Application Security Lead

Persistent

Pune District

Hybrid

INR 4,000,000 - 6,000,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Education sponsorship
Health & life insurance
Long service awards
Annual health check-ups
Inclusive culture

Job summary

Persistent in Pune is seeking an experienced Application Security Lead to embed security into the Software Development Lifecycle, drive DevSecOps, and advance an enterprise‑wide security program. You will partner with Cyber Security, Cloud Security, Enterprise Architecture, DevOps, and Development teams to mitigate risks across the enterprise.

The role demands 12+ years in IT/Cyber Security with at least 7+ years in Application Security, strong secure SDLC knowledge, and hands‑on expertise with

Qualifications

  • 12+ years of IT/Cyber Security experience with 7+ years in App Security
  • Strong knowledge of Secure SDLC, DevSecOps, threat modeling, and API security
  • Experience with cloud security configurations in AWS/Azure/GCP
  • Proficient in modern programming languages (Java, .NET, Python, JavaScript)
  • Familiarity with security tooling and container security (Kubernetes, Docker)
  • Bachelor's degree in a relevant discipline or equivalent experience

Responsibilities

  • Lead the Group-wide Application Security Program
  • Embed security into SDLC and DevSecOps practices
  • Define and enforce application security standards and governance
  • Collaborate with Cyber/Cloud Security, EA, DevOps, and Development teams
  • Manage KPIs, KRIs, remediation status and risk maturity
  • Perform secure code reviews, threat modeling, and architecture reviews
  • Conduct web, mobile, API, and cloud-native security assessments
  • Review pen test outcomes and validate remediation
  • Support incident investigations and root cause analyses
  • Secure cloud-native apps across AWS, Azure, and GCP

Skills

Application Security
DevSecOps
Threat Modeling
Secure SDLC
Cloud Security
Kubernetes
AWS
Azure
GCP
Java
Python
REST APIs

Education

Bachelor's degree in CS or related

Tools

Checkmarx
Veracode
Fortify
Burp Suite
Snyk
Azure DevOps security controls

Job description

About Position:

We are seeking a highly skilled and hands‑on Application Security Lead to enhance and support the Group‑wide Application Security Program. This role is pivotal in embedding security into the Software Development Lifecycle (SDLC), driving DevSecOps adoption, implementing application security automation, and partnering with development teams to mitigate application‑related cyber risks across the enterprise.


  • Role: Application Security Lead
  • Location: Pune
  • Experience: Between 8 to 12 Years
  • Job Type: Full Time Employment

What You'll Do:


  • Application Security Program
  • Support
  • Support the implementation and continuous improvement of Mahindra Groups Application Security Program.
  • Define, maintain, and enforce application security standards, processes, secure coding requirements, and governance practices.
  • Collaborate with Cyber Security, Cloud Security, Enterprise Architecture, DevOps, and Development teams to integrate security throughout the application lifecycle.
  • Track and report application security KPIs, KRIs, remediation status, risk exposure, and maturity progress.
  • Secure SDLC and DevSecOps Embed security controls across all phases of the Software Development Lifecycle.
  • Integrate security testing into CI/CD pipelines and establish risk‑based security gates for application releases.
  • Drive adoption of DevSecOps practices across internal and partner‑led development teams.
  • Support automation of application security controls, vulnerability triage, remediation tracking, and management dashboards.
  • Security Testing and Technical Assessments
  • Conduct and lead secure code reviews, threat modeling, architecture security reviews, and API security reviews.
  • Perform web, mobile, API, and cloud‑native application security assessments.
  • Review penetration testing outcomes from internal teams or third‑party partners and validate remediation effectiveness.
  • Support application‑layer incident investigations, root cause analysis, and corrective action planning where required.
  • Cloud and Modern Application Security Secure cloud‑native applications deployed on AWS, Azure, or GCP.
  • Review security of containers, Kubernetes, APIs, microservices, serverless applications, and Infrastructure-as-Code.
  • Partner with the Principal Cloud Security and cloud platform teams to implement secure architecture patterns and preventive controls.

Expertise You'll Bring:


  • 12+ years of overall IT/Cyber Security experience, with at least 7+ years in Application Security or Product Security.
  • Strong knowledge of Secure SDLC, DevSecOps, threat modeling, secure code review, web and API security testing, mobile security, architecture reviews, and vulnerability management.
  • Experience with Security Configuration Management in Cloud environments.
  • Working knowledge of programming languages such as Java, .NET, Python, JavaScript, Node.js, React, REST APIs, and microservices architecture.
  • Familiarity with security tooling such as Checkmarx, Veracode, Fortify, Burp Suite, Snyk, and Azure DevOps security controls.
  • Experience with cloud platforms (AWS, Azure, GCP) and container security (Kubernetes, Docker).
  • Knowledge of AI Security practices and secure AI Development Lifecycle.
  • Familiarity with frameworks such as OWASP Top 10, NIST SSDF, and MITRE ATT&&CK.
  • Educational background: Bachelor's degree in a relevant discipline or equivalent practical experience.

Benefits:


  • Competitive salary and benefits package
  • Culture focused on talent development with quarterly growth opportunities and company‑sponsored higher education and certifications
  • Opportunity to work with cutting‑edge technologies
  • Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
  • Annual health check‑ups
  • Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents

Values‑Driven, People‑Centric & Inclusive Work Environment:


Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.


  • We support hybrid work and flexible hours to fit diverse lifestyles.
  • Our office is accessibility‑friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
  • If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment

Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect: - Cloud + CSPM + GitHub
Security Architect: - Cloud + CSPM + GitHub

United States Digital Space LLC • Karnataka

Hybrid
INR 4,200,000 - 7,000,000
Annual health check-ups
Insurance coverage
Flexible work hours
+1
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Senior Software Engineering Lead
Senior Software Engineering Lead

Persistent Systems • Pune District

Hybrid
INR 3,500,000 - 6,000,000
Group term life
Personal accident
Mediclaim hospitalization
+2
C#.NET Lead Developer
C#.NET Lead Developer

Persistent Systems Limited • Pune District

On-site
INR 5,500,000 - 9,000,000
Competitive salary
Talent development
Cutting-edge tech
+3
Support Engineer
Support Engineer

Persistent Systems • Pune District

On-site
INR 900,000 - 1,200,000
C#.NET Lead Developer
C#.NET Lead Developer

Persistent • Pune District

On-site
INR 1,200,000 - 2,000,000
Competitive salary
Hybrid work
Healthcare coverage
+1
Cybersecurity Project Manager
Cybersecurity Project Manager

Persistent • Pune District

Hybrid
INR 1,800,000 - 3,200,000
Competitive salary
Growth opportunities
Cutting-edge technologies
+3
Application Security Architect
Application Security Architect

Mettler-Toledo, Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,000,000
Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
+1
Cloud Security & VM Lead
Cloud Security & VM Lead

Persistent • Pune District

Hybrid
INR 2,800,000 - 4,800,000
Competitive salary
Growth opportunities
Hybrid work
+3
Engineering Manager TPM
Engineering Manager TPM

Persistent Systems • Pune District

Hybrid
INR 2,000,000 - 3,000,000
Competitive salary
Insurance coverage for family
Hybrid work options
+2