Tower Lead (Support & Operations)

HCL Technologies Limited

Pune District

On-site

INR 4,500,000 - 7,000,000

Full time

28 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

HCL Technologies Limited in Pune seeks an experienced Application Security specialist (L3 SME) with 14+ years in secure SDLC, DevSecOps, and vulnerability management to lead advanced findings and governance.

You will mentor L2 engineers, coordinate with security architecture, risk, and external testers, and drive policy-driven security gates and onboarding of applications into AppSec tools. Strong hands-on with SAST/DAST, OWASP Top 10, and CI/CD integration is required.

Qualifications

  • Hands-on experience with SAST, SCA, DAST, API security testing, secret scanning, container/image scanning.
  • Strong understanding of OWASP Top 10, CWE, CVSS, secure coding practices.
  • Experience triaging findings, validating false positives, and providing remediation guidance.
  • Experience supporting app onboarding into AppSec tools and secure-SDLC workflows.

Responsibilities

  • Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, and operating-model improvement.
  • Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
  • Mentor L2 engineers and coordinate with security architecture, engineering, risk, external testing providers, and application owners.

Skills

SAST & SCA
DAST
API security testing
Secret scanning
Container security
OWASP Top 10
CWE/CVSS
CI/CD security
Threat modeling
Remediation guidance

Education

Bachelor's degree in Computer Science/IT

Tools

Jira
ServiceNow
Wiz Code

Job description

  • 14+ years of experience in Application Security, secure SDLC,DevSecOps, application-security architecture, and vulnerability management.

General Description

  • Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, andoperating-model improvement.
  • Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
  • Mentor L2 engineers andcoordinatewith security architecture, engineering, risk, external testing providers, and application owners.
Key Responsibilities
Years of Experience
  • 14+ years of experience in Application Security, secure SDLC,DevSecOps, application-security architecture, and vulnerability management.
General Description
  • Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, andoperating-model improvement.
  • Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
  • Mentor L2 engineers andcoordinatewith security architecture, engineering, risk, external testing providers, and application owners.
Skill Requirements
Technical Requirements
  • Hands-on experience with SAST, SCA, DAST, API security testing,secretsscanning, container/image scanning, and cloud-code security tools such as Wiz Code or equivalent.
  • Strong understanding of OWASP Top 10, CWE, CVSS, secure coding practices, vulnerability lifecycle, and risk-based prioritization.
  • Experience triaging application-security findings,validatingfalse positives, assigning severity, andprovidingremediation guidance.
  • Experience supporting application onboarding into AppSec tools andsecure-SDLCworkflows.
  • Experience with Jira/ServiceNow, finding backlogs, exception workflows, evidence preparation, and AppSec reporting.
  • Understanding of CI/CD security integration and policy-driven security gates.
  • Deepexpertisein advanced web, API, cloud-native, container, microservices, authentication, authorization, cryptography, and business-logic vulnerabilities.
  • Experience defining AppSec standards, threat-modeling approaches, secure-design reviews, testing strategies, and risk-based remediation models.
  • Ability to review complex Java/Spring Boot, Angular, Python, API, AWS, and Kubernetes/EKS application architectures.
  • Experience designing and integrating AppSec controls into CI/CD pipelines, including policy-as-code and release-security gates.
  • Ability to lead tool tuning, false-positive reduction, coverage analysis, AppSec metrics, exception governance, and maturity improvement.
  • Experience supporting regulatory/audit evidence and communicating application risk to senior stakeholders.
Soft Skills
  • Excellent communication and presentation skills.
  • Strong problem-solving and critical thinking skills.
  • Exceptional project management and organizational abilities.
  • Team collaboration and leadership skills.
  • Client-focused approach with a commitment to delivering exceptional customer service.
Certifications (Good to have)

Good to have relevant certificates like (any of the below):

  • CSSLP, OSWE, GWAPT, GWEB, CISSP, or equivalent advanced application-security certification.
  • Cloud-security orDevSecOpscertification is preferred.
Educational Qualifications
  • University degree in IT or/and IT Security.
  • Bachelor’s degree in computer science/ IT or any relevant fields.

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Lead
Technical Lead

HCL Technologies Limited • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Track Lead - Security Analysis, SIEM
Track Lead - Security Analysis, SIEM

HCL Technologies Limited • Lucknow

On-site
INR 2,500,000 - 4,000,000
Open Source COE Security Architect
Open Source COE Security Architect

Hewlett Packard Enterprise • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Azure DevOps Senior Technical Specialist
Azure DevOps Senior Technical Specialist

HCL Technologies Limited • Nagpur District

On-site
INR 2,400,000 - 4,000,000
Open Source COE Security Architect
Open Source COE Security Architect

Hewlett Packard Enterprise Development LP • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Health & Wellbeing
Personal & Professional Development
Unconditional Inclusion
Sr Subject Matter Expert (Support&Ops)
Sr Subject Matter Expert (Support&Ops)

HCL Technologies Limited • Pune District

On-site
INR 350,000 - 700,000
Senior Technical Lead
Senior Technical Lead

HCL Technologies Limited • India

On-site
INR 1,500,000 - 2,100,000
Software Security Developer (C, C++, Security Protocols)
Software Security Developer (C, C++, Security Protocols)

Hewlett Packard Enterprise • Bengaluru

Hybrid
INR 1,500,000 - 2,700,000
Career development programs
Inclusive culture
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Security Lead
Security Lead

Hewlett Packard Enterprise • Mumbai

On-site
INR 4,000,000 - 7,000,000