HamburgerMenu
hirist

Job Description

We are looking for a Product Security and Privacy Champion to join HID Global's Product Security & Privacy team. This role will work closely with engineering teams and security architects to drive adoption of the Secure Software Development Lifecycle (SSDL) and strengthen product security practices across multiple application environments.

The ideal candidate should have strong knowledge of Application Security, Threat Modeling, Secure SDLC, SAST, DAST, SCA, Vulnerability Management and Security Testing, along with hands-on exposure to one or more domains such as Web & API Security, Mobile Security, Embedded Security or Desktop Security.

This is a hands-on security enablement role involving security assessments, threat-model reviews, training, architecture reviews, risk management and collaboration with global engineering teams.

Roles & Responsibilities :

- Deliver Product Security & Privacy controls and Threat Modeling training sessions for engineering and product teams.

- Conduct Product Security & Privacy control assessment workshops.

- Facilitate and support Threat Modeling review sessions.

- Work closely with Security Architects and engineering teams to improve security practices across the software development lifecycle.

- Support the creation and delivery of reusable security training content.

- Participate in security architecture reviews and audits.

- Support security risk management, incident handling and security tool triage.

- Help engineering teams implement reusable secure design and development patterns.

- Support software supply-chain security initiatives.

- Assist with acquisition onboarding and security training activities.

- Support compliance initiatives including the Cyber Resilience Act (CRA) and other applicable security/privacy requirements.

- Interpret HID's internal security and privacy standards and guide engineering teams on implementation.

- Provide feedback to the Product Security & Privacy team regarding process gaps, engineering challenges and opportunities to improve security tooling and platforms.

- Promote Secure SDLC and security-by-design practices across product teams.

Technical Requirements :

- 4+ years of overall experience in Software Engineering, Application Security, Product Security or related areas.

- Experience contributing to at least one Secure Software Development Lifecycle (SSDL / SSDLC) program.

- Experience working as a Security Champion, Product Security Engineer, Application Security Engineer, Security Architect or similar role.

- Strong understanding of general Application Security principles and secure coding practices.

- Working knowledge of Threat Modeling methodologies and security risk assessment.

- Experience using security tools such as :

1. SAST

2. DAST

3. SCA

4. Vulnerability Scanners

5. Secret Scanning tools

- Hands-on experience in one or more of the following security domains :

1. Web & API Security

2. Mobile Application Security

3. Embedded Device Security

4. Desktop Application Security

- Experience conducting security reviews, workshops or technical training for engineering teams.

- Understanding of software vulnerabilities, security testing and remediation processes.

- Ability to collaborate effectively with developers, architects, product owners and technical stakeholders.

Preferred Skills :

- Cloud Security and Cloud Infrastructure Security

- Software Supply Chain Security

- Operational Security

- Agile / SAFe Methodology

- AI tools used in the context of cybersecurity or security programs

- Security and privacy compliance

- Cyber Resilience Act (CRA)

- Security Architecture

- Risk Management

- Incident Handling

- Secure Design Patterns

- Security or privacy certifications such as CISSP, CSSLP, CEH, CIPT or equivalent will be an added advantage.

Education :

- Bachelor's Degree in Computer Science, Information Technology, Engineering or a related discipline, or equivalent relevant experience.

Soft Skills :

- Strong communication and presentation skills.

- Ability to explain complex security concepts to technical and non-technical stakeholders.

- Strong interest in training, coaching and knowledge sharing.

- Ability to collaborate with development teams, architects and product owners.

- Adaptable and approachable working style.

- Strong technical aptitude and problem-solving ability.

- Continuous learning mindset.

About HID Global :

HID Global is a global leader in trusted identity and access solutions, enabling secure access to physical and digital environments. HID serves governments, enterprises, financial institutions, healthcare organisations, educational institutions and industrial businesses worldwide.

HID operates across more than 100 countries and is part of the ASSA ABLOY Group. In India, HID has engineering centres in Chennai and Bengaluru, with its Global Engineering Team based in Chennai.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...