Careers at 42Gears

Lead- Product Security

Full Time
Bengaluru, India

A clearer role summary, responsibilities, and application entry point are laid out below so this page feels like a destination, not a placeholder.

Role type

Full Time

Location

Bengaluru, India

Role Details

Relevant Experience: 5- 8 years


About the Role


We are looking for a Lead– Product Security to lead and coordinate product security initiatives across the software development lifecycle. This role is ideal for someone with a strong foundation in application and product security, combined with excellent project management and stakeholder coordination skills.

You will work closely with Engineering, Product Management, QA, DevOps, Compliance, and Security teams to drive security programs, track remediation efforts, manage security reviews, and ensure security requirements are embedded throughout the SDLC. The role requires strong ownership, communication, and execution skills to ensure product security initiatives are delivered on time and aligned with business objectives.


Key Responsibilities

  • Lead and manage product security initiatives, ensuring timely execution of security projects across multiple engineering teams.
  • Coordinate security activities including threat modeling, secure design reviews, architecture reviews, code reviews, penetration testing, and release security assessments.
  • Track and drive remediation of vulnerabilities identified through SAST, DAST, SCA, penetration testing, bug bounty programs, and customer-reported security findings.
  • Collaborate with Product, Engineering, DevOps, QA, and Compliance teams to integrate security requirements into the Secure Software Development Lifecycle (SSDLC).
  • Maintain security project plans, milestones, dashboards, and executive status reports to ensure visibility into ongoing security initiatives.
  • Facilitate security governance meetings, track action items, identify project risks, and escalate issues when required.
  • Define and monitor Product Security KPIs and metrics, including vulnerability remediation SLAs, security review coverage, and release readiness.
  • Support customer security assessments, compliance audits, and certification activities by coordinating responses and providing security evidence.
  • Drive continuous improvements to product security processes, documentation, and automation to improve operational efficiency.
  • Mentor junior security engineers and promote security awareness and secure development best practices across engineering teams.

Qualifications

  • 5–8 years of experience in Product Security, Application Security, Information Security, or Cybersecurity.
  • 2–4 years of experience managing cross-functional technical or security projects.
  • Strong understanding of Secure Software Development Lifecycle (SSDLC) and secure development practices.
  • Hands-on knowledge of application security concepts, including the OWASP Top 10, API Security, threat modeling, and secure architecture reviews.
  • Experience coordinating vulnerability management and remediation across multiple engineering teams.
  • Familiarity with SAST, DAST, SCA, container security, cloud security, and CI/CD security practices.
  • Experience working in Agile/Scrum development environments.
  • Excellent project management, stakeholder management, communication, and organizational skills.
  • Ability to manage multiple priorities while delivering high-quality outcomes within defined timelines.

Preferred Skills

  • Experience with Jira, Confluence, Azure DevOps, GitLab.
  • Familiarity with security tools such as SonarQube, Snyk, Burp Suite, OWASP dependency check, or similar platforms.
  • Knowledge of cloud platforms (AWS, Azure, or GCP) and container technologies (Docker and Kubernetes).
  • Experience supporting SOC 2, ISO/IEC 27001, or other security compliance frameworks.
  • Certifications such as PMP, Certified Scrum Master (CSM), Security+, CSSLP or equivalent are an added advantage.

Key Competencies

  • Strong project and program management skills.
  • Excellent stakeholder and cross-functional collaboration.
  • Risk identification, prioritization, and mitigation.
  • Strong analytical and problem-solving abilities.
  • Effective written and verbal communication.
  • Ability to influence engineering teams without direct authority.
  • High level of ownership, accountability, and attention to detail.