⚑ New

Product Information Security Officer

HCLSoftware

NoidaFull-timeMid LevelOn-site

Job Description

Title: Product Information Security Officer

Band: E5

Location: Noida/Bangalore

Role Overview

The Product Information Security Officer (PISO) is responsible for embedding security into product design, development, and delivery. This role bridges product management and security, ensuring that information security is a core product requirement rather than a post-release consideration. The PISO champions security best practices, manages product risk, and drives a security-conscious product culture.

Key Responsibilities

1. Product Security Architecture & Design

β€’ Define and maintain product security architecture and threat models

β€’ Conduct threat modeling for new features and systems

β€’ Lead security design reviews during product planning and architecture phases

β€’ Establish secure-by-default principles and baseline security controls

β€’ Review and approve authentication, authorization, and encryption strategies

2. Secure Development & Code Review

β€’ Establish secure coding standards and guidelines

β€’ Conduct security code reviews for high-risk features and components

β€’ Manage static application security testing (SAST) and dynamic testing (DAST) tools

β€’ Define and enforce secure SDLC practices (threat modeling, secure testing, secure deployment)

β€’ Partner with engineering to shift-left security and integrate security earlier in development

3. Vulnerability & Risk Management

β€’ Coordinate vulnerability disclosure program

β€’ Manage product vulnerability lifecycle: triage, remediation, patch coordination

β€’ Track and prioritize security debt; negotiate remediation timelines with product & engineering

β€’ Maintain product risk register and escalate critical risks to CISO and executive leadership

β€’ Perform periodic risk assessments and penetration testing

4. Compliance & Regulatory

β€’ Interpret compliance requirements (SOC 2, ISO 27001, NIS2, GDPR, CCPA) for product teams

β€’ Build compliance requirements into product roadmap early

β€’ Coordinate security evidence collection and audit readiness

β€’ Advise on data residency, encryption, and handling requirements

β€’ Partner with Legal and Compliance teams on privacy, data protection, and contractual security obligations

5. Security Culture & Engineering Education

β€’ Lead security training and awareness programs for engineering and product teams

β€’ Champion OWASP, CWE, and other security frameworks and best practices

β€’ Foster a culture of shared security responsibility; normalize security discussions

β€’ Mentor security engineers and junior team members

6. Incident Response & Post-Mortem

β€’ Lead response to security incidents affecting product

β€’ Coordinate fix validation and accelerated patch deployment

β€’ Conduct blameless security-focused post-mortems and publish lessons learned

β€’ Drive prevention of recurrence through architecture or process changes

7. Third-Party & Dependency Management

β€’ Manage vendor security assessments and risk evaluation

β€’ Define and implement software composition analysis (SCA) and dependency scanning

β€’ Establish supply chain security practices (sign, verify, binary authorization)

β€’ Evaluate security implications of new libraries, frameworks, and tools before adoption

8. Security Metrics & Reporting

β€’ Define and track product security KPIs (MTTR, vulnerability density, code coverage, etc.)

β€’ Produce monthly/quarterly security dashboards for product, engineering, and leadership

β€’ Report to Product Leadership and CISO organization

Required Qualifications

Education & Certifications:

β€’ BS in Computer Science, Information Security, or equivalent professional experience

β€’ CISSP, CCSK, or equivalent security certification

Experience:

β€’ 10+ years in information security, with 5+ years in product security or application security roles

β€’ Demonstrated experience shipping secure SaaS products at scale

β€’ Experience with threat modelling, secure SDLC, and vulnerability management

β€’ Hands-on experience with security testing tools (SAST, DAST, IAST, SCA)

β€’ Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, etc.)

Technical Skills:

β€’ Deep understanding of application security, network security, and cryptography

β€’ Proficiency with secure coding practices (OWASP Top 10, CWE, etc.)

β€’ Familiarity with modern development practices (CI/CD, containerization, microservices, cloud

platforms)

β€’ Ability to read and understand code; ideally hands-on coding ability in common languages

β€’ Experience with security architecture and design patterns

Soft Skills:

β€’ Excellent communication; ability to explain security concepts to non-technical audiences

β€’ Ability to influence without authority; strong stakeholder management

β€’ Collaborative mindset; comfortable working with product, engineering, and business teams

β€’ Strategic thinker with attention to detail and strong project management skills

β€’ Comfort with ambiguity and competing priorities; ability to prioritize ruthlessly

Preferred Qualifications

β€’ OSCP (Offensive Security Certified Professional) or similar hands-on penetration testing cert

β€’ Background in product management or start-up/scaling experience

β€’ Published security research, conference talks, or open-source security contributions

Security-Focused KPIs & Metrics

Vulnerability & Risk Management:

β€’ Mean Time To Remediate (MTTR) for critical vulnerabilities

β€’ Mean Time To Remediate (MTTR) for high vulnerabilities

β€’ Number of vulnerabilities discovered post-release

β€’ Active security debt items tracked and prioritized in roadmap

β€’ Security architecture improvements: # of systems transitioned to secure-by-design patterns

Posted Today

Related Jobs

Related Searches

Apply Now