Hiring.Camp

Application Security Lead

Slihrms

·

Yesterday

Location
AtkinsRéalis - Corporate Office Bangalore, India
Type
Full-time
Department
Security
Seniority
Lead
Source
Workday

Description

Job Description

Overview

The Global Application Security & DevSecOps Lead is responsible for, operating and continuously improving the organisation’s application security function across the complete software development lifecycle. 

The role owns the policies, technical standards, engineering controls, security testing services, Azure DevOps integrations, application security platforms and governance processes required to ensure that internally developed and externally supplied applications are designed, built, tested and released securely. 

This is both a leadership and hands-on engineering role. The role holder must be capable of defining the global AppSec strategy while also configuring, integrating, operating, troubleshooting and improving the underlying security tools. 

The role will embed automated and risk-based security controls into Azure DevOps repositories and CI/CD pipelines at enterprise scale, covering potentially hundreds of Azure DevOps projects and thousands of repositories. 

The role is accountable for ensuring that security controls are: 

  • Technically effective. 
  • Integrated into engineering workflows. 
  • Proportionate to application risk. 
  • Reliable enough to support mandatory release gates. 
  • Properly tuned to minimise false positives. 
  • Measurable and auditable. 
  • Supported by clear operating procedures. 
  • Adopted consistently across global development teams. 

Your role

Principal accountabilities 

AppSec strategy and operating model 

The role holder will: 

  • Maintain the global Application Security and DevSecOps strategy. 
  • Establish the AppSec function’s mandate, service catalogue, governance model and engagement process. 
  • Define the division of responsibilities between AppSec, engineering, cloud security, architecture, SOC, vulnerability management, risk and compliance. 
  • Develop a risk-based AppSec control framework for different application types and criticality levels. 
  • Establish minimum security requirements for internally developed, externally developed and SaaS applications. 

Define application risk tiers based on factors such as: 

  • Data classification. 
  • Internet exposure. 
  • Transaction value. 
  • Regulatory impact. 
  • Privileged access. 
  • Customer impact. 
  • Business criticality. 
  • Safety impact. 
  • Use of AI or autonomous functionality. 
  • Maintain an AppSec roadmap covering people, process, technology and maturity. 
  • Undertake periodic maturity assessments against NIST SSDF and OWASP SAMM. 
  • Develop annual investment, licensing and resource plans. 
  • Own the AppSec tooling budget and supplier roadmap. 
  • Produce executive-level risk reporting for the CISO and technology leadership. 
  • Represent Application Security at architecture, engineering and risk governance forums. 

AppSec service catalogue 

Establish and operate defined services covering: 

  • Secure code review. 
  • SAST onboarding. 
  • SCA onboarding. 
  • DAST onboarding. 
  • API security testing. 
  • Mobile security testing. 
  • Pipeline security assessment. 
  • Secure Azure DevOps configuration. 
  • Secrets scanning. 
  • IaC and container scanning. 
  • Penetration-test scoping and coordination. 
  • AppSec exception assessment. 
  • Secure release assurance. 
  • Developer security training. 
  • Security Champions support. 
  • Supplier application security review. 
  • Application incident root-cause analysis. 

Secure software development lifecycle 

Secure SDLC governance 

The role holder will: 

  • Define mandatory security activities for each SDLC stage. 
  • Establish security acceptance criteria for epics, features and user stories. 
  • Define mandatory evidence required for production release. 
  • Develop risk-based security release gates. 
  • Ensure emergency-release procedures include proportionate security checks and retrospective review. 
  • Define criteria for when applications require manual review or penetration testing. 
  • Integrate AppSec activities with enterprise architecture and change-management processes. 

About you

Scope of the function 

The role owns or governs the following application security capabilities: 

  • Secure software development lifecycle governance. 
  • Secure coding standards. 
  • Static application security testing. 
  • Software composition analysis. 
  • Dynamic application security testing. 
  • Interactive application security testing, 
  • Manual secure code review. 
  • Application penetration testing. 
  • API security testing. 
  • Cloud-native and serverless application security. 
  • Container and application image security during build. 
  • Infrastructure-as-code security within application delivery pipelines. 
  • Secrets detection and prevention. 
  • Software supply-chain security. 
  • SBOM generation and governance. 
  • Build provenance, artifact integrity and signing. 
  • Azure DevOps repository and pipeline security. 
  • Application security tool ownership and operation. 
  • Security Champions and developer enablement. 
  • Application security exception and risk-acceptance processes. 
  • Application security metrics, reporting and assurance. 
  • Third-party and externally developed software assurance. 
  • Security of AI-enabled applications and AI-generated code. 
  • Product security incident support and root-cause analysis. 

Explicit scope boundary: not enterprise vulnerability management 

        This role does not own the central enterprise vulnerability management function. 

        The following remain outside the role unless separately assigned: 

  • Operating-system vulnerability scanning. 
  • General infrastructure vulnerability scanning. 
  • Network-device vulnerability management. 
  • Endpoint vulnerability management. 
  • Firmware vulnerability management. 
  • Enterprise patch management. 
  • Cloud-host vulnerability remediation. 
  • Runtime host and virtual-machine vulnerability management. 
  • General CSPM remediation ownership. 
  • SOC monitoring and incident queue management. 
  • Enterprise-wide CVE reporting unrelated to applications. 
  • Infrastructure penetration testing. 

The AppSec function nevertheless owns the management of security defects, including: 

  • Validation and triage of AppSec findings. 
  • Removal of false positives and duplicate findings. 
  • Assignment of findings to the correct engineering teams. 
  • Definition of application-security remediation requirements. 
  • Verification that fixes are effective. 
  • Management of AppSec-specific exceptions. 
  • Reporting on application-security exposure. 
  • Escalation of overdue high-risk application findings. 

For containers, the function owns build-time image and Dockerfile security. Runtime host, node and deployed-container vulnerability management should remain with Cloud Security, Platform Security or Vulnerability Management, subject to a defined RACI. 

Rewards & benefits

Explore the rewards and benefits that help you thrive – at every stage of your life and your career.

This includes:

  • Comprehensive life insurance coverage.
  • Premium medical insurance for you and your dependents.
  • Generous annual leave balance.
  • Flexible and hybrid work solutions.
  • Remote work opportunities outside of country.
  • Company gratuity scheme.
  • Discretionary bonus program.
  • Relocation assistance.
  • Employee Wellbeing Program: 24/7 access to specialists in finance, legal matters, family care, personal health, fitness, and nutrition.

Seize every opportunity to sharpen your skills, expand your expertise, and be recognized for the impact you make.

About AtkinsRéalis

We're AtkinsRéalis, a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world's infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. We're committed to leading our clients across our various end markets to engineer a better future for our planet and its people.

Find out more.     

Worker Type

Employee

Job Type

Regular

At AtkinsRéalis, we seek to hire individuals with diverse characteristics, backgrounds and perspectives. We strongly believe that world-class talent makes no distinctions based on gender, ethnic or national origin, sexual identity and orientation, age, religion or disability, but enriches itself through these differences.  

Skills

AzureCI/CDPenetration TestingSOCDevOpsCompliance

Similar Jobs

30

Lead Application Security

Chevron Corporation is one of · Houston 1500 Louisiana Street, United States of America

2 months ago

Application Security Lead

Hightouch · Remote (North America) · Remote

3 months ago

Lead, Application Security

Pru · Wash, 213 Washington St., Newark, NJ, United States of America

4 months ago

Application Security Lead

CENSUS SA · worldwide · Remote

1+ year ago

SAP Application Security Lead

Accenture Federal Services · Washington, DC +1 · Remote

4 days ago

SAP Application Security Lead

Accenture Federal Services · Washington, DC +1 · Remote

2 weeks ago

Lead Application Security Engineer, IT Security

Raymond James · FL - Saint Petersburg - 880 Carillon Pkwy Tower 2, United States of America · Hybrid

2 weeks ago

Lead Application Security Eng

Morgan Stanley · Alpharetta, GA,US, US

4 weeks ago

Lead Application Security Eng

Ms · Alpharetta GA 3, United States of America

4 weeks ago

Lead Application Security Engineer

Cais · London, England +1

4 weeks ago

Senior Lead Application Security Engineer

IFS · Vancouver, British Columbia, Canada · Hybrid

1 month ago

Capability Lead – Application Security

Nttlimited · hyderabad, India · Hybrid

1 month ago

Lead Application Security Engineer

Encora · Kuala Lumpur

1 month ago

Devoteam Cyber Trust | Application Security - Lead | Banking Sector

Devoteam · Lisboa, Lisboa, Portugal · Hybrid

2 months ago

DevSecOps & Application Security Lead

JustMarkets · Remote, Europe · Remote

2 months ago

Lead Application Security Engineer

Bakerhughes · IN-MH-Pune-Cummins India Office Campus, 8th floor Survey No. 21, Balewadi +4

3 months ago

Application Security Lead | Offshore

Photon Group · India

8 months ago

Team Lead - Application Security

METRO/MAKRO · Maharashtra, PUNE, India

1+ year ago

Lead Security Architect (Application Security)

Wells Fargo · 142019-NC-300 South Brevard, Charlotte, United States of America +3 · Hybrid

2 days ago

Application Security Engineering Lead

Athene · West Des Moines 7700 Mills Civic Parkway, United States of America

3 weeks ago

Lead Architect – Application Security

Ffive · San Jose, United States of America +1 · Hybrid

4 weeks ago

Application Security Engineer, Lead

Booz Allen Hamilton · USA, CO, Colorado Springs (1050 Stewart Ave), United States of America

1 month ago

Application Security Team Lead

Gongio · Tel Aviv +1

1 month ago

Application & Cloud Security Lead

Spgi · IN - HYDERABAD SKYVIEW, India +2

1 month ago

Application & Cloud Security Lead

Spgi · IN - HYDERABAD SKYVIEW, India +2

1 month ago

Application Security & IAM Lead

Slihrms · IN.TN.Chennai.IndiQube Alpine, Jawaharlal Nehru Road, Block No. 4, SIDCO Industrial Estate.Guindy, India

1 month ago

Senior/Lead/Principal Application Security Researcher

Salesforce · Israel - Tel Aviv · Onsite

6 months ago

Product, Application and Offensive Security Lead

Wpp · United Kingdon

1 month ago

Lead Strategic Services Consultant (Application Security)

"Black Duck Software, Inc." · Burlington, MA (Remote) · Remote

Today

Lead Information Security Engineer - Web Application Security

Wells Fargo · 141278-NC-CIC Customer Information Ctr, United States of America +2 · Hybrid

Yesterday