Application Security Lead

AtkinsRéalis

Bengaluru

On-site

INR 2,500,000 - 5,000,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Life insurance
Medical insurance
Generous annual leave
Hybrid work
Remote work opportunities outside of a
Bonus program
Relocation support
Wellbeing program

Job summary

AtkinsRéalis in Bengaluru, India, seeks a Global Application Security & DevSecOps Lead to own and continuously advance the organisation's AppSec across the full software development lifecycle. This role blends leadership with hands-on engineering to define the global AppSec strategy and govern the security tooling, pipelines and platforms used to secure internally developed and SaaS applications.

You will embed automated and risk-based security controls into Azure DevOps repositories and CI/CD

Qualifications

  • Maintain and evolve the global AppSec strategy and operating model.
  • Define AppSec mandate, service catalogue, governance model and engagement process.
  • Define division of responsibilities between AppSec and other security/engineering domains.
  • Develop a risk-based AppSec control framework for different application types.

Responsibilities

  • Maintain the global Application Security and DevSecOps strategy.
  • Establish the AppSec governance model and engagement process.
  • Define responsibilities between AppSec, engineering, cloud security and risk/compliance.
  • Develop risk-based security controls and release gates across the SDLC.

Skills

Azure DevOps
Security strategy
Governance

Tools

SAST tooling
SCA tooling
DAST tooling
API security tools

Job description

Overview

The Global Application Security & DevSecOps Lead is responsible for, operating and continuously improving the organisation's'application security function across the complete software development lifecycle.


The role owns the policies, technical standards, engineering controls, security testing services, Azure DevOps integrations, application security platforms and governance processes required to ensure that internally developed and externally supplied applications are designed, built, tested and released securely.


This is both a leadership and hands-on engineering role. The role holder must be capable of defining the global AppSec strategy while also configuring, integrating, operating, troubleshooting and improving the underlying security tools.


The role will embed automated and risk-based security controls into Azure DevOps repositories and CI/CD pipelines at enterprise scale, covering potentially hundreds of Azure DevOps projects and thousands of repositories.


The role is accountable for ensuring that security controls are:



  • Technically effective.

  • Integrated into engineering workflows.

  • Proportionate to application risk.

  • Reliable enough to support mandatory release gates.

  • Properly tuned to minimise false positives.

  • Measurable and auditable.

  • Supported by clear operating procedures.

  • Adopted consistently across global development teams.


Your role

AppSec strategy and operating model


The role holder will:



  • Maintain the global Application Security and DevSecOps strategy.

  • Establish the AppSec function's mandate, service catalogue, governance model and engagement process.

  • Define the division of responsibilities between AppSec, engineering, cloud security, architecture, SOC, vulnerability management, risk and compliance.

  • Develop a risk-based AppSec control framework for different application types and criticality levels.

  • Establish minimum security requirements for internally developed, externally developed and SaaS applications.


Define application risk tiers based on factors such as:



  • Data classification.

  • Internet exposure.

  • Transaction value.

  • Regulatory impact.

  • Privileged access.

  • Customer impact.

  • Business criticality.

  • Safety impact.

  • Use of AI or autonomous functionality.



  • Maintain an AppSec roadmap covering people, process, technology and maturity.

  • Undertake periodic maturity assessments against NIST SSDF and OWASP SAMM.

  • Develop annual investment, licensing and resource plans.

  • Own the AppSec tooling budget and supplier roadmap.

  • Produce executive-level risk reporting for the CISO and technology leadership.

  • Represent Application Security at architecture, engineering and risk governance forums.


AppSec service catalogue


Establish and operate defined services covering:



  • Secure code review.

  • SAST onboarding.

  • SCA onboarding.

  • DAST onboarding.

  • API security testing.

  • Mobile security testing.

  • Pipeline security assessment.

  • Secure Azure DevOps configuration.

  • Secrets scanning.

  • IaC and container scanning.

  • Penetration-test scoping and coordination.

  • AppSec exception assessment.

  • Secure release assurance.

  • Developer security training.

  • Security Champions support.

  • Supplier application security review.

  • Application incident root-cause analysis.


Secure SDLC governance


The role holder will:



  • Define mandatory security activities for each SDLC stage.

  • Establish security acceptance criteria for epics, features and user stories.

  • Define mandatory evidence required for production release.

  • Develop risk-based security release gates.

  • Ensure emergency-release procedures include proportionate security checks and retrospective review.

  • Define criteria for when applications require manual review or penetration testing.

  • Integrate AppSec activities with enterprise architecture and change-management processes.


About you

The role owns or governs the following application security capabilities:



  • Secure software development lifecycle governance.

  • Secure coding standards.

  • Static application security testing.

  • Software composition analysis.

  • Dynamic application security testing.

  • Interactive application security testing,

  • Manual secure code review.

  • Application penetration testing.

  • API security testing.

  • Cloud-native and serverless application security.

  • Container and application image security during build.

  • Infrastructure-as-code security within application delivery pipelines.

  • Secrets detection and prevention.

  • Software supply-chain security.

  • SBOM generation and governance.

  • Build provenance, artifact integrity and signing.

  • Azure DevOps repository and pipeline security.

  • Application security tool ownership and operation.

  • Security Champions and developer enablement.

  • Application security exception and risk-acceptance processes.

  • Application security metrics, reporting and assurance.

  • Third-party and externally developed software assurance.

  • Security of AI-enabled applications and AI-generated code.

  • Product security incident support and root-cause analysis.


Explicit scope boundary: not enterprise vulnerability management



  • Operating-system vulnerability scanning.

  • General infrastructure vulnerability scanning.

  • Network-device vulnerability management.

  • Endpoint vulnerability management.

  • Firmware vulnerability management.

  • Enterprise patch management.

  • Cloud-host vulnerability remediation.

  • Runtime host and virtual-machine vulnerability management.

  • General CSPM remediation ownership.

  • SOC monitoring and incident queue management.

  • Enterprise-wide CVE reporting unrelated to applications.

  • Infrastructure penetration testing.


The AppSec function nevertheless owns the management of security defects, including:



  • Validation and triage of AppSec findings.

  • Removal of false positives and duplicate findings.

  • Assignment of findings to the correct engineering teams.

  • Definition of application-security remediation requirements.

  • Verification that fixes are effective.

  • Management of AppSec-specific exceptions.

  • Reporting on application-security exposure.

  • Escalation of overdue high-risk application findings.


For containers, the function owns build-time image and Dockerfile security. Runtime host, node and deployed-container vulnerability management should remain with Cloud Security, Platform Security or Vulnerability Management, subject to a defined RACI.


Rewards & benefits

Explore the rewards and benefits that help you thrive – at every stage of your life and your career.


This includes:



  • Comprehensive life insurance coverage.

  • Premium medical insurance for you and your dependents.

  • Generous annual leave balance.

  • Flexible and hybrid work solutions.

  • Remote work opportunities outside of country.

  • Company gratuity scheme.

  • Discretionary bonus program.

  • Relocation assistance.

  • Employee Wellbeing Program: 24/7 access to specialists in finance, legal matters, family care, personal health, fitness, and nutrition.


Seize every opportunity to sharpen your skills, expand your expertise, and be recognized for the impact you make.


About AtkinsRéalis

We're AtkinsRéalis , a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world's'infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. We're committed to leading our clients across our various end markets to engineer a better future for our planet and its people.


Find out more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Lead
Application Security Lead

AtkinsRéalis • Bengaluru

Hybrid
INR 3,000,000 - 5,400,000
Comprehensive life insurance
Premium medical insurance
Generous annual leave
+6
Functional Analyst
Functional Analyst

Snc-Lavalin • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work solutions
Relocation assistance
Senior Engineer (Electrical Designer)
Senior Engineer (Electrical Designer)

Snc-Lavalin • Gurugram District

On-site
INR 1,500,000 - 2,100,000
Relocation assistance
Discretionary bonus program
Premium medical insurance
+4
Senior Mechanical Engineer
Senior Mechanical Engineer

Snc-Lavalin • Bengaluru

Hybrid
INR 1,800,000 - 3,000,000
Comprehensive life insurance coverage.
Premium medical insurance for you and/
Generous annual leave balance.
+6
Hybrid Cloud Infrastructure Engineer
Hybrid Cloud Infrastructure Engineer

AtkinsRéalis • Bengaluru

Hybrid
INR 3,000,000 - 5,000,000
Comprehensive life insurance
Premium medical insurance
Flexible and hybrid work solutions
+4
Lead Engineer - System Requirements
Lead Engineer - System Requirements

Snc-Lavalin • Bengaluru

Hybrid
INR 4,000,000 - 6,000,000
Comprehensive life insurance coverage
Premium medical insurance for depend­-
Generous annual leave balance
+2
P&C Electrical Designer/Lead Designer
P&C Electrical Designer/Lead Designer

AtkinsRéalis • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Life insurance
Medical insurance
Annual leave balance
+5
Project Coordinator
Project Coordinator

AtkinsRéalis • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Life Insurance
Medical Insurance
Annual Leave
+5
Nuclear Safety Engineer
Nuclear Safety Engineer

Snc-Lavalin • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Life Insurance
Medical Insurance
Annual Leave
+4
Quantity Surveyor | Civil | UK Experience
Quantity Surveyor | Civil | UK Experience

Snc-Lavalin • Mumbai

On-site
INR 4,000,000 - 8,000,000
Life insurance
Medical insurance
Generous leave
+5