Job Description: Head of Product Security- LTTS
Role:
Head of Product Security
Location:
Bangalore
Reporting To:
Head - Cybersecurity Practice
Role Overview
LTTS is seeking an experienced and visionary Head of Product Security to lead
our end-to-end product cybersecurity offerings across industries. This leader
will drive strategy, architecture, frameworks, compliance, secure development
lifecycle, and advisory engagements for global OEMs and industrial
enterprises.
You will work closely with engineering teams, customer CISOs, product
managers, OT leaders, and LTTS cybersecurity leadership to deliver world‑class
secure product engineering services.
This is a high-impact role for someone who can blend deep technical expertise,
industry frameworks, and business leadership.
Key Responsibilities
1. Product Security Strategy & Leadership
-
Define and own LTTS’ product security strategy, offerings, accelerators, and
solution stacks.
-
Establish organization-wide standards for secure product engineering across
embedded, IoT, industrial, and cloud‑connected systems.
-
Represent LTTS in CISO-level discussions, industry consortiums, and global
product security forums.
2. Secure Development Lifecycle (SDLC)
-
Build and institutionalize a comprehensive PS-SDLC incorporating threat
modeling, secure coding, security design reviews, automated testing, and
release governance.
-
Enable integration of security checkpoints across product roadmaps, agile
cycles, and DevSecOps pipelines.
3. Vulnerability & Risk Management
-
Lead vulnerability discovery, triage, and remediation governance for product
lines across firmware, applications, cloud backends, and OT systems.
-
Oversee VEX, SBOM management, and zero-trust design principles for
engineering programs.
4. Standards, Compliance & Certification
Drive customer programs aligned with:
-
UL 2900, IEC 62443, ISO 21434, ISO 27001, NIST 800 series, FDA cybersecurity
requirements, EU CRA, and global product security standards.
-
Support customers in passing external audits and product security
certifications.
5. Architecture & Technical Leadership
-
Review and define secure architectures across embedded systems, connectivity
stacks, industrial controllers, digital platforms, and cloud services.
-
Provide guidance on cryptography, identity, secure boot, secure firmware
updates, key management, and data protection mechanisms.
6. Customer Delivery & Practice Growth
-
Lead product security engagements for global OEMs across industrial, energy,
automotive, medical, and hi‑tech verticals.
-
Build a strong product security team and mentor architects, PMs, and
engineers.
-
Develop reusable frameworks, IPs, and accelerators to scale LTTS’
cybersecurity business.
Required Qualifications
-
12–18 years of experience in product, embedded, or platform security, with
at least 5+ years in a leadership role.
-
Strong knowledge of embedded systems, IoT, IIoT, OT, cloud architectures,
and API-based ecosystems.
-
Hands-on expertise in threat modeling (STRIDE, attack trees), secure design,
secure coding, fuzzing, SAST/DAST, container security, and crypto
frameworks.
-
Proven experience working with global OEMs or regulated industry clients.
-
Experience in driving compliance for IEC 62443, ISO 21434, UL 2900, or
similar frameworks.
Preferred Skills
-
Experience with SBOM/VEX tools (e.g., Cybeats, Finite State, Synopsys, SPDX/
CycloneDX frameworks).
-
Exposure to AI security and emerging agentic AI risks.
-
Experience in OT cybersecurity, ICS protocols, and industrial architectures.
-
Strong stakeholder management and ability to engage with CXO-level leaders.
-
Thought leadership experience-blogs, conferences, patents, or whitepapers.