Adani Group Logo

Adani Group

Application Security Head

Posted 3 Days Ago
Be an Early Applicant
In-Office
Mumbai, Maharashtra, IND
Expert/Leader
In-Office
Mumbai, Maharashtra, IND
Expert/Leader
Lead and execute the organization's application security strategy across the SDLC. Manage a team to perform code reviews, static/dynamic analysis, SAST/DAST/SCA, penetration testing, vulnerability management, incident response, and third-party risk assessments. Ensure compliance with industry standards, select security tools, automate testing and remediation, run training, and coordinate with other security and product teams to reduce application risk.
The summary above was generated by AI
Responsibilities

Leadership and Strategy Development:

  • Oversee the organization's application security initiatives, ensuring alignment with business goals and risk management strategies.
  • Define and implement strategies to protect applications across their entire lifecycle—from design to deployment and beyond.
  • Manage and mentor a team of application security professionals, including security engineers and analysts, to build a robust application security culture within the organization.
  • Collaborate with senior management, development teams, product teams, and IT to ensure alignment on security priorities and initiatives.
     

Risk Management:

  • Evaluate the security posture of applications and assess potential risks, such as data breaches, vulnerabilities, and exploitation tactics.
  • Proactively identify potential threats and assess how the application’s architecture could be targeted by cybercriminals.
  • Develop and recommend remediation strategies to minimize risk exposure.

Secure Software Development Lifecycle (SDLC):

  • Ensure that security is embedded throughout the software development lifecycle (SDLC), including design, coding, testing, and deployment.
  • Perform code reviews, static/dynamic analysis, and penetration testing to identify vulnerabilities in applications.
  • Work with developers to integrate secure coding practices, secure design principles, and appropriate security controls into application development.
     

Application Security Testing and Tools:

  • Oversee the implementation and execution of security testing activities, such as automated scanning, vulnerability assessments, and penetration testing.
  • Select and implement the appropriate security tools (e.g., Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA)) to identify vulnerabilities in applications.
  • Coordinate remediation efforts and track the status of vulnerabilities found in applications, ensuring timely fixes.
     

Compliance and Governance:

  • Ensure that applications meet industry standards and regulatory requirements related to application security, such as GDPR, PCI DSS, HIPAA, or SOC 2.
  • Develop and enforce security policies, standards, and best practices for secure application development and deployment.
  • Conduct regular audits of applications and security programs, and report security metrics to management and external auditors.

Incident Response and Threat Intelligence:

  • Lead efforts to investigate and respond to application security incidents, including identifying root causes and preventing future occurrences.
  • Stay up-to-date on the latest trends in application security vulnerabilities, exploits, and attack techniques, and adjust strategies accordingly.
     
  • Work with the broader cybersecurity team to coordinate responses and communicate the impact and mitigation steps to internal and external stakeholders.

Training and Awareness:

  • Provide regular security training sessions for developers, QA engineers, and other relevant teams to foster a culture of security awareness.
  • Educate and advocate for secure coding standards and practices across development teams.
  • Promote awareness around secure application development and threat landscapes to improve organizational security culture.

Collaboration with Other Security Teams:

  • Collaborate with the infrastructure security team to ensure that application security integrates well with network security, endpoint security, and cloud security.
  • Engage in or facilitate red teaming exercises to assess application vulnerabilities and ensure security resilience in real-world attack scenarios.

Tool Selection and Automation:

  • Implement security automation tools to help streamline security testing and vulnerability management.
  • Continuously evaluate and refine application security practices, tools, and workflows to improve efficiency and security coverage.
     

Vendor and Third-Party Risk Management:

  • Ensure that third-party applications and services used by the organization meet security standards and are regularly assessed for vulnerabilities.

Evaluate and assess the security of third-party suppliers, vendors, and contractors who provide software or services to the organization.

Qualifications

Educational qualifications & Experience:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field
     Master’s degree or relevant certifications in Cybersecurity or Technology Management (preferred)
     
  • Certifications:
     Certifications in Cybersecurity such as CISSP, CISM, or equivalent
     Additional certifications in emerging technologies and innovation management (desired)
     

Work Experience (Range in Years) :
 Minimum 15+ years of experience in the Cybersecurity industry
 Demonstrated track record of leadership in driving technological advancements and innovation
 Proven experience in product development and implementation within the cybersecurity domain.

Similar Jobs

3 Hours Ago
Remote or Hybrid
India
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design, develop, test, and document ServiceNow applications, integrations, and migrations. Translate business requirements into scalable ServiceNow solutions, maintain platform health, perform upgrades, participate in code reviews, mentor team members, and drive automation and workflow improvements while ensuring security and quality.
Top Skills: Ai TechnologiesCommon Service Data Model (Csdm)Employee Center ProGrc/IrmHamHrsdJavaScriptNow AssistRest ApiSamSecopsServicenowServicenow ItsmServicenow UpgradesServicenow Version ControlSoap ApiUpdate SetsVirtual Agent
4 Hours Ago
In-Office
Mid level
Mid level
Artificial Intelligence • Hardware • Information Technology • Machine Learning
The Test Automation Handler Engineer will address product issues, optimize manufacturing processes, coordinate procurement, and implement new technologies while ensuring safety and compliance in assembly processes.
Top Skills: AodsDoe TechniquesEtiEtmaintEtreportsMicisSap Matreq
4 Hours Ago
In-Office
Senior level
Senior level
Artificial Intelligence • Hardware • Information Technology • Machine Learning
Lead and deliver cross-functional strategic programs from strategy through execution. Define program charters, governance, schedules, budgets, and success metrics. Drive continuous improvement, cost optimization, vendor management, and stakeholder alignment while advising senior leadership and building high-performing PMO teams.
Top Skills: Ai-Related Software

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account