← Все вакансии/Senior/jobgether
SeniorRemoteIndia

Product Security Advisor

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security Advisor based in India.

As a Product Security Advisor, you will help embed security into products from design through deployment and ongoing operations.

Responsibilities
  • Advise product engineering teams on secure coding, vulnerability management, secure software development lifecycle (SSDLC), and secure-by-design practices.
  • Support the adoption and effective use of application security tools, including SAST, SCA, IAST, and CNAPP, and help teams analyse and remediate identified vulnerabilities.
  • Conduct threat modelling using established frameworks such as STRIDE, PASTA, and MAESTRO to identify application weaknesses and control gaps.
  • Partner with architecture teams to embed security principles into product design, lead security design reviews, and maintain secure application architecture guidelines.
  • Help ensure products comply with applicable security standards, regulations, and industry frameworks, including OWASP, CIS, PCI-DSS, and related requirements.
  • Collaborate with audit and compliance teams to document security controls, maintain traceable evidence, and support regulatory and customer audits such as SOC 2, PCI-DSS, CIS, and FedRAMP.
  • Build strong relationships with engineering teams, functional stakeholders, and technology leadership to increase awareness and adoption of product security practices.
  • Provide regular security updates, training sessions, and presentations to technical teams, employees, and management.
  • Monitor emerging threats, technologies, vulnerabilities, and industry trends to proactively identify risks and recommend appropriate mitigations.
  • Mentor colleagues and stakeholders on secure coding techniques, security architecture patterns, and practical product security principles.
Requirements
  • 5+ years of experience in cybersecurity, product security, security architecture, or a closely related technology security discipline.
  • 3+ years of information security experience within hybrid cloud environments.
  • Strong expertise in secure coding practices, threat modelling, secure architecture, and secure SDLC/CI/CD pipelines.
  • Previous experience in software development or engineering, with the ability to communicate effectively with development teams.
  • In-depth technical experience identifying, assessing, and advising on remediation of application security vulnerabilities across cloud and web-based applications.
  • Strong knowledge of security frameworks and industry standards, including OWASP, PCI, CIS, and NIST.
  • Demonstrated ability to solve complex technical and organisational security problems proactively and with a strong sense of ownership.
  • Experience influencing stakeholders and presenting security topics to senior technology and information security executives.
  • Strong communication, relationship-building, mentoring, and stakeholder management skills.
  • Bachelor’s degree in Computer Science, Information Technology, or another technology-related discipline.
  • Security certifications such as CISSP, SSCP, or CSSLP are preferred.
  • Ability and willingness to travel domestically for up to approximately 15% of the time.
Conditions
  • Remote working opportunity based in India.
  • Flexible working environment designed to support work-life balance.
  • Opportunity to work with global technology, engineering, and cybersecurity teams.
  • Exposure to complex product security, cloud security, application security, and regulatory environments.
  • Opportunities to contribute to security strategy, architecture, and organisation-wide security initiatives.
  • Professional development and opportunities to expand technical and leadership capabilities.
  • Collaborative environment focused on innovation, continuous learning, and knowledge sharing.
  • Opportunity to contribute to initiatives with broader social and community impact.
Стек и навыки

С чем работаем