Ideagen

Product Security Lead

Posted Date 3 weeks ago(1/20/2025 5:39 AM)
Job ID
2024-2151
# of Openings
2
Category
Information Technology
Role type
Permanent
Working
In Office
Name
India - Hyderabad

About Us

New advert image

Location - Hyderabad, India

 

Department - Legal & Compliance

 

Level - Subject Matter Expert 

 

Working Pattern - Work from office.

 

Benefits - Benefits at Ideagen

 

DEI - DEI strategy

 

Salary - this will be discussed at the next stage of the process, if you do have any questions, please feel free to reach out!

 

Ideagen is looking for Product Security Lead who will be responsible for guiding, implementing, monitoring, and managing security principles and best practices across all the products of the business line, as well as working with the Cyber Security team across the business. This role will be an invaluable addition to Ideagen’s current and growing Cyber Security arsenal, driving change, and a cyber secure work culture. 

 

Responsibilities

  • Cultivate security culture with your product technology and business colleagues. Products that have the right security culture will strive to prioritize sustainable controls and driving real risk reduction outcomes. Strong technical expertise in threat modelling is required, secure architecture design review, application security and cloud security principles. Embed the following security fundamentals such as threat modelling, solutions architecture, secure code review into agile product development by empowering technology teams to ship secure products faster that are secure from the start. Requires proactive integration into Product meetings for full understanding, and to set security expectations early in the process.
  • Know your products across their breadth and depth. Be fluent in your business line’s product's strategies and roadmaps as well as its key investment programs. Be aware of how product sits within the overarching strategy, and family portfolio. Identify unfamiliar technology components, capabilities, and business concepts and be self-motivated to learn all about them, applying critical thinking to identify hidden issues along the way. Be a subject matter expert in knowing the cyber risk posture of the entire Products.
  • Be your product's security thought leader. Learn from your product and cybersecurity teams and share best practice in both directions. Be recognized in your product as the clear point of escalation and subject matter expert for IT Risk and Cyber domains. Responsibility for adding to the Risk Register where required and following up on these actions. Main point of contact for sales account managers in reference in specific customer queries around security penetration testing, and able to identify and progress solutions.
  • Act with urgency managing emerging issues. Proactively monitor Key Risk Indicators to ensure issues are identified, quantified, communicated, and managed in a timely manner, including recommendations for resolution, and identifying the root cause/key themes.

Skills and Experience

  • Experience with cloud technologies in high availability environments.
  • Reading, interpreting and being able to deliver a business level report of penetration reports.
  • Willingness to ask questions / question current practices in search of better solutions.
  • Knowledge and experience of cloud architecture/design, security challenges, and solutions.
  • Strong project management skills for managing multiple products, testing, and reporting.
  • Experience in Network, Windows, and Linux security.
  • Basic programming/scripting skills.
  • Strong analytical skills.
  • Strong communication skills.
  • Must be willing to participate in, and be able to pass, a comprehensive background check.
  • Experience in Vulnerability Management including configuring, running, and analyzing scans (Nessus preferred).
  • Experience in Web Vulnerability Management (OWASP Top 10, CWE Top 25).
  • Experience in SIEM configuration, analysis, and reporting.
  • Experience with IPS/IDS and Data Loss Prevention tools, configuration, and analysis.
  • Experience with threat analysis and reporting.
  • Must be able to take occasional customer facing calls to discuss customer requirements including customer audits where needed.
  • Participate in tooling requirements and fully integrate business lines into any new tooling processes.
  • Understanding of CVEs, and risk priority Desirable skills.
  • Community recognized security certificates CEH, CISM, SANS (GSEC, GCIA, GCED, GCIH), CISSP.
  • Exposure to or knowledge of compliance standards such as FedRAMP, ISO 27001, SOC2/3, Cyber Essentials, and/or PCI compliance.
  • Exposure to or knowledge of DevOps/Agile development methodologies.
  • Incident Response/Forensics experience including evidence/artefact preservation.
  • Experience integrating security checks and validation into a CI/CD pipeline.
  • Amazon AWS experience.
  • AWS Certified Security - Specialty.
  • Data analytics/reporting experience.
  • Penetration Testing experience and understanding of the generated results.
  • Experience using Jira.

 

About Ideagen

 

Ideagen is the invisible force behind many things we rely on every day - from keeping airplanes soaring in the sky, to ensuring the food on our tables is safe, to helping doctors and nurses care for the sick. So, when you think of Ideagen, think of it as the silent teammate that's always working behind the scenes to help those people who make our lives safer and better. Everyday millions of people are kept safe using Ideagen software. We have offices all over the world including America, Australia, Malaysia and India with people doing lots of different and exciting jobs.

 

What is next?

 

If your application meets the requirements for this role, our Talent Acquisition team will be in touch to guide you through the next steps.

To ensure a flexible and inclusive process, please let us know if you require any reasonable adjustments by contacting us at recruitment@ideagen.com. All matters will be treated with strict confidence.

 

At Ideagen, we value the importance of work-life balance and welcome candidates seeking flexible or part-time working arrangements. If this is something you are interested in, please let us know during the application process.

 

Enhance your career and make the world a safer place!

 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.