Responsibilities
Conduct risk assessments and threat modeling
Perform security architecture, design, and software security reviews
Interpret results from security tests and scanners (e.g. SAST, DAST, SCA) and
guide development teams on riskbased prioritization and remediation ...
Consult product teams on secure development practices: secure architecture,
secure coding, and security testing, contribute security guidance, best
practices, and lightweight training
Facilitate and continuously improve the Secure Software Development
Lifecycle (SSDLC) and support consistent SSDLC adoption across different
product types and technologies
Support and grow the Security Champion community through mentoring and
knowledge sharing
Provide input to crossproduct security frameworks and maturity improvements
Work with the Software Security Lead on governance, standards, and strategic
initiatives
Required qualifications
Minimum 7 years of experience in secure software development
o Experience with Javabased web applications and at least one other
programming language / tech stack (preferably C#) in development
teams
o Proven experience implementing or working within an SSDLC
Minimum 4 years of experience in security engineering roles
o Handson experience with threat assessments and security reviewso Solid understanding of common software security risks and mitigations
o Strong ability to communicate security findings clearly to engineering
teams
Good to have
Experience with IEC 62443
Familiarity with OWASP SAMM
Experience supporting or running a Security Champion program
Experience in mixed hardwaresoftware or industrial environments
Experience with GenAI usage in software development
Ways of working
Part of a centralized security function under the guidance of the Software
Cyber Security Lead
Works crossproduct with multiple development teams across R&D sites in
Gurugram and Munich
Riskbased, pragmatic approach focused on enablement and collaboration
Operates with a high degree of independence, proactively shaping and driving
software security practices
experience
12show more Responsibilities
Conduct risk assessments and threat modeling
Perform security architecture, design, and software security reviews
Interpret results from security tests and scanners (e.g. SAST, DAST, SCA) and
guide development teams on riskbased prioritization and remediation
Consult product teams on secure development practices: secure architecture,
secure coding, and security testing, contribute security guidance, best
practices, and lightweight training
Facilitate and continuously improve the Secure Software Development
Lifecycle (SSDLC) and support consistent SSDLC adoption across different
product types and technologies
Support and grow the Security Champion community through mentoring and
knowledge sharing
Provide input to crossproduct security frameworks and maturity improvements
Work with the Software Security Lead on governance, standards, and strategic
initiatives
Required qualifications
Minimum 7 years of experience in secure software development
o Experience with Javabased web applications and at least one other
programming language / tech stack (preferably C#) in development
...
teams
o Proven experience implementing or working within an SSDLC
Minimum 4 years of experience in security engineering roles
o Handson experience with threat assessments and security reviewso Solid understanding of common software security risks and mitigations
o Strong ability to communicate security findings clearly to engineering
teams
Good to have
Experience with IEC 62443
Familiarity with OWASP SAMM
Experience supporting or running a Security Champion program
Experience in mixed hardwaresoftware or industrial environments
Experience with GenAI usage in software development
Ways of working
Part of a centralized security function under the guidance of the Software
Cyber Security Lead
Works crossproduct with multiple development teams across R&D sites in
Gurugram and Munich
Riskbased, pragmatic approach focused on enablement and collaboration
Operates with a high degree of independence, proactively shaping and driving
software security practices
experience
12show more