Application Security Lead
Sagility · Bengaluru, Karnataka, India
Free to search · AI fit score against your CV · tailor your résumé in one click
Sagility · Bengaluru, Karnataka, India
Sagility is a tech-enabled BPM services provider, a thought partner providing a broad spectrum of transformational services, to enable our clients to provide efficient and hi-quality care across the healthcare system. Sagility™️ combines industry-leading technology and transformation-driven BPM services with decades of healthcare domain expertise to help clients draw closer to their members. We optimize the entire member/patient experience through service offerings for clinical, case management, member engagement, provider solutions, payment integrity, claims cost containment, and analytics. Leading industry analyst firms have consistently cited our service excellence, breadth of offerings, and ability to execute. The most recent being recognized as a leader for Healthcare Payer Operations in 2022 as a part The Healthcare Payer Operations PEAK Matrix® Assessment report by Everest Group. To learn more about our recognition please visit our AWARDS SECTION We have 48,000+ employees in 15 cities across 5 countries – India, Philippines, USA, Jamaica, and Colombia. About the Role: This role creates a single point of accountability for application security across the entire group portfolio — not one pillar or one programme: someone who can judge whether what we are building is genuinely secure, set the standard before code is written, and stand credibly in front of Information Security, Internal Audit and client security reviewers with the evidence to prove it. This is a hands-on leadership role, not a compliance-checklist role. The person must be technical enough to challenge an architecture and commercial enough to shape a client proposal. Key responsibilities: Secure design and architecture assurance: • Review solution and application architectures across every application in the group and issue clear, documented security decisions — approve, approve with conditions, or reject with rationale. • Provide security design inputs early: authentication and authorisation models, identity and access design, data classification and segregation, encryption in transit and at rest, key and secrets management, logging and monitoring, network and tenancy boundaries. • Define and maintain secure design standards, reference patterns and reusable controls, so teams start from a known-good baseline instead of inventing one per programme. • Assess the security implications of cloud and platform choices across AWS, Azure and SaaS estates, and of third-party components introduced by delivery partners. Threat modelling and risk assessment: • Run structured threat modelling (STRIDE or equivalent) for new products and material changes, covering data flows, trust boundaries, abuse cases and privilege paths. • Maintain a group-level application risk register with severity, business impact, owner, remediation plan and target date — and drive it to closure rather than reporting on it. • Define risk acceptance criteria and the escalation path for exceptions, so residual risk is a deliberate, documented business decision. • Extend threat modelling to AI and LLM-based applications: prompt injection, data leakage through model context, unsafe tool and agent permissions, model and vendor supply chain, with controls aligned to the OWASP Top 10 for LLM Applications. Security testing strategy and governance: • Decide what testing is required for each application and each release tier, and hold teams to it. This is a decision the role owns, not a recommendation it offers. • SAST — tool selection, rule tuning, pipeline integration, false-positive triage and severity gating. • DAST and API security testing — including authenticated scanning and business-logic coverage. • Software composition analysis — open-source and third-party dependency risk, licence exposure, transitive vulnerabilities, SBOM generation and currency. • Penetration testing — define scope and rules of engagement, select and manage external testing partners, review findings for validity and severity, and own the remediation and retest cycle through to sign-off. • Secrets scanning, container and infrastructure-as-code scanning, and cloud security posture checks where applicable. • Embed these gates into CI/CD so security is enforced by the pipeline rather than by goodwill, and define the criteria under which a release is blocked. Alignment with Information Security and Internal Audit: • Act as the translation layer between engineering reality and enterprise security policy — interpret Information Security requirements into implementable controls, and represent engineering constraints back into policy discussions. • Prepare the group’s applications for internal and external audits: control mapping, evidence packs, walkthroughs and auditor Q&A. • Own closure of audit and Information Security findings relating to applications, including root-cause analysis and preventive control changes. • Maintain traceability between applicable obligations — ISO 27001, SOC 2, HIPAA / HITRUST, PCI-DSS and client contractual security requirements, as relevant to each application — and the controls actually implemented. Solutioning and proposal support: • Own the security content of proposals, RFP and RFI responses: security architecture narrative, control descriptions, assurance approach, certifications and attestations. • Respond to client security questionnaires and due-diligence assessments, and represent Sagility in client security and architecture review calls. • Size the security effort in solution estimates — tooling, testing cycles, remediation capacity — so security is costed rather than absorbed silently. • Translate our security posture into a commercial differentiator in front of prospects, not a list of caveats. Documentation and evidence: • Define the mandatory security documentation set per application and enforce it as a release gate: security architecture document, data flow diagrams and trust boundaries, threat mode