Head of Product Security

Accops

Pune District

Hybrid

INR 6,000,000 - 9,000,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote-friendly within India
Competitive pay

Job summary

Accops is seeking a hands-on Head of Product Security to own security from code to customer incident response. You will lead the product security testing team, perform white-box testing with access to code, and oversee incident response, forensics and disclosure across all products.

You will report to the CEO/CTO, work remotely within India, and drive security across gateways, client apps (Windows, macOS, Linux, mobile), web portals and cloud services.

Qualifications

  • 10+ years in software/security roles with hands-on security research and testing.
  • Strong hands-on code review and white-box testing ability across languages.
  • Experience in incident response, forensics and vulnerability management.
  • Proven track record leading security testing teams and mentoring engineers.
  • Excellent written and spoken English and customer-facing communication.

Responsibilities

  • Lead the product security testing team and set standards for releases across gateways, clients, web portals and cloud services.
  • Perform white-box testing with access to code and designs; develop exploits and PoCs when needed.
  • Direct incident response and forensics, establish root cause and drive fixes to closure.
  • Manage vulnerability intake, CVE handling and coordinated disclosure with auditors.

Skills

Security research
Penetration testing
Code review
Incident response
Forensics
Team leadership
Communications
English proficiency

Tools

Burp Suite
IDA/Ghidra

Job description

Accops is hiring a hands-on Head of Product Security to own the security of every product we ship from source code to customer incident response.

Experience: 10+ years total, including 5+ years in hands‑on security research / pen testing

Background: Former software engineer turned security researcher

Reports to CEO / CTO

Team

Leads the product security testing team

About Accops and the role

Accops builds secure remote access and Zero Trust products, including the HySecure ZTNA line, used by enterprises, banks and government organisations. Our customers trust us to sit at the edge of their networks, so the security of our own code is the product.

You will be the single owner of product security: you decide what gets tested, find the hard bugs before attackers do, lead the response when something goes wrong, and speak for Accops to customers when they ask how secure we are.

What you’ll own

Lead the security testing team

  • Build, mentor and manage the product security / pen testing team; set hiring bar, career paths and quality standards.
  • Own the security testing plan for every release across gateway, client (Windows, macOS, Linux, mobile), web portals and cloud services.
  • Define severity ratings, SLAs for fixes, and release sign-off criteria.

Secure code review and white-box testing

  • Run white-box pen tests with full code and design access; write exploits and proof‑of‑concepts to prove impact.
  • Lead threat modelling and design reviews for new features and architecture changes.
  • Embed SAST, DAST, SCA, fuzzing and secrets scanning into CI/CD, and tune them so engineers trust the results.

Incident response and forensics

  • Lead technical investigation of security incidents involving Accops products, in‑house and at customer sites.
  • Perform log, memory, disk and network forensics; establish root cause, blast radius and timeline.
  • Drive fixes, hotfixes and post‑incident reviews through to closure.

Vulnerability management and disclosure

  • Run the intake and triage of vulnerabilities from researchers, customers, bug bounty and third‑party audits.
  • Own CVE assignment, security advisories and coordinated disclosure.
  • Manage external pen test vendors and certification audits (e.g. CERT‑In empanelled audits, ISO 27001, SOC 2 evidence).

Customer communication

  • Be the trusted security voice of Accops to customers: CISOs, bank and government security teams, and auditors.
  • Write and present clear advisories, incident reports and root‑cause analyses for both technical and executive audiences.
  • Answer security questionnaires, join customer calls during incidents, and handle tough conversations with calm and transparency.
  • Brief the leadership team regularly on product security posture and risk.

What you bring (must‑have skills)

  • 10+ years of experience, starting as a software engineer who shipped production code, followed by 5+ years focused on security research and penetration testing.
  • Deep hands‑on skill in source code review and white‑box testing; able to read unfamiliar code quickly and find logic, memory‑safety and auth flaws.
  • Strong command of network and application security: TLS/PKI, VPN and tunnelling, SSO (SAML, OIDC, OAuth), MFA, OWASP Top 10, API security.
  • Experience with exploit development and PoC writing; comfortable with tools like Burp Suite, IDA/Ghidra, debuggers and fuzzers.
  • Practical incident response and forensics experience: log analysis, memory and disk forensics, attacker timeline reconstruction.
  • Proven record of leading or mentoring a security testing team.
  • Excellent written and spoken English; has handled customer‑facing security discussions, advisories or incident calls with senior stakeholders.
  • High integrity and sound judgement with sensitive information.

Nice to have

  • Published CVEs, conference talks (e.g. Nullcon, c0c0n, DEF CON, Black Hat) or bug bounty hall‑of‑fame credits.
  • Certifications such as OSCP, OSWE, OSED, OSCE3, GXPN or GCFA.
  • Background in ZTNA, VPN, VDI, identity or endpoint security products.
  • Experience with Windows kernel/driver, macOS or Linux client internals.
  • Familiarity with Indian regulatory expectations (RBI, SEBI, CERT‑In) and secure SDLC frameworks (OWASP SAMM, NIST SSDF).

What success looks like

First 90 days: a clear map of the attack surface across all products, a prioritised risk backlog, and a team operating on agreed severity SLAs.

First year:

  • Every major release passes a white‑box review and sign‑off before GA.
  • Critical and high findings fixed within agreed SLAs.
  • A tested incident response playbook, with customer communication templates.
  • A public vulnerability disclosure policy and advisory process in place.
  • Customers and auditors see Accops product security as a strength in deals and renewals.
  • Own product security end to end at a company whose products protect critical enterprise and government access.
  • Work directly with the founders, with real authority to block a release on security grounds.
  • Build and shape your own team.
  • Remote‑friendly within India, with competitive pay.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineering Manager
Engineering Manager

Accops • Pune District

On-site
INR 1,500,000 - 2,500,000
Head - Security & Compliance
Head - Security & Compliance

Novelvox • Faridabad District

On-site
INR 3,000,000 - 5,400,000
Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • India

On-site
INR 3,500,000 - 5,500,000
Remote-first environment
In-person team sprints abroad
Learning budget USD 2,000 (annual)
Threat Researcher II (AEV)
Threat Researcher II (AEV)

Balbix, Inc. • New Delhi

On-site
INR 1,400,000 - 2,200,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Threat Researcher II (AEV)
Threat Researcher II (AEV)

Lever, Inc. • New Delhi

On-site
INR 1,800,000 - 2,400,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Senior InfoSec Analyst
Senior InfoSec Analyst

ACKO • Bengaluru

On-site
INR 2,000,000 - 3,500,000
Head- Security Operations & Security Architecture
Head- Security Operations & Security Architecture

airtel • Gurugram District

On-site
INR 2,000,000 - 3,000,000
Vulnerability Researcher II
Vulnerability Researcher II

Safe • New Delhi

On-site
INR 1,800,000 - 3,000,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Senior InfoSec Analyst
Senior InfoSec Analyst

ACKO Technology & Services Private Limited • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Lead- Product Security
Lead- Product Security

42 Gears Mobility Systems • Bengaluru

On-site
INR 4,000,000 - 6,400,000