Enter a job title or keyword

Manager – SSDLC


Job Location:

Mumbai - India

Monthly Salary: Not provided by the employer
Posted: 30 September 2026 (Yesterday)
Application Deadline: 28 December 2026
Vacancies: 1 Vacancy

Job Summary

Role Name

Job Title

Manager - Application Security

Reporting Structure

Reports to Senior/Chief Manager or AVP

Education

BE/BCA/BTECH/ or any IT Graduate from government authorised university

Experience/ Qualifications

  • Excellent written and verbal communication skills in English high integrity strong work ethic and ability to empathize with the customer.
  • 7 years in experience in application security with 2 years leading technical teams.
  • Experience of large organization Bank or global IT or consulting firm is desired.
  • Strong background of Application Security Secure Software Development Lifecycle (SSDLC).
  • Strong background in secure coding ( php Python C# etc.) and CI/CD tools.
  • Strong experience in Application Security Testing - SCA SAST & DAST.
  • Expert knowledge of Agile and DevSecOps maturity models.
  • Exposure of application security tools integration in DevOps architecture.
  • Exposure of Microservices security API security and AI security.
  • Exposure of evaluation and implementation of Application Security & Testing tools.
  • Troubleshooting and problem-solving ability including analytical thinking and strong attention to details.
  • Good understanding of Application Security Standards like OWASP SANS NIST MAITRE etc.
  • Good understanding of Security by Design and Privacy by Design principles.
  • Exposure of cloud application (SaaS) security solutions is desirable.
  • Good understanding of encryption tools and technologies; SSL Keys Management HSM and PKI infrastructure and secrets management.

Responsibilities

  • Plan and lead the execution of application security assessment. Manage a team of Secure Software Development Lifecycle (SSDLC) engineers.
  • Manage mentor and task a team of allocated SSDLC engineers.
  • Drive secure coding practices automation continuous assessment and vulnerability remediation across design development and deployment.
  • Manage the integration of SAST DAST and SCA tools into CI/CD pipelines.
  • Evaluate and establish standards for ongoing manual and automated security code reviews.
  • Prioritize and track vulnerabilities from discovery to engineering remediation.
  • Enforce security quality gates before code deployment to production.
  • Define and track AppSec metrics (e.g. time-to-remediate defect density) for leadership.
  • Prepare weekly/monthly service delivery reports and review with BU Head and VH.
  • Provide advice on Secure coding best practices. Conduct Application Security related trainings for team and developers.
  • Review Standards & SOPs Secure Coding best practices.
  • Conduct Project Delivery reviews with software development Project Managers.
  • Ensure periodic open-source dependency checks and code reviews for projects during development and during the production lifecycle.
  • Face internal and external audits for the scope of service delivery.
  • Participate in security risk assessments and -up and transfer interdisciplinary knowledge.
  • Review of effectiveness of application security controls and preparing Risk dashboards.
  • Collaborate with internal and external stakeholders for timely delivery of the assigned engagements/projects.
  • Reviewing the status of the projects and taking corrective/preventive measures as approved.
  • Provide service delivery inputs to PMO & other relevant systems.
  • Provide SME advice on security tool capabilities and configuration adjustmentswhen needed to contain security incidents or block future security attacks.
  • Participate in continual improvement and benchmarking activities.
  • Contribute to CoE initiatives and other activities delegated by BU Head or Vertical Head.

Certifications

ISO 27001 CISSP CISA CISM CCSP CSSLP CEH CASE CSSD GWEB CMWPT GPEN API Security Architect

Location

Navi Mumbai


Required Skills:

7 years in experience in application security with 2 years leading technical teams.