Senior Manager - Application Security & AI Security

Pine Labs

Dadri

On-site

INR 4,500,000 - 7,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Pine Labs is seeking a Senior Manager – Application Security to lead and strengthen security across Application, AI, API, Mobile, and SAST initiatives. The role partners with Engineering, Product, Infrastructure, and Compliance to embed secure practices in the SDLC and drive a security-first culture.

The ideal candidate brings deep expertise in Secure SDLC, AI Security, DevSecOps, Cloud Security, API Security, and Security Automation, with proven leadership of high-performing security teams.

Qualifications

  • Bachelor's or Master's degree in Computer Science, IT, Cyber Security or related field.
  • 12+ years of Information Security experience.
  • 10+ years in Application Security or Product Security leadership roles.
  • Proven experience leading enterprise AppSec programs in cloud-native environments.
  • Strong understanding of DevSecOps and modern software engineering practices.

Responsibilities

  • Define, implement, and improve Secure SDLC practices across the org.
  • Conduct security architecture reviews, secure design assessments, and threat modeling.
  • Perform application security assessments for web, cloud-native, and microservices apps.
  • Drive vulnerability management and remediation programs.
  • Establish secure coding standards and security requirements.
  • Remediate vulnerabilities with engineering teams throughout the software lifecycle.
  • Lead AI security reviews, governance, and risk assessments.
  • Define API security governance and assess API risks.
  • Drive SAST strategy and security automation across teams.
  • Coach developers on secure coding and security best practices.

Skills

Application Security
Secure SDLC
Threat Modeling
Secure Design Reviews
Secure Coding Practices
OWASP Top 10
Vulnerability Assessment & Penetration

Education

Bachelor's or Master's degree in Computer Science/IT/Cyber Security

Tools

Checkmarx
GitHub Advanced Security

Job description

We're Hiring | Senior Manager – Application Security (AppSec)

Work Mode: 5 Days Work from Office (No Remote/Hybrid)

Role Overview

We are looking for an experienced Senior Manager – Application Security to lead and strengthen our Application Security, AI Security, API Security, Mobile Security, and Secure Code (SAST) programs.

This leadership role will drive secure engineering practices across the organization by embedding security into every stage of the software development lifecycle. You will partner closely with Engineering, Product, Infrastructure, and Compliance teams to build scalable, cloud-native, and secure applications.

The ideal candidate brings deep expertise in Application Security, Secure SDLC, AI Security, DevSecOps, Cloud Security, API Security, Mobile Security, Secure Code Reviews, and Security Automation, along with proven experience leading high-performing security teams.

Key Responsibilities
Application Security
  • Define, implement, and continuously improve Secure SDLC practices across the organization.
  • Conduct security architecture reviews, secure design assessments, and threat modeling exercises.
  • Perform application security assessments for web, cloud-native, and microservices-based applications.
  • Drive vulnerability management and remediation programs.
  • Establish secure coding standards and security requirements.
  • Partner with engineering teams to remediate security vulnerabilities throughout the software lifecycle.
AI Security
  • Establish enterprise-wide AI/LLM security standards and governance.
  • Conduct security reviews and threat modeling for AI, GenAI, LLM, Agentic AI, and RAG-based applications.
  • Assess risks related:
  • AI Supply Chain Risks
  • Evaluate security controls for MCP-based solutions and third-party AI integrations.
  • Enable secure adoption of AI technologies across the organization.
API Security
  • Define API Security governance aligned with the OWASP API Security Top 10.
  • Perform API security assessments and threat modeling.
  • Review authentication, authorization, encryption, and access control mechanisms.
  • Ensure secure implementation of OAuth 2.0, OpenID Connect, JWT, and API Gateway security controls.
  • Maintain API inventory and assess third-party API risks.
  • Lead Android and iOS application security assessments.
  • Establish mobile security standards aligned with OWASP MASVS.
  • Review:
  • Secure Storage
  • Encryption
  • Certificate Pinning
  • Anti-Tampering Controls
  • Manage mobile penetration testing and remediation programs.
  • Own the organization's Secure Code (SAST) strategy.
  • Deploy and manage SAST solutions across engineering teams.
  • Perform secure code reviews.
  • Validate remediation of identified vulnerabilities.
  • Define vulnerability management SLAs.
  • Optimize SAST rules to reduce false positives.
  • Coach developers on secure coding best practices.
DevSecOps & Security Automation
  • Integrate security controls into CI/CD pipelines.
  • Implement and manage:
  • SAST
  • DAST
  • SCA
  • Secrets Scanning
  • Container Security
  • Infrastructure as Code (IaC) Security
  • Automate security testing and compliance validation.
  • Implement security gates and risk-based approval workflows.
  • Drive Shift-Left Security practices across engineering teams.
Governance & Compliance
  • Develop and maintain application security policies and standards.
  • Track AppSec KPIs and security posture metrics.
  • Support compliance with:
  • PCI DSS
  • ISO 27001
  • RBI Guidelines
  • DPDP
  • Other regulatory frameworks
  • Participate in audits and enterprise risk assessments.
  • Drive Security Champion and developer awareness programs.
Leadership & Stakeholder Management
  • Lead and mentor Application Security Engineers and Security Analysts.
  • Collaborate with Product, Engineering, Infrastructure, Architecture, and Compliance teams.
  • Present security risks, remediation plans, and KPIs to senior leadership.
  • Define and execute the Application Security roadmap and maturity initiatives.
Required Skills & Expertise

Application Security

  • Secure SDLC
  • Threat Modeling
  • Secure Design Reviews
  • Secure Coding Practices
  • OWASP Top 10
  • Vulnerability Assessment & Penetration Testing

SAST & Code Security

  • Checkmarx
  • GitHub Advanced Security (CodeQL)

API Security

  • OWASP API Security Top 10
  • OAuth 2.0
  • OpenID Connect
  • JWT
  • API Gateway Security
  • API Testing & Security Validation

AI Security

  • GenAI Security
  • LLM Security
  • RAG Security
  • AI Threat Modeling
  • MCP Security Reviews
Required Experience
  • Bachelor's or Master's degree in Computer Science, Information Technology, Cyber Security, or a related field.
  • 12+ years of overall Information Security experience.
  • Minimum 10 years of experience in Application Security or Product Security leadership roles.
  • Proven experience leading enterprise Application Security programs in cloud-native environments.
  • Strong understanding of modern software engineering practices and DevSecOps.
What We're Looking For
  • Passion for building secure software at scale.
  • Ability to influence engineering teams and embed security into product development.
  • Strong leadership, stakeholder management, and communication skills.
  • Experience driving security transformation in fast-paced technology organizations.
What You Should Be Comfortable With
  • Working from the office 5 days a week.
  • Challenging conventional thinking and driving innovation.
  • Taking ownership of large-scale security initiatives.
  • Working in a fast-paced, high-impact engineering environment.
What We Value

You Take the Shot

You make decisions with confidence and execute with speed.

You act like the CEO of your work, taking complete ownership and accountability.

You Craft with Pride

You continuously learn, strive for excellence, and take pride in building secure, world-class products.

If you're passionate about building secure engineering ecosystems and shaping the future of Application & AI Security, we'd love to hear from you.

  • This version is optimized for LinkedIn with clear headings, concise bullets, recruiter-friendly keywords, and improved readability while preserving all of the technical depth.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Team Lead
Application Security Team Lead

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Architect
Application Security Architect

Mettler-Toledo, Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,000,000
Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
+1
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Application Security Manager
Application Security Manager

InMobi Advertising • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Vice President, Application Security
Vice President, Application Security

Saviynt Inc. • Bengaluru

Hybrid
INR 3,000,000 - 4,500,000