P

Senior Manager - Application Security & AI Security

Pine Labs Β· Noida, Uttar Pradesh, India

10–18 yrs experiencefull_timePosted 2 days ago
Apply now β†’

Job description

**We're Hiring | Senior Manager – Application Security (AppSec)** πŸ“ **Location:** Noida Sector 62 (Pine Labs) 🏒 **Work Mode:** 5 Days Work from Office (No Remote/Hybrid) **Role Overview** We are looking for an experienced **Senior Manager – Application Security** to lead and strengthen our **Application Security, AI Security, API Security, Mobile Security, and Secure Code (SAST)** programs. This leadership role will drive secure engineering practices across the organization by embedding security into every stage of the software development lifecycle. You will partner closely with Engineering, Product, Infrastructure, and Compliance teams to build scalable, cloud-native, and secure applications. The ideal candidate brings deep expertise in **Application Security, Secure SDLC, AI Security, DevSecOps, Cloud Security, API Security, Mobile Security, Secure Code Reviews, and Security Automation** , along with proven experience leading high-performing security teams. **Key Responsibilities** **Application Security** - Define, implement, and continuously improve Secure SDLC practices across the organization. - Conduct security architecture reviews, secure design assessments, and threat modeling exercises. - Perform application security assessments for web, cloud-native, and microservices-based applications. - Drive vulnerability management and remediation programs. - Establish secure coding standards and security requirements. - Partner with engineering teams to remediate security vulnerabilities throughout the software lifecycle. **AI Security** - Establish enterprise-wide AI/LLM security standards and governance. - Conduct security reviews and threat modeling for AI, GenAI, LLM, Agentic AI, and RAG-based applications. - Assess risks related to: - Prompt Injection - Insecure Output Handling - Data Leakage - Model Manipulation - AI Supply Chain Risks - Evaluate security controls for MCP-based solutions and third-party AI integrations. - Enable secure adoption of AI technologies across the organization. **API Security** - Define API Security governance aligned with the OWASP API Security Top 10. - Perform API security assessments and threat modeling. - Review authentication, authorization, encryption, and access control mechanisms. - Ensure secure implementation of OAuth 2.0, OpenID Connect, JWT, and API Gateway security controls. - Maintain API inventory and assess third-party API risks. **Mobile Application Security** - Lead Android and iOS application security assessments. - Establish mobile security standards aligned with OWASP MASVS. - Review: - Secure Storage - Encryption - Certificate Pinning - Anti-Tampering Controls - Root/Jailbreak Detection - Manage mobile penetration testing and remediation programs. **SAST & Secure Code Review** - Own the organization's Secure Code (SAST) strategy. - Deploy and manage SAST solutions across engineering teams. - Integrate SAST into CI/CD pipelines. - Perform secure code reviews. - Validate remediation of identified vulnerabilities. - Define vulnerability management SLAs. - Optimize SAST rules to reduce false positives. - Coach developers on secure coding best practices. **DevSecOps & Security Automation** - Integrate security controls into CI/CD pipelines. - Implement and manage: - SAST - DAST - SCA - Secrets Scanning - Container Security - Infrastructure as Code (IaC) Security - Automate security testing and compliance validation. - Implement security gates and risk-based approval workflows. - Drive Shift-Left Security practices across engineering teams. **Governance & Compliance** - Develop and maintain application security policies and standards. - Track AppSec KPIs and security posture metrics. - Support compliance with: - PCI DSS - ISO 27001 - RBI Guidelines - DPDP - Other regulatory frameworks - Participate in audits and enterprise risk assessments. - Drive Security Champion and developer awareness programs. **Leadership & Stakeholder Management** - Lead and mentor Application Security Engineers and Security Analysts. - Collaborate with Product, Engineering, Infrastructure, Architecture, and Compliance teams. - Present security risks, remediation plans, and KPIs to senior leadership. - Define and execute the Application Security roadmap and maturity initiatives. **Required Skills & Expertise** Application Security - Secure SDLC - Threat Modeling - Secure Design Reviews - Secure Coding Practices - OWASP Top 10 - Vulnerability Assessment & Penetration Testing SAST & Code Security - Checkmarx - GitHub Advanced Security (CodeQL) API Security - OWASP API Security Top 10 - OAuth 2.0 - OpenID Connect - JWT - API Gateway Security - API Testing & Security Validation Mobile Security - Android Security - iOS Security - Mobile Application Hardening - Mobile Penetration Testing AI Security - GenAI Security - LLM Security - Prompt Injection Prevention - RAG Security - AI Threat Modeling - AI Risk Assessment - MCP Security Reviews **Required Experience** - Bachelor's or Master's degree in Computer Science, Information Technology, Cyber Security, or a related field. - **12+ years** of overall Information Security experience. - Minimum **10 years** of experience in Application Security or Product Security leadership roles. - Proven experience leading enterprise Application Security programs in cloud-native environments. - Strong understanding of modern software engineering practices and DevSecOps. **What We're Looking For** βœ” Passion for building secure software at scale. βœ” Ability to influence engineering teams and embed security into product development. βœ” Strong leadership, stakeholder management, and communication skills. βœ” Experience driving security transformation in fast-paced technology organizations. **What You Should Be Comfortable With** - Working from the office **5 days a week** . - Challenging conventional thinking and driving innovation. - Taking ownership of large-scale security initiatives. -