
Application Security Manager (Technical Lead)
- Bangalore, Karnataka
- Permanent
- Part-time
- Design and lead our technical application security strategy, focusing on automation, cloud-native security, and secure software development.
- Manage the local application security team and align them with the broader goals of the global Application Security organization.
- Drive adoption and integration of SAST, DAST, SCA, IaC security, container scanning, RASP, and secret scanning tools.
- Build and enhance automation pipelines that support real-time vulnerability detection and remediation across our development lifecycle.
- Lead the Developer Security Champion program, engaging and mentoring engineers across the business to create a security-first culture.
- Collaborate with DevOps and SRE teams to design secure, scalable cloud infrastructure and application deployment models.
- Translate security requirements into actionable tooling, architecture, and secure coding practices.
- Support security initiatives related to AI/ML-driven development, model security, and responsible use of AI in software.
- Continuously evolve AppSec KPIs and metrics to track risk, compliance, and team effectiveness.
- Significant hands-on experience (7+ years) in application security, software engineering, or DevSecOps.
- Solid development background - ideally in Java and JavaScript.
- Proven experience implementing and managing AppSec tooling (SAST, DAST, SCA, IaC, RASP, secrets detection).
- Deep knowledge of cloud environments (Azure, AWS, GCP) and cloud-native security principles.
- Strong background in building and securing infrastructure using Infrastructure as Code (e.g., Terraform, ARM).
- Experience supporting and securing modern application architectures including containers and microservices.
- Familiarity with OWASP Top 10, threat modeling, and secure design patterns.
- Exceptional communication and cross-functional collaboration skills; you're comfortable working across Dev, Ops, and Security organizations.
- Experience mentoring or managing a team and running security champion initiatives is a big plus.
- Industry certifications (e.g., OSWE, GSSP, CISSP, CSSLP) are desirable.