Loading open roles
Loading open roles
Loading role

Vrinda Global · posted 2 months ago
Basic Function
We are looking for a forward-thinking and skilled Application Security Leader
to strengthen and drive our Application
Security practice, with a focus on DevSecOps and cloud-native applications in
EXL, a $2B Nasdaq-listed global
cloud-native organization. This role demands a visionary leader with extensive
experience in securing complex,
multi-cloud and AI-based solutions/applications.
This role is crucial as we enhance our digital business capabilities,
especially in the context of handling sensitive
Health and Insurance data.
The ideal candidate will have a proven track record of developing and
implementing robust application security
programs, ensuring the protection of critical business applications and data,
and leading a high-performing team of
security professionals.
Collaborate with senior management and department leaders to identify
opportunities to improve EXL’s cloud
security posture and establish a roadmap to mature the application security
program.
Essential Functions
Strategic Leadership:
o Develop and execute a comprehensive application security strategy that
aligns with the
organization’s business goals and technology landscape.
o Lead and mentor a global team of application security professionals,
fostering a culture of
excellence and continuous improvement.
Collaboration and Integration:
o Collaborate with development, DevOps, and IT teams to integrate security
practices into the
software development lifecycle (SDLC) and DevOps processes.
o Knowledge of secure coding principles and practices to prevent
vulnerabilities such as SQL
injection, XSS, and CSRF.
o Experience with static application security testing (SAST), dynamic
application security testing
(DAST), and interactive application security testing (IAST) tools.
o Work closely with product management and engineering teams to ensure
security
requirements are defined and implemented in new products and features.
o Establish and enable a high security baseline for all container environments
across
repositories, CI/CD pipelines and runtime analysis.
Threat Management and Vulnerability Assessment:
o Oversee the identification and assessment of application security threats,
vulnerabilities, and
risks.
o Implement and manage vulnerability management programs, including regular
security
assessments, penetration testing, and code reviews.
Regulatory Compliance and Reporting:
o Ensure compliance with relevant regulatory requirements and industry
standards.
o Prepare and present regular reports on the status of application security
programs, metrics,
and incidents to executive leadership and the board of directors.
Innovation and Continuous Improvement:
o Stay abreast of emerging security trends, threats, and technologies, and
continuously evaluate
and improve the organization’s application security posture.
o Foster a culture of innovation, encouraging the adoption of advanced
security technologies
and practices.
Primary Internal Interactions
Works in a consultative fashion with cross-functions EXL teams (Cloud CCOE,
Domain Platform, Legal,
Global Technology, Compliance) and external partners, advising on Cloud
Security opportunities in a
collaborative to improve information security efficiency and effectiveness
Primary External Interactions
Interaction with vendors/ OEMs during Design, Implementation and
Troubleshooting and ongoing service
management.
Organizational Relationships
Reports To : VP-II and Head of Cyber
Supervises : Team of highly focused subject matters Security Analysts (L1, L2,
L3), Security Infrastructure
Administrators, AM and LAMs; External partner resources
Skills:
Technical Skills
Deep knowledge of application security frameworks, standards, and best
practices.
Proficiency in secure coding practices, threat modeling, and security
testing
methodologies.
Strong understanding of cloud platforms (AWS, Azure, GCP) and their security
features.
o Cloud security administration
o Cloud security architecture
o Cloud network engineering
o Cloud engineering
o Cloud governance
o Container security or engineering
Offensive Security
o Vulnerability Management
o Minimum security Baseline
o Secure Configuration Audit
o Application Security
o Breach Attack Simulation
Security Architecture
o Threat Modelling
o Architecture Review
o Business Impact Analysis
Process Specific
Skills
Working, real-world, knowledge of operationalizing cloud native security tools
at scale
(AWS Guard Duty, AWS WAF, GCP Security Center)
Soft skills (Minimum)
- Ability to handle senior management escalation
- Vendor management Skills
- Effective communication
- Proficient team leader
- Business Acumen
- Decision making and communication
- Risk management skills
- Knowledge of latest cybersecurity trends & global industry best
practices pertaining to
financial Industry
Soft Skills (Desired) Operational experience in a Global-multi Industry-Regulated-Growth business
environment
Knowledge of Advanced Cyber Security Capabilities in the Industry
JD Template– AM’s & Above
FORM/109
Internal Version 2.0 Page 3 of 4
Cyber Risk Management mindset
Self-Started & Sense of Purpose
Education Requirements
Engineering graduate with certification in CISSP / CCSP, ISO Lead Auditor etc
Work Experience Requirements
Should have a minimum of 12 years of overall cyber security experience,
preferably with wide exposure to
various security domains such as Architecture, Application Security,
Compliance, Security Operations etc.
5+ years of industry experience in Cloud Security Architecture with strong
demonstrable knowledge of Cloud
Security related to Multi-Cloud environments - Containerization, Cloud
Security Architecture, Cloud Identity
Management, encryption, Key Management, S-SDLC, DevSecOps, etc.