Manager - Product Security
BengaluruFull-timePosted Jul 20, 2026
PRINCIPAL DUTIES AND RESPONSIBILITIES:
- Assist in the day-to-day management of the Product Security program, providing secure development and application security services across multiple product and engineering teams. This includes secure SDLC implementation, application security monitoring, vulnerability management, threat modeling, and security policy enforcement.
- Define and track key program metrics, including Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs), to measure the effectiveness of the Product Security program and assess product and application security risks across the organization.
- Partner with engineering, architecture, DevOps, cloud, and business stakeholders to embed security controls, automate policy enforcement, and identify opportunities for secure technology integrations within product ecosystems.
- Collaborate with third-party vendors and internal teams to conduct application security assessments, penetration testing, secure code reviews, and red team exercises across products and platforms.
- Support and coordinate Product Security incident response activities, including triage, investigation, remediation guidance, and escalation management for application and product-related security incidents.
- Lead and mentor Product Security engineers and analysts by establishing clear goals, deliverables, development plans, performance feedback, coaching, and operational metrics.
- Oversee the planning and execution of vulnerability assessments, penetration testing, threat modeling, and security reviews for products, applications, APIs, and cloud-native platforms. Drive remediation and risk reduction strategies for identified vulnerabilities across product lines.
- Manage the execution of tactical and strategic Product Security initiatives through effective coordination of cross-functional teams, with accountability for deliverables, timelines, resource planning, and operational outcomes.
- Stay current with industry best practices, emerging threats, secure development frameworks, cloud security standards, and regulatory guidance related to product and application security.
- Lead the development and enhancement of Product Security policies, standards, procedures, and secure engineering guidelines to address evolving application, API, cloud, and software supply chain threats.
Lead and/or contribute to Product Security transformation initiatives, security tooling enhancements, DevSecOps integrations, compliance activities, and other strategic projects assigned by leadership.