Padmi

AI Product Security - AppSec - Assistant Manager (Kolkata)

IndiaPosted 2 months ago
CybersecuritySeniorFull Time; Regular
Apply at Grant Thornton INDUS

Opens the source posting on shine.com

Source description

About the role

View original

Job ID: 865218 7 - 9 Years 1 Opening Bengaluru, Kolkata Role description Role Overview We are looking for a senior security leader to define and scale end-to-end Product Security across modern cloud-native and AI-driven systems. You will own security across the full lifecyclefrom secure design and threat modeling, to DevSecOps pipeline security, to AI/LLM security governance, to vulnerability management and PSIRT operations. This is a hands-on leadership role requiring deep technical expertise and the ability to influence engineering teams at scale while enabling fast, secure product delivery. What You Will Own (Outcomes) 1. Secure-by-Design Engineering - Define and enforce Secure SDLC standards across product engineering teams - Lead architecture-level security reviews for high-risk systems and features - Drive threat modeling (STRIDE / MITRE ATT&CK;) - Establish reusable secure design patterns (identity, secrets, crypto, data protection) 2. DevSecOps at Scale - Embed security controls into CI/CD pipelines (shift-left + shift-right) - Operationalize SAST / SCA / Secrets scanning / IaC security - Implement DAST and runtime security validation - Drive SBOM generation, artifact signing, and provenance controls - Define release security gates and remediation SLAs Embed security controls in CI/CD pipelines (pre-commit - deploy): SAST, SCA, secret scanning, IaC/K8s policy-as-code, SBOM generation, artifact signing and provenance. - Operationalize DAST via Veracode integration patterns and developer runbooks; track fix SLAs, break-glass criteria, and remediation metrics. - Partner with Cloud & Platform teams to ensure telemetry, detection, and incident hooks align with SOC/SIEM runbooks. 3. AI / LLM & Data Security - Define and implement AI/ML and LLM security controls - Secure AI lifecycle: training, inference, deployment - Mitigate prompt injection, data leakage, and model abuse risks - Enforce data protection via DLP frameworks (e.g., Microsoft Purview) - Establish AI governance, lineage, and monitoring . - Engineer AI security guardrails: prompt/input validation, output filtering, model abuse monitoring, adversarial testing (prompt injection, data exfiltration, hallucination risk), dataset/model lineage, and access controls. - Integrate AI security tests into CI/CD pipelines and enforce Microsoft Purview DLP policies to prevent data leakage in AI-assisted development. 4. Product Security Incident Response (PSIRT) - Lead vulnerability intake, triage, and coordinated disclosure - Drive patching, remediation tracking, and customer communication - Align PSIRT with supply chain and GRC frameworks - Track KPIs (MTTR, vuln aging, exploitability, SBOM coverage) 5. Security Leadership & Metrics - Define product security metrics and reporting - Influence engineering leadership and drive adoption of standards - Act as a trusted advisor across Product, Engineering, and Security teams Skills Basic Qualifications - 8+ years in Application Security / Product Security / Security Engineering - 3+ years leading DevSecOps or AppSec programs - Solid experience with CI/CD security (Azure DevOps / similar) - Hands-on expertise in SAST, DAST, SCA, threat modeling - Experience securing cloud-native systems (AWS / Azure / GCP) Preferred Qualifications - Experience in Product Security/AppSec roles at top-tier product companies - Experience building or scaling PSIRT programs - Familiarity with SBOM (SPDX / CycloneDX), SLSA, Sigstore, Cosign - Exposure to AI/ML or LLM security in production environments AI/ML Security Certifications & Coursework (Preferred) - ISO/IEC 42001 Lead Implementer (AI governance and risk management for enterprise systems) - Certified AI Risk Manager (CAIRM) (AI risk identification and mitigation) - Training aligned to NIST AI Risk Management Framework (governance, risk, and compliance for AI systems) Cloud AI & Security Certifications (Strong Practical Signal): - Microsoft Certified: Azure AI Engineer Associate - Microsoft Certified: Azure Security Engineer Associate - AWS Certified Machine Learning Specialty - AWS Certified Security Specialty Nice to have these certifications but not mandatory or core for Product Security Manager more valuable for cloud security or AI/ML engineering roles. About Grant Thornton INDUS Grant Thornton INDUS comprises GT U.S. Shared Services Center India Pvt Ltd and Grant Thornton U.S. Knowledge and Capability Center India Pvt Ltd. Grant Thornton INDUS is the shared services center supporting the operations of Grant Thornton LLP, the U.S. member firm of Grant Thornton International Ltd. Established in 2012, Grant Thornton INDUS employs professionals across a wide range of disciplines including Tax, Audit, Advisory, and other operational functions. What sets us apart isnt just what we do its how we do it. We support and enable the firms purpose of making business more personal and building trust into every result. Were collaborators Job

One address, no account. We’ll tell you when matching roles go live.

More at Grant Thornton INDUS

Related open roles

View all roles