Назад
Company hidden
обновлено 13 часов назад

Product Security Advisor (Cybersecurity)

Формат работы
remote (только India)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
India
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Advisor (Cybersecurity): Ensuring secure-by-design product development across the lifecycle with an accent on secure coding, vulnerability management, threat modeling, and cloud application security. Focus on leading security design reviews, embedding secure architecture patterns, analyzing SAST/SCA/IAST/CNAPP findings, and supporting compliance with OWASP, CIS, PCI-DSS, SOC 2, and FedRAMP requirements.

Location: Chennai; remote position with occasional in-person attendance at work-related events and up to 15% domestic travel.

Company

hirify.global's Global Technology team develops secure, reliable, market-ready products for customers, consumers, and colleagues.

What you will do

  • Advise product engineering teams on secure coding, vulnerability management, and secure software development lifecycle processes.
  • Support adoption of SAST, SCA, IAST, and CNAPP tooling and analyze findings to prevent vulnerabilities from reaching production.
  • Conduct threat modeling using STRIDE, PASTA, and MAESTRO frameworks.
  • Lead security design reviews and embed secure-by-design principles into product architecture.
  • Partner with audit and compliance teams to document controls, prepare evidence, and respond to CIS, SOC 2, PCI-DSS, and FedRAMP audits.
  • Provide security education, presentations, mentoring, and stakeholder guidance across Global Technology.

Requirements

  • 5+ years of experience in cybersecurity, product security, or security architecture.
  • 3+ years of information security experience in a hybrid cloud environment.
  • In-depth experience with secure coding, threat modeling, secure architecture design, and secure SDLC/CI/CD pipelines.
  • Prior software development or engineering experience and hands-on application security vulnerability remediation for cloud and web applications.
  • Experience with OWASP, PCI, CIS, and NIST frameworks and standards.
  • A BA/BS degree in computer science or a related technology field.

Nice to have

  • Information security certifications such as CISSP, SSCP, or CSSLP.
  • Experience presenting to senior technology and information security executives and influencing stakeholders.

Culture & Benefits

  • Remote work with occasional in-person work-related events.
  • Work/life flexibility and resources supporting professional and personal development.
  • Opportunities to collaborate across a global technology organization and contribute to secure products.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →