Security Lead_ Trivandrum
VGreen Technology Solutions (VGreenTEK)
Location: Thiruvananthapuram, Kerala
Job Type: Full Time / Employment
Work Mode: Work from Office
Joining: Immediate
Department: Cyber Security
Experience: 10+ years in Information Security, including 4+ years in a Security Leadership role
Required Skills:
- Security Governance & Architecture: Own application, platform, and software security across all Scrum pods; establish the security control framework aligned with ISO 27001 and applicable government security standards, covering application/infrastructure architecture, authentication, authorization, data protection, APIs, dependencies, deployment, and security controls.
- Secure SDLC & DevSecOps: Define and govern Secure SDLC standards, secure coding practices, SAST/DAST gates, dependency scanning, threat modelling, CI/CD security gates, and provide technical security direction to DevOps for implementing pipeline security controls across all delivery pods.
- Vulnerability, Testing & Remediation: Own vulnerability management including scanning cadence, vulnerability triage, remediation tracking, security reviews, penetration-test scoping, and remediation verification; identify and manage security risks and ensure appropriate controls are implemented before release.
- IAM, Data Protection & Risk Management: Provide technical direction on IAM, authentication, authorization, cryptography, encryption, key management, application/infrastructure security, and formal security risk assessment/treatment planning; maintain the security risk register and escalate material risks to the Engineering Manager.
- Leadership, Compliance & Qualifications: Lead security workstreams across multiple teams and collaborate with Enterprise Architecture, Engineering, DevOps, QA, and development teams; support audits, accreditation, and client security assurance. Bachelor's degree in CS/IT or related field; CISSP required or equivalent demonstrable seniority, with ISO 27001 LA/LI preferred. CISM/equivalent, government/national-security or border/identity platform experience, and HSM/PKI design are advantageous.