Product Security Advisor
On-siteChennai, Tamil Nadu, India
Job Summary
Conduct threat modeling using frameworks like STRIDE and PASTA to identify control gaps, while advising product development teams on secure coding practices and secure SDLC processes. Partner with architecture groups to embed secure-by-design principles, lead security design reviews, and analyze results from application security tooling to ensure vulnerabilities are remediated before production deployment. Collaborate with engineering, audit, and compliance teams to maintain audit-ready documentation for standards such as PCI-DSS, CIS, and SOC 2, providing periodic education to staff on emerging threats and industry trends.
Required Qualifications
- 5+ years of experience in cybersecurity, product security, or security architecture in a technology-related industry
- 3+ years of information security experience in a hybrid cloud environment
- In depth experience secure coding practices, threat modeling, secure architecture design, and secure SDLC/CICD pipelines
- Prior experience in software development or engineering
- In-depth technical experience identifying and advising on the remediation of application security vulnerabilities on cloud and web-based applications
- Demonstrated ability as a proactive action-oriented problem solver in complex technology and organizational environments
- Experience in presenting to senior technology and information security executives and in influencing stakeholders to achieve strategic objectives
- Experience in working with industry frameworks and standards such as OWASP, PCI, CIS, and NIST
- A BA/BS degree in a computer science or technology related field
- Ability to travel domestically up to 15% of time
Desired Qualifications
- Information Security certifications including CISSP, SSCP, CSSLP are preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.