Product Security and Privacy Champion (Chennai, India) – Job ID: 47583
Profile Summary: As part of the Product Security and Privacy team, reporting to the Chief Product Security & Privacy Architect, you will provide hands‑on support to engineering teams. Working autonomously, you will be the go‑to person for all day‑to‑day security and privacy related activities. Your main goal is to coach and help teams succeed in adopting the SSDL program. You work closely with security architects, ensuring consistent quality of the program outputs and managing escalations. You will have opportunities to work on a very wide portfolio of applications based on different technologies (Web, Embedded, Mobile, Desktop) within a very diverse and international context covering all five HID Business Areas.
Qualifications
- Demonstrated experience facilitating security reviews/workshops or delivering training to engineering teams.
- Experience contributing to at least one Secure Software Development Lifecycle (SSDL) program, either as a security architect, security champion, or similar role.
- Working knowledge of general principles of application security.
- Working knowledge of threat modeling principles.
- Experience using security tools (SAST, DAST, SCA, Vulnerability Scanners, Secret Scanners).
- Hands‑on experience in at least one, preferably more, of these application domains:
- Embedded device security
- Mobile security
- Web & API security
- Desktop security
Roles & Responsibilities (Other duties may be assigned)
- Deliver Product Security & Privacy (PSP) controls and Threat Modeling face‑to‑face and virtual training sessions.
- Run PSP controls assessment working sessions.
- Facilitate threat model review sessions.
- Hands‑on support in partnership with Security Architects and engineering teams focusing on enablement, facilitation, and scalable reuse in:
- Training content creation
- Architecture Reviews/Audits
- Risk Management/Incident Handling/Tool Triage
- Implementation of Reusable Patterns
- Supply Chain Issues
- Acquisition Onboarding / Training Delivery
- External compliance activities, such as Cyber Resilience Act (CRA)
- Interpretation and training on HID internal security/privacy standards and PSP controls.
- Provide feedback and insights from engineering reality to the PSP team: what works, what doesn’t, friction points, and opportunities to improve processes, tooling, and platforms.
Preferred Qualifications
- Cloud infrastructure, Supply Chain, and Operational Security
- Experience with Agile/SAFe Methodology
- Experience with usage of AI tools in the context of a security program
- At least one security or privacy certification (CISSP, CIPT, CSSLP, CEH, …) is a plus
Education and/or Experience
- Bachelor’s Degree or equivalent experience in computer science
- 4+ years of total experience in software engineering and a strong affinity for product/application security
Soft Skills
- Ability to effectively communicate complex concepts clearly and effectively in the English language, both verbally and in writing
- Like training and knowledge‑sharing, with a strong motivation to ensure the security program is successfully implemented by the teams
- Highly adaptable and approachable, fostering collaboration and open communication
- Ability to tailor your communication to different audiences such as product owners, development teams, architects, and other high‑level users
- Strong technical acumen with the ability to engage effectively with development teams
- Continuous learning mindset
This opportunity may be open to flexible working arrangements.
HID is an Equal Opportunity/Affirmative Action Employer – Minority/Female/Disability/Veteran/Gender Identity/Sexual Orientation.