





Niche AppSec plus FSI audit needs and seniority reduce applicant density despite Bengaluru metro.
Role requires deep AppSec, cloud security, and financial-institution audit experience, limiting cross-industry fit.
Explicit 10+ years, 4+ years leading, and mandatory FSI AppSec experience create strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and grow a multi-disciplinary Security Engineering team managing Secure SDLC, AppSec, and cloud security across the product portfolio.
Own Secure SDLC governance, threat modelling, vulnerability operations, and supply chain security strategies with measurable impact on security posture and remediation timelines.
Act as technical SME for financial-institution customer audits, direct incident response, external penetration tests, and security program reporting to senior leadership and boards.
10+ years in application/product and cloud security, including 4+ years leading AppSec or Security Engineering teams.
Experience running Secure SDLC programs for B2B software vendors in regulated financial services.
Hands-on familiarity with at least two security frameworks such as OWASP SAMM, BSIMM, or AWS SRA plus strong AWS cloud security knowledge.
Proven experience integrating security tooling into CI/CD pipelines and leading customer/regulator security audit responses.
Experienced in managing security engineering teams in regulated financial services software environments with direct Secure SDLC ownership.
Strong operational background in AppSec tooling (SAST, DAST, SCA, ASPM), cloud security posture, and vulnerability management integrated at scale.
Comfortable engaging with senior leadership and external auditors, with hands-on approach to complex security initiatives including emerging AI/LLM risks.