Principal Application & Product Architect

Wolters Kluwer

Pune District

On-site

INR 2,400,000 - 4,800,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Wolters Kluwer in Pune invites a seasoned Divisional Security Lead ATHIP to champion application security across the ATHIP division. You will guide PSLs and Security Champions, shape security strategy, and partner with the AppSec CoE to embed security-by-design in development pipelines.

As a senior SME, you will drive threat modeling, risk remediation, and governance, align with GIS and DevSecOps teams, and report to the ATHIP CTO.

Qualifications

  • Bachelor's degree.
  • GIAC GSEC, CISSP, or an equivalent baseline certification and one vendor-neutral Secure SDLC/AppSec certification (e.g., CSSLP) (preferred).
  • 12+ years of experience in application/product security, software engineering, or related roles.
  • Demonstrated success leading cross-functional security initiatives and improving operational workflows.
  • In case of an internal candidate, familiarity with Wolters Kluwer security policies and standards is required, and familiarity with ATHIP products is preferred.
  • Experience managing or indirectly influencing others in a matrixed or project-based environment.
  • Proficiency in one or more modern programming languages (Java, Python, C#, JavaScript).
  • Hands-on experience with security testing tools (SAST, SCA, DAST, IaC scanning, container/runtime scanning).
  • Experience embedding security checks in CI/CD (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Bitbucket etc.).
  • Understanding of security facilities and capabilities in at least one major cloud provider (AWS, Azure, GCP).
  • Strong business acumen with understanding of secure product strategy.
  • Ability to translate strategic direction into actionable operational execution.
  • Highly organized with strong attention to detail and process discipline.
  • Effective communicator, able to influence across functions and seniority levels.
  • Demonstrated ability to manage competing priorities in a fast-paced, matrixed .

Responsibilities

  • Guide, mentor, and align PSLs and Security Champions in the ATHIP division, ensuring AppSec policies and standards are upheld.
  • Serve as the primary AppSec SME for ATHIP, providing expert guidance, incident support, and escalation for security issues.
  • Ensure continuous threat modeling, scanning, regular security reviews, and timely vulnerability remediation across ATHIP portfolios.
  • Oversee training activities as part of mentoring PSLs and Security Champions, and ensure PSLs and Champions are enabled and empowered.
  • Provide quarterly AppSec briefings to the ATHIP CTO and prepare monthly AppSec reports.
  • Collaborate with GIS to support NIST attestation, incident management and exception filing.
  • Collaborate with the DevSecOps CoE in driving integration of security controls in CI/CD pipelines (SAST, SCA, DAST, container scanning, IaC checks) to track provenance and protect the integrity of software.
  • Validate and enforce ASVS-based security requirements across ATHIP services and applications.
  • Nominate, assess, and guide PSLs and Security Champions; provide fallback if PSLs/Champions are unavailable.
  • Collaborate with product managers, architects, Privacy Champions, and other CoEs to balance security and privacy requirements.
  • Participate in and drive AppSec CoE strategic programs, including AppSec Metrics & Resources, AppSec Tools Deployment, ASVS Gap Assessment & Remediation, and SBOM/Supply Chain Management.
  • Contribute to the AppSec CoEs mission and align with its goals to equip teams with standards, tools, and training to identify and fix security issues early and efficiently.

Skills

Java
Python
C#
JavaScript

Education

Bachelor's degree

Tools

SAST
SCA
DAST
IaC scanning
Container scanning
CI/CD security

Job description

Join us at Wolters Kluwer and be part of a dynamic global technology company that makes a difference every day. Were innovators with impact. We provide expert software and information solutions that the worlds leading professionals rely on, in the moments that matter most.

As part of this mission, were looking for a driven and experienced Divisional Security Lead ATHIP (Advanced Technology and Health) to join our Application Security Center of Excellence (AppSec CoE).

About the role:

The Divisional Security Lead (DSL) for ATHIP is a senior Application Security SME embedded within the AppSec CoE and the ATHIP divisional CTO team. This role is responsible for ensuring that AppSec policies, standards, and best practices are consistently applied across all ATHIP development teams, and for guiding and aligning Portfolio Security Leads (PSLs) and Security Champions within the division.

The DSL acts as the central point of contact for application security strategy, training, and governance in ATHIP, and is empowered to drive divisional AppSec initiatives, provide expert guidance, and escalation for security issues. The DSL operates with autonomy and seniority, reporting administratively to the Director of AppSec CoE and functionally to the ATHIP CTO.

The AppSec CoE is a centralized, cross-functional team that provides standardized tools, SOPs, and expert guidance for security-by-design development. It supports a federated model with a central team and a virtual network of Security Champions and Leads, collaborating with other Centers of Excellence and GIS teams to deliver secure, compliant, and innovative solutions.

The DSL role is responsible for aligning Application Security practices in the ATHIP division with Application Security CoE roadmap, best practices and initiatives to establish consistency across DXG organization.

Essential Duties and Responsibilities:
  • Guide, mentor, and align Portfolio Security Leads (PSLs) and Security Champions in the ATHIP division, ensuring AppSec policies and standards are upheld.
  • Serve as the primary AppSec SME for ATHIP, providing expert guidance, incident support, and escalation for security issues.
  • Ensure continuous threat modeling, scanning, regular security reviews, and timely vulnerability remediation across ATHIP portfolios.
  • Oversee training activities as part of mentoring PSLs and Security Champions, and ensure PSLs and Champions are enabled and empowered.
  • Provide quarterly AppSec briefings to the ATHIP CTO and prepare monthly AppSec reports.
  • Collaborate with Global Information Security (GIS) to support NIST attestation, incident management and exception filing.
  • Collaborate with the DevSecOps CoE in driving integration of security controls in CI/CD pipelines (SAST, SCA, DAST, container scanning, IaC checks) to track provenance and protect the integrity of software.
  • Validate and enforce ASVS-based security requirements across ATHIP services and applications.
  • Nominate, assess, and guide PSLs and Security Champions; provide fallback if PSLs/Champions are unavailable.
  • Collaborate with product managers, architects, Privacy Champions, and other CoEs to balance security and privacy requirements.
  • Participate in and drive certain AppSec CoE strategic programs, including AppSec Metrics & Resources, AppSec Tools Deployment, ASVS Gap Assessment & Remediation, and SBOM/Supply Chain Management.
  • Contribute to the AppSec CoEs mission and align with its goals to equip teams with standards, tools, and training to identify and fix security issues early and efficiently.
Job Qualifications:
  • Bachelors degree.
  • GIAC GSEC, CISSP, or an equivalent baseline certification and one vendor-neutral Secure SDLC/AppSec certification (e.g., CSSLP) (preferred).
  • 12+ years of experience in application/product security, software engineering, or related roles.
  • Demonstrated success leading cross-functional security initiatives and improving operational workflows.
  • In case of an internal candidate, familiarity with Wolters Kluwer security policies and standards is required, and familiarity with ATHIP products is preferred.
  • Experience managing or indirectly influencing others in a matrixed or project-based environment.
  • Proficiency in one or more modern programming languages (Java, Python, C#, JavaScript).
  • Hands-on experience with security testing tools (SAST, SCA, DAST, IaC scanning, container/runtime scanning).
  • Experience embedding security checks in CI/CD (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Bitbucket etc.).
  • Understanding of security facilities and capabilities in at least one major cloud provider (AWS, Azure, GCP).
  • Strong business acumen with understanding of secure product strategy.
  • Ability to translate strategic direction into actionable operational execution.
  • Highly organized with strong attention to detail and process discipline.
  • Effective communicator, able to influence across functions and seniority levels.
  • Demonstrated ability to manage competing priorities in a fast-paced, matrixed .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application & Product Architect
Principal Application & Product Architect

wk • India

On-site
INR 4,000,000 - 6,500,000
Application Security Team Lead
Application Security Team Lead

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Lead Security Engineer
Lead Security Engineer

Rwindia • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Head of Application Security
Head of Application Security

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 4,000,000 - 7,000,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX

Global Software Solutions Group • Bengaluru

On-site
INR 2,500,000 - 5,000,000