Application Security Lead
Persistent Systems · Pune City, Maharashtra, India
Apply & track with Apply EdgeAbout Position:We are seeking a highly skilled and hands-on Application Security Lead to enhance and support the Group-wide Application Security Program. This role is pivotal in embedding security into the Software Development Lifecycle (SDLC), driving DevSecOps adoption, implementing application security automation, and partnering with development teams to mitigate application-related cyber risks across the enterprise.Role: Application Security LeadLocation: PuneExperience: Between 8 to 12 YearsJob Type: Full Time EmploymentWhat You'll Do:Application Security ProgramSupportSupport the implementation and continuous improvement of Mahindra Groups Application Security Program.Define, maintain, and enforce application security standards, processes, secure coding requirements, and governance practices.Collaborate with Cyber Security, Cloud Security, Enterprise Architecture, DevOps, and Development teams to integrate security throughout the application lifecycle.Track and report application security KPIs, KRIs, remediation status, risk exposure, and maturity progress.Secure SDLC and DevSecOps Embed security controls across all phases of the Software Development Lifecycle.Integrate security testing into CI/CD pipelines and establish risk-based security gates for application releases.Drive adoption of DevSecOps practices across internal and partner-led development teams.Support automation of application security controls, vulnerability triage, remediation tracking, and management dashboards.Security Testing and Technical AssessmentsConduct and lead secure code reviews, threat modeling, architecture security reviews, and API security reviews.Perform web, mobile, API, and cloud-native application security assessments.Review penetration testing outcomes from internal teams or third-party partners and validate remediation effectiveness.Support application-layer incident investigations, root cause analysis, and corrective action planning where required.Cloud and Modern Application Security Secure cloud-native applications deployed on AWS, Azure, or GCP.Review security of containers, Kubernetes, APIs, microservices, serverless applications, and Infrastructure-as-Code.Partner with the Principal Cloud Security and cloud platform teams to implement secure architecture patterns and preventive controls.Expertise You'll Bring:12+ years of overall IT/Cyber Security experience, with at least 7+ years in Application Security or Product Security.Strong knowledge of Secure SDLC, DevSecOps, threat modeling, secure code review, web and API security testing, mobile security, architecture reviews, and vulnerability management.Experience with Security Configuration Management in Cloud environments.Working knowledge of programming languages such as Java, .NET, Python, JavaScript, Node.js, React, REST APIs, and microservices architecture.Familiarity with security tooling such as Checkmarx, Veracode, Fortify, Burp Suite, Snyk, and Azure DevOps security controls.Experience with cloud platforms (AWS, Azure, GCP) and container security (Kubernetes, Docker).Knowledge of AI Security practices and secure AI Development Lifecycle.Familiarity with frameworks such as OWASP Top 10, NIST SSDF, and MITRE ATT&&CK.Educational background: Bachelor's degree in a relevant discipline or equivalent practical experience.Benefits:Competitive salary and benefits packageCulture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certificationsOpportunity to work with cutting-edge technologiesEmployee engagement initiatives such as project parties, flexible work hours, and Long Service awardsAnnual health check-upsInsurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parentsValues-Driven, People-Centric & Inclusive Work Environment: Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.We support hybrid work and flexible hours to fit diverse lifestyles.Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employmentLet’s unleash your full potential at Persistent - persistent.com/careers“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”