Application Security Lead

AtkinsRéalis

Bengaluru

Hybrid

INR 3,000,000 - 5,400,000

Full time

10 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive life insurance
Premium medical insurance
Generous annual leave
Flexible and hybrid work solutions
Remote work opportunities outside of a
Company gratuity scheme
Discretionary bonus program
relocation assistance
Wellbeing program

Job summary

AtkinsRéalis seeks a Global Application Security & DevSecOps Lead to own and continuously improve the organisation's AppSec function across the complete software development lifecycle. You will define the global AppSec strategy, establish governance, and embed automated security controls into Azure DevOps pipelines at enterprise scale.

The role combines leadership with hands-on engineering, ensuring internally developed and SaaS applications are securely designed, built, tested and released,

Qualifications

  • Proven ability to define and lead global AppSec strategy and governance.
  • Experience embedding automated security controls into CI/CD pipelines.
  • Knowledge of NIST SSDF and OWASP SAMM frameworks.

Responsibilities

  • Define the global AppSec strategy and governance model.
  • Establish security controls across SDLC and release gates.
  • Lead security testing services, SAST/DAST/SCA, and pipeline security.

Skills

Leadership
AppSec strategy
DevSecOps
Azure DevOps
Policy governance
Risk management
Secure SDLC

Tools

Azure DevOps tools
SAST/DAST/SCA tooling

Job description

Overview

The Global Application Security & DevSecOps Lead is responsible for, operating and continuously improving the organisation's'application security function across the complete software development lifecycle.

Overview

The Global Application Security & DevSecOps Lead is responsible for, operating and continuously improving the organisation's'application security function across the complete software development lifecycle. The role owns the policies, technical standards, engineering controls, security testing services, Azure DevOps integrations, application security platforms and governance processes required to ensure that internally developed and externally supplied applications are designed, built, tested and released securely. This is both a leadership and hands‑on engineering role. The role holder must be capable of defining the global AppSec strategy while also configuring, integrating, operating, troubleshooting and improving the underlying security tools. The role will embed automated and risk‑based security controls into Azure DevOps repositories and CI/CD pipelines at enterprise scale, covering potentially hundreds of Azure DevOps projects and thousands of repositories. The role is accountable for ensuring that security controls are:

  • Technically effective.
  • Integrated into engineering workflows.
  • Proportionate to application risk.
  • Reliable enough to support mandatory release gates.
  • Properly tuned to minimise false positives.
  • Measurable and auditable.
  • Supported by clear operating procedures.
  • Adopted consistently across global development teams.
Your role
The Role Holder Will:
  • Maintain the global Application Security and DevSecOps strategy.
  • Establish the AppSec function's mandate, service catalogue, governance model and engagement process.
  • Define the division of responsibilities between AppSec, engineering, cloud security, architecture, SOC, vulnerability management, risk and compliance.
  • Develop a risk-based AppSec control framework for different application types and criticality levels.
  • Establish minimum security requirements for internally developed, externally developed and SaaS applications.
Define Application Risk Tiers Based On Factors Such As:
  • Data classification.
  • Internet exposure.
  • Transaction value.
  • Regulatory impact.
  • Privileged access.
  • Customer impact.
  • Business criticality.
  • Safety impact.
  • Use of AI or autonomous functionality.
  • Maintain an AppSec roadmap covering people, process, technology and maturity.
  • Undertake periodic maturity assessments against NIST SSDF and OWASP SAMM.
  • Develop annual investment, licensing and resource plans.
  • Own the AppSec tooling budget and supplier roadmap.
  • Produce executive-level risk reporting for the CISO and technology leadership.
  • Represent Application Security at architecture, engineering and risk governance forums.
Establish And Operate Defined Services Covering:
  • Secure code review.
  • SAST onboarding.
  • SCA onboarding.
  • DAST onboarding.
  • API security testing.
  • Mobile security testing.
  • Pipeline security assessment.
  • Secure Azure DevOps configuration.
  • Secrets scanning.
  • IaC and container scanning.
  • Penetration-test scoping and coordination.
  • AppSec exception assessment.
  • Secure release assurance.
  • Developer security training.
  • Security Champions support.
  • Supplier application security review.
  • Application incident root-cause analysis.
The Role Holder Will:
  • Define mandatory security activities for each SDLC stage.
  • Establish security acceptance criteria for epics, features and user stories.
  • Define mandatory evidence required for production release.
  • Develop risk-based security release gates.
  • Ensure emergency-release procedures include proportionate security checks and retrospective review.
  • Define criteria for when applications require manual review or penetration testing.
  • Integrate AppSec activities with enterprise architecture and change-management processes.
About You

The role owns or governs the following application security capabilities:

  • Secure software development lifecycle governance.
  • Secure coding standards.
  • Static application security testing.
  • Software composition analysis.
  • Dynamic application security testing.
  • Interactive application security testing,
  • Manual secure code review.
  • Application penetration testing.
  • API security testing.
  • Cloud-native and serverless application security.
  • Container and application image security during build.
  • Infrastructure-as-code security within application delivery pipelines.
  • Secrets detection and prevention.
  • Software supply-chain security.
  • SBOM generation and governance.
  • Build provenance, artifact integrity and signing.
  • Azure DevOps repository and pipeline security.
  • Application security tool ownership and operation.
  • Security Champions and developer enablement.
  • Application security exception and risk-acceptance processes.
  • Application security metrics, reporting and assurance.
  • Third-party and externally developed software assurance.
  • Security of AI-enabled applications and AI-generated code.
  • Product security incident support and root-cause analysis.
Explicit scope boundary

This role does not own the central enterprise vulnerability management function.

The Following Remain Outside The Role Unless Separately Assigned
  • Operating-system vulnerability scanning.
  • General infrastructure vulnerability scanning.
  • Network-device vulnerability management.
  • Endpoint vulnerability management.
  • Firmware vulnerability management.
  • Enterprise patch management.
  • Cloud-host vulnerability remediation.
  • Runtime host and virtual-machine vulnerability management.
  • General CSPM remediation ownership.
  • SOC monitoring and incident queue management.
  • Enterprise-wide CVE reporting unrelated to applications.
  • Infrastructure penetration testing.
The AppSec function nevertheless owns the management of security defects, including:
  • Validation and triage of AppSec findings.
  • Removal of false positives and duplicate findings.
  • Assignment of findings to the correct engineering teams.
  • Definition of application-security remediation requirements.
  • Verification that fixes are effective.
  • Management of AppSec-specific exceptions.
  • Reporting on application-security exposure.
  • Escalation of overdue high-risk application findings.
Rewards & benefits

Explore the rewards and benefits that help you thrive – at every stage of your life and your career.

This Includes
  • Comprehensive life insurance coverage.
  • Premium medical insurance for you and your dependents.
  • Generous annual leave balance.
  • Flexible and hybrid work solutions.
  • Remote work opportunities outside of country.
  • Company gratuity scheme.
  • Discretionary bonus program.
  • Relocation assistance.
  • Employee Wellbeing Program: 24/7 access to specialists in finance, legal matters, family care, personal health, fitness, and nutrition.
About AtkinsRéalis

We’re AtkinsRéalis, a world‑class engineering services and nuclear organization. We connect people, data and technology to transform the world's'infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. We’re committed to leading our clients across our various end markets to engineer a better future for our planet and its people.

Find out more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Cloud Infrastructure Engineer
Hybrid Cloud Infrastructure Engineer

AtkinsRéalis • Bengaluru

Hybrid
INR 3,000,000 - 5,000,000
Comprehensive life insurance
Premium medical insurance
Flexible and hybrid work solutions
+4
Application Security Architect
Application Security Architect

Mettler-Toledo, Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,000,000
Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
+1
Automation Engineer
Automation Engineer

Snc-Lavalin • Bengaluru

On-site
INR 1,500,000 - 2,400,000
Life insurance
Medical insurance
Annual leave
+4
Senior Engineer (Electrical Designer)
Senior Engineer (Electrical Designer)

Snc-Lavalin • Cyber City

Hybrid
INR 2,000,000 - 4,000,000
Life insurance
Medical insurance
Annual leave
+1
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Nuclear Safety Engineer
Nuclear Safety Engineer

AtkinsRéalis • Gurugram District

Hybrid
INR 1,500,000 - 2,300,000
Life insurance
Medical insurance
Generous annual leave
+4
Senior Manager - Project Planning & Controls
Senior Manager - Project Planning & Controls

AtkinsRéalis • Mumbai

On-site
INR 3,500,000 - 6,000,000
Life insurance
Medical insurance
Relocation assistance
+2
Assistant Project Manager
Assistant Project Manager

Snc-Lavalin • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Life insurance
Medical insurance
Annual leave
+4
Project Coordinator
Project Coordinator

Snc-Lavalin • Bengaluru

Hybrid
INR 600,000 - 1,000,000
Life Insurance
Medical Insurance
Annual Leave
+5
Airport Systems – IT / ICT (SME)
Airport Systems – IT / ICT (SME)

AtkinsRéalis • Mumbai

Hybrid
INR 3,000,000 - 5,500,000
Life insurance
Medical insurance
Annual leave
+4