DIRECTOR - Application Security

Happiest Minds Technologies

Bengaluru

On-site

INR 400,000 - 1,000,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Happiest Minds Technologies seeks a visionary Practice Head to lead Application Security, Red Teaming and TVM, owning the practice strategy and roadmap. You will shape delivery, governance, and client advisory in a senior leadership capacity across complex environments.

You will manage talent, drive offensive security programs, and partner with engineering and executive teams to align security priorities with business goals in India’s major tech hubs.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cyber Security, Information Technology, or a related field.
  • 10–15 years of deep hands-on experience across offensive security, application testing, and vulnerability management.
  • Minimum 3–5 years of experience leading and scaling cybersecurity teams or practices in India.

Responsibilities

  • Define vision and strategy for AppSec, Red Teaming, and TVM offerings.
  • Oversee practice growth, budgeting, tooling, and vendor partnerships.
  • Establish modern delivery frameworks, playbooks, and reporting structures for offensive operations.
  • Mentor and upscale a high-performing team of ethical hackers and AppSec engineers.

Skills

AppSec leadership
Red Teaming
TVM
Secure SDLC
Threat Modeling
SAST
DAST
SCA
CI/CD DevSecOps
MITRE ATT&CK
OWASP
Cloud security
Python/PowerShell

Education

Bachelor's or Master’s degree in CS/Cyber Security/IT

Tools

Burp Suite
Metasploit
Cobalt Strike
Qualys
Nessus
Checkmarx

Job description

Practice Head ? Application Security, Red Teaming, & Threat/Vulnerability Management (TVM)

Location: India (Major Tech Hubs: Bengaluru / Mumbai / NCR / Hyderabad / Pune)
Experience Required: 10?15 Years
Employment Type: Full-time, Permanent

Position Overview

We are seeking a visionary, highly technical, and strategically minded Practice Head to lead, scale, and mature our Application Security (AppSec), Red Teaming, and Threat & Vulnerability Management (TVM) cybersecurity division.

In this senior leadership role, you will take full ownership of the practice, driving technology roadmaps, managing P&L, nurturing top-tier offensive security talent, and acting as a trusted advisor to executive stakeholders. You will balance a deep technical background in adversary simulation and secure software development with strong business acumen to protect our enterprise ecosystem and clients.

Key Responsibilities
1. Practice Leadership & Strategy
  • Define the vision and strategy for the AppSec, Red Teaming, and TVM service offerings, aligning them with overall enterprise risk management goals.
  • Oversee practice growth, resource allocation, budgeting, tool evaluation, and vendor partnerships.
  • Establish modern delivery methodologies, frameworks, playbooks, and standardized reporting structures for offensive operations.
  • Serve as a thought leader, representing the firm at cybersecurity conferences and driving internal security advocacy.
2. Technical Governance & Execution
  • Application Security (AppSec): Drive Secure SDLC practices by embedding threat modeling, secure code reviews (SAST), dynamic testing (DAST), and Software Composition Analysis (SCA) into advanced CI/CD DevSecOps pipelines.
  • Red Teaming & Adversary Simulation: Oversee sophisticated cyber-attack simulations across cloud environments (AWS/Azure/GCP), complex Active Directory setups, and network architectures using frameworks like MITRE ATT&CK.
  • Threat & Vulnerability Management (TVM): Architect enterprise-wide vulnerability discovery, prioritization, validation, and remediation programs. Ensure seamless transition of threat intelligence into proactive testing parameters.
3. Team Management & Mentorship
  • Lead, mentor, and upscale a high-performing team of ethical hackers, AppSec engineers, and security analysts.
  • Build a continuous-learning culture focused on reverse engineering, exploit development, and emerging threat research.
4. Stakeholder & Cross-Functional Alignment
  • Translate highly technical vulnerability and attack path findings into clear, business-relevant risk profiles for engineering leads and C-suite executives.
  • Coordinate with DFIR, SOC, and Threat Intelligence teams during active incident response or post-assessment reviews.
Required Skills and Qualifications
Education & Experience
  • Bachelor?s or Master?s degree in Computer Science, Cyber Security, Information Technology, or a related field.
  • 10?15 years of deep hands-on experience across offensive security, application testing, and enterprise vulnerability management.
  • Minimum 3?5 years of experience leading and scaling cybersecurity teams or practices in India.
Technical Proficiencies
  • Core Methodologies: Expert knowledge of OWASP (Web/API/Mobile Top 10), SANS Top 25, MITRE ATT&CK framework, and NIST standards.
  • Offensive Security Tooling: In-depth knowledge of platforms like Burp Suite, Metasploit, Cobalt Strike, Qualys, Nessus, and Checkmarx.
  • Cloud & Infrastructure: Proven architecture security knowledge of AWS, Azure, or GCP alongside containerized security (Kubernetes/Docker).
  • Automation: Scripting fluency in Python, PowerShell, Bash, or Go to customize attack payloads and automate security tests.
Preferred Professional Certifications

Candidate must possess one or more recognized advanced credentials:

  • Offensive: OSCP (Mandatory/Highly Preferred), OSCE, OSWE, GXPN, CRTO.
  • Management/Governance: CISSP, CISM, or equivalent.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Associate Director/Director-Cyber Security-Tech Risk
Associate Director/Director-Cyber Security-Tech Risk

Pierag Consulting • Gurugram District

On-site
INR 1,500,000 - 3,000,000
T&T | Cyber: D&R | Manager | Vulnerability Assessment & Penetration Testing (VAPT) | Bengaluru
T&T | Cyber: D&R | Manager | Vulnerability Assessment & Penetration Testing (VAPT) | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 4,000,000 - 7,000,000
SENIOR ARCHITECT - Penetration Testing
SENIOR ARCHITECT - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Principal Penetration Tester/ Offensive Security Team Lead
Principal Penetration Tester/ Offensive Security Team Lead

BreachLock Inc. • Pune District

On-site
INR 5,000,000 - 7,500,000
Principal Penetration Tester/ Offensive Security Team Lead
Principal Penetration Tester/ Offensive Security Team Lead

BreachLock, Inc. • Dadri

On-site
INR 1,500,000 - 2,000,000
239939-Manager
239939-Manager

EXL • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Job Role : Manager/ Assistant Manager – Offensive Security Expert- Red Team
Job Role : Manager/ Assistant Manager – Offensive Security Expert- Red Team

Multi Commodity Exchange Clearing Corporation Limited (MCXCCL • Mumbai

On-site
INR 1,500,000 - 2,800,000
Application Security Analyst – Java / DevSecOps
Application Security Analyst – Java / DevSecOps

Hireflex247 India Private Limited • India

On-site
INR 1,500,000 - 2,700,000