Atleos serves financial and public-sector organizations in more than 100 countries and is headquartered in Atlanta, Georgia, USA. 

The opportunity 

As an Application Security Compliance Specialist, you will help ensure that NCR Atleos software products and development practices meet applicable security, privacy and regulatory requirements. Working within our global Application Security team, you will turn complex requirements into practical guidance, prepare teams for assessments, and help demonstrate that security and privacy are embedded throughout the software lifecycle. 

A major focus is organization-level PCI Software Security Framework (SSF) activities: support product teams to achieve and retain PCI Secure Software Standard listings and maintain validation of our Secure Software Lifecycle practices. This role suits someone who combines compliance expertise with software development and application security knowledge.

What you will do 

  • Govern the Secure SDLC. Maintain and improve practices aligned with the PCI Secure SLC Standard. 
  • Enable PCI SSF validation. Guide teams through external assessment, self-assessment, annual attestation and periodic revalidation activities. 
  • Interpret requirements. Translate security, privacy, legal and industry requirements into clear, proportionate guidance. 
  • Assess readiness and close gaps. Coordinate reviews, evidence, gap analysis, remediation and resolution of findings. 
  • Engage and influence. Partner with engineering, Legal, risk, compliance and security teams, QSAs and the PCI SSC. 
  • Build capability. Create training and reusable guidance; monitor developments and communicate material changes. 
  • Drive continual improvement. Use industry changes, stakeholder feedback, internal audits, assessment outcomes, recurring findings, and incidents to strengthen controls and processes. 

What you will bring 

Essential experience and capabilities 

  • Typically, 7+ years of relevant experience in application security, software security assurance, secure software development, technology risk, privacy, compliance, or audit. 
  • Practical experience developing, operating, governing or assessing a Secure SDLC. 
  • Experience interpreting security or compliance requirements and supporting assessments, evidence collection, gap analysis and remediation. 
  • Working knowledge of threat modelling, vulnerability management, security testing, and risk-based decision-making. 
  • Technical understanding of cloud services, source-code management, and CI/CD practices sufficient to engage credibly with engineering teams. 
  • Ability to convert complex requirements into pragmatic guidance and make evidence-based recommendations. 
  • Strong stakeholder management, communication, analytical and problem-solving skills, including the ability to influence without direct authority. 
  • Ability to work independently and effectively within a globally distributed team. 
  • Comfortable using AI assistants, such as Copilot, responsibly in day-to-day work to improve personal productivity, quality, and speed of delivery. 
  • A bachelor’s degree in a STEM discipline, or equivalent relevant professional experience and qualifications. 

Desirable experience and capabilities 

  • Direct experience of PCI SSF validation or a comparable software security assurance framework. 
  • Knowledge of payment-card security, GDPR requirements, NIST CSF and OWASP standards and guidance. 
  • Experience delivering application security or compliance-related training. 
  • Knowledge of security and governance for AI-enabled software development and products. 
  • A relevant certification, such as CISSP, CSSLP, CIPP, CIPT or CIPM. 

 

How you will succeed 

  • Teams receive clear, timely, and actionable compliance guidance. 
  • PCI SSF validation activities are well planned, appropriately evidenced, and progressed effectively. 
  • Compliance gaps and findings are clearly owned, prioritized, tracked, and resolved. 
  • Secure SDLC requirements remain practical, current, and consistently understood. 
  • Assessment and incident lessons lead to sustainable improvements and strong stakeholder relationships. 

Evidence we value

In your application, we would particularly welcome examples of how you have interpreted a security standard, prepared a product or organization for assessment, resolved a significant compliance gap, or influenced an engineering team to adopt a more effective security practice. 

Offers of employment are conditional upon passage of screening criteria applicable to the job.

EEO Statement NCR Atleos is an equal-opportunity employer. It is NCR Atleos policy to hire, train, promote, and pay associates based on their job-related qualifications, ability, and performance, without regard to race, color, creed, religion, national origin, citizenship status, sex, sexual orientation, gender identity/expression, pregnancy, marital status, age, mental or physical disability, genetic information, medical condition, military or veteran status, or any other factor protected by law.

Statement to Third Party Agencies

To ALL recruitment agencies: NCR Atleos only accepts resumes from agencies on the NCR Atleos preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Atleos employees, or any NCR Atleos facility. NCR Atleos is not responsible for any fees or charges associated with unsolicited resumes.

Similar roles