Head - Security & Compliance

Novelvox

Faridabad District

On-site

INR 3,000,000 - 5,400,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Novelvox seeks a hands-on security leader to own execution, not paperwork, ensuring releases meet security expectations in regulated industries such as healthcare and banking.

This execution-first role has authority, accountability, and direct access to executive leadership, including the CEO, to drive root cause analysis, CAPA, and secure delivery practices across product and delivery teams.

Qualifications

  • 8-15 years in application security, product security, or delivery security.
  • Hands-on with API security, web apps, and SaaS platforms.

Responsibilities

  • Own the security gate for all product releases: mandatory VAPT/SAST/DAST artifacts.
  • Define non-negotiable security standards for tools, file sharing, source code handling and release artifacts.
  • Automate scans and integrate security checks into release checklists with product engineering.
  • Lead root cause analysis, CAPA, and executive-ready incident reports with customers.
  • Maintain audit-ready documentation and respond to customer audits or security reviews.

Skills

API security
Secure SDLC
Vulnerability scanning
Secure file transfer
Cloud security (AWS)

Job description

We are looking for a hands‑on security leader who owns practical security execution, not paperwork. This role exists to ensure that product releases, delivery practices, and customer interactions consistently meet security expectations especially in regulated industries like healthcare and banking.

This is not a CISO role. This is an execution‑first security leadership role with authority, accountability, and direct access to executive leadership.

Core Objective: Prevent avoidable security incidents caused by:

  • Tool misuse (e.g., Postman, file sharing)
  • Poor release hygiene
  • Delivery shortcuts under customer pressure

And when something does happen:

  • Act as the single authoritative face to customers
  • Drive root cause analysis
  • Implement permanent preventive controls
1. Security Governance (Practical, Not Bureaucratic)
  • Define non‑negotiable security standards for:
    • API testing tools
    • File sharing
    • Source code handling
    • Release artifacts
  • Convert policies into enforceable controls, not guidelines
  • Maintain a clear allowed / disallowed tools list
2. Product & Release Security
  • Own the security gate for all product releases:
    • Mandatory VAPT / SAST / DAST artifacts
    • Verification that no test code, debug flags, or credentials are included
  • Work with product engineering to:
    • Define release checklists
    • Automate scans where possible
  • Periodically review legacy components for risk exposure
3. Delivery Security & Field Discipline
  • Define secure delivery playbooks for:
    • Customer testing
    • Data exchange
    • Temporary access
  • Eliminate ad-hoc practices (e.g., Dropbox, personal tools)
  • Train delivery teams on what is never allowed, regardless of customer pressure
4. Incident Response & Customer Trust
  • Act as the single point of leadership during:
    • Security findings
    • Ethical hacking disclosures
    • Customer audits or security reviews
  • Lead:
    • Root cause analysis
    • Corrective and preventive actions (CAPA)
  • Prepare executive‑ready and customer‑ready incident reports
5. Compliance & External Readiness
  • Support security requirements for:
    • Healthcare (HIPAA)
    • Banking / Financial institutions
  • Coordinate:
    • External security consultants
    • Penetration testing vendors
  • Maintain audit‑ready documentation without slowing delivery
6. Internal Enablement (Not Just Training)
  • Design short, practical security training for:
    • Delivery teams
    • Product teams
  • Focus on real scenarios, not theoretical security
  • Continuously reinforce expectations through process and tooling
Required Experience Must-Have
  • 8-15 years in application security, product security, or delivery security
  • Hands‑on experience with:
    • API security
    • Web applications
    • SaaS platforms
  • Prior experience supporting:
    • Enterprise customers
    • Regulated industries (healthcare, banking, financial services)
  • Proven ability to push back on customers without damaging relationships
Strongly Preferred
  • Background as:
    • Senior architect
    • Principal engineer
    • Security consultant
  • Experience working in:
    • Product companies (not just IT services)
  • Exposure to:
    • SOC2, HIPAA, ISO 27001 (certification not mandatory)
Skills & Competencies Technical
  • API security & OAuth concepts
  • Secure SDLC
  • Vulnerability scanning (VAPT, SAST, DAST)
  • Secure file transfer mechanisms
  • Cloud security fundamentals (AWS preferred)
Leadership & Judgment (This Matters More)
  • Strong decision‑making under pressure
  • Willingness to say “No, this is not allowed”
  • Calm, authoritative communication with customers
  • Zero tolerance for shortcuts disguised as urgency
Best Fit Profile

This role is NOT for:

  • Policy‑only security people
  • Audit‑only professionals
  • Compliance checkbox specialists

This role IS ideal for someone who:

  • Has seen security failures caused by human shortcuts
  • Understands how delivery teams actually behave
  • Can balance speed with discipline
  • Is comfortable being unpopular when needed
Reporting & Authority
  • Reports directly to the CEO
  • Has authority to:
    • Block releases on security grounds
    • Enforce delivery security standards
    • Escalate non‑compliance immediately
Success Metrics (First 12 Months)
  • Zero repeat incidents from the same root cause
  • Clear reduction in customer‑flagged security findings
  • Consistent, audit‑ready release process
  • Increased customer confidence during security reviews
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead- Product Security
Lead- Product Security

42 Gears Mobility Systems • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Cybersecurity Engineer Engineering
Cybersecurity Engineer Engineering

Practice by Numbers • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

JobCubby • Kolkata District

On-site
INR 2,400,000 - 3,600,000
Information Technology Security Manager
Information Technology Security Manager

Accops • Pune District

On-site
INR 4,000,000 - 6,500,000
Security Architect
Security Architect

ValueLabs • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Director - Product Security
Director - Product Security

HighRadius • Hyderabad

On-site
INR 6,000,000 - 9,000,000
Competitive salary
Fun-filled work culture
Equal employment opportunities
+1
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Manager — Information Security and Compliance
Manager — Information Security and Compliance

APEX Analytix • India

On-site
USD 120,000 - 150,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000