HamburgerMenu
hirist

Lead Product Security Engineer - SAST/DAST

Sunovaa Tech
8 - 12 Years
Bangalore

Posted on: 30/09/2026

Job Description

Role & Responsibilities:

- Lead Application Security and Product Security initiatives across the complete Secure SDLC.

- Own security strategy and technical direction for products, applications and cloud-native platforms.

- Lead Threat Modeling and Risk Assessment for application, API, cloud and product architectures.

- Define and implement security controls across design, development, CI/CD, deployment and production.

- Lead SAST, DAST, SCA and vulnerability management programs and drive remediation with engineering teams.

- Review application and solution architectures from a security perspective and provide actionable recommendations.

- Lead security assessments for AWS/Azure cloud environments, including IAM/RBAC, network security, encryption, secrets management and monitoring.

- Drive Container and Kubernetes Security, including image security, RBAC, secrets, network policies and runtime controls.

- Establish and improve DevSecOps practices, integrating automated security checks into CI/CD pipelines.

- Define security standards, guidelines and best practices aligned with OWASP and industry security frameworks.

- Work closely with Software Engineering, DevOps, Cloud, Architecture and Product teams to resolve security risks.

- Prioritize vulnerabilities based on technical and business risk and drive timely remediation.

- Mentor and provide technical guidance to security engineers and development teams.

- Lead security reviews, audits, risk reporting and security improvement initiatives.

- Stay current with emerging application, cloud, container and product security threats and technologies.

Preferred Candidate Profile:

- 7 - 12 years of experience in Application Security, Product Security, Cloud Security, DevSecOps or Cybersecurity, with demonstrated technical leadership.

- Strong hands-on expertise in Application/Product Security and Secure SDLC.

- Proven experience leading Threat Modeling and Risk Assessment activities.

- Strong knowledge of AWS and/or Azure Cloud Security.

- Strong hands-on experience with Docker, Kubernetes and Container Security.

- Excellent understanding of SAST, DAST, SCA, OWASP Top 10 and vulnerability management.

- Experience designing and implementing DevSecOps and CI/CD security controls.

- Strong understanding of IAM/RBAC, API Security, secrets management, encryption and cloud security architecture.

- Experience with security tools such as Snyk, Checkmarx, Fortify, Veracode, SonarQube, Trivy, Burp Suite, Prisma Cloud, Aqua or equivalent.

- Ability to review security architecture and translate security risks into practical technical solutions.

- Demonstrated experience leading technical discussions, mentoring engineers and influencing development/architecture teams.

- Strong communication, stakeholder-management and problem-solving skills.

- Must have hands-on implementation experience in addition to security leadership experience.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...