Senior Manager - Product Security
Xerox View all jobs
- India
- Permanent
- Full-time
- Lead and manage a team of Product Security and DevSecOps Engineers.
- Assist in the establishment of action plans, timetables, and outcome measurements.
- Supervise security projects associated with all SDL phases.
- Mentor and support engineers in creating scripts, frameworks, and tools for supply chain security
- Validate security requirements for firmware, cloud assets, web applications, mobile applications, and networks.
- Develop and maintain secure coding practices and security engineering standards for the development team.
- Perform threat modelling, security design reviews of application or products and define security requirements as part of SDL process.
- Track and report on product security metrics and communicate the security posture of products to stakeholders.
- Ensure comprehensive documentation of assessment findings and remediation recommendations.
- Communicate and collaborate effectively with engineering and other security teams.
- Coordinate and present operational briefings and presentations to non-technical audiences and executive management.
- Stay informed about the latest trends in cybersecurity, including new attack techniques and vulnerabilities.
- At least 4 years of experience in managing Product Security projects and teams and total of 10+ years of experience in cyber security domain.
- Strong written and verbal communication skills, with the ability to create clear documentation and effectively convey technical concepts.
- Highly organized and able to manage multiple projects simultaneously.
- Motivated team player with a sense of urgency and initiative.
- Strong understanding of common vulnerabilities, attack vectors and corresponding mitigation techniques
- Prior experience in performing secure code reviews/reviewing results of static analysis tools.
- Good understanding of Secure SDLC as well as development and integration of tools used as part of CI/CD process.
- Strong exposure to popular application security standards including OWASP TOP 10, etc.
- Proficiency with at least one of the programming languages desired: Java, .Net, C#, C, C++
- Prior software development experience is a plus.
- Uncompromising personal and professional integrity and ethics