Jobgether
Product Security Advisor
engineeringfull-timeIndia
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Accountabilities
- Advise product engineering teams on secure coding, vulnerability management, secure software development lifecycle (SSDLC), and secure-by-design practices.
- Support the adoption and effective use of application security tools, including SAST, SCA, IAST, and CNAPP, and help teams analyse and remediate identified vulnerabilities.
- Conduct threat modelling using established frameworks such as STRIDE, PASTA, and MAESTRO to identify application weaknesses and control gaps.
- Partner with architecture teams to embed security principles into product design, lead security design reviews, and maintain secure application architecture guidelines.
- Help ensure products comply with applicable security standards, regulations, and industry frameworks, including OWASP, CIS, PCI-DSS, and related requirements.
- Collaborate with audit and compliance teams to document security controls, maintain traceable evidence, and support regulatory and customer audits such as SOC 2, PCI-DSS, CIS, and FedRAMP.
- Build strong relationships with engineering teams, functional stakeholders, and technology leadership to increase awareness and adoption of product security practices.
- Provide regular security updates, training sessions, and presentations to technical teams, employees, and management.
- Monitor emerging threats, technologies, vulnerabilities, and industry trends to proactively identify risks and recommend appropriate mitigations.
- Mentor colleagues and stakeholders on secure coding techniques, security architecture patterns, and practical product security principles.
- 5+ years of experience in cybersecurity, product security, security architecture, or a closely related technology security discipline.
- 3+ years of information security experience within hybrid cloud environments.
- Strong expertise in secure coding practices, threat modelling, secure architecture, and secure SDLC/CI/CD pipelines.
- Previous experience in software development or engineering, with the ability to communicate effectively with development teams.
- In-depth technical experience identifying, assessing, and advising on remediation of application security vulnerabilities across cloud and web-based applications.
- Strong knowledge of security frameworks and industry standards, including OWASP, PCI, CIS, and NIST.
- Demonstrated ability to solve complex technical and organisational security problems proactively and with a strong sense of ownership.
- Experience influencing stakeholders and presenting security topics to senior technology and information security executives.
- Strong communication, relationship-building, mentoring, and stakeholder management skills.
- Bachelor’s degree in Computer Science, Information Technology, or another technology-related discipline.
- Security certifications such as CISSP, SSCP, or CSSLP are preferred.
- Ability and willingness to travel domestically for up to approximately 15% of the time.
- Remote working opportunity based in India.
- Flexible working environment designed to support work-life balance.
- Opportunity to work with global technology, engineering, and cybersecurity teams.
- Exposure to complex product security, cloud security, application security, and regulatory environments.
- Opportunities to contribute to security strategy, architecture, and organisation-wide security initiatives.
- Professional development and opportunities to expand technical and leadership capabilities.
- Collaborative environment focused on innovation, continuous learning, and knowledge sharing.
- Opportunity to contribute to initiatives with broader social and community impact.
Requirements
Benefits
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply