← Back to jobs

Application Security Lead

Persistent Systems · Security DU6 · Lead

Apply ↗
Location
Pune, Maharashtra, India
Employment type
Full-time
Posted
18-Aug-2026

Skills

["Security Configuration Management - Cloud""Cloud Security"]

Technology stack

{}

Description

About Persistent We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what's next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem. Our disruptor's mindset, commitment to client success, and agility to thrive in the dynamic environment have enabled us to sustain our growth momentum. Persistent has been recognized across top industry platforms for innovation, leadership, and inclusion. We reported $1,654.4M FY26 revenue with 17.4% Y-o-Y growth. We have delivered 24 sequential quarters of growth with $436.0M in Q4 FY26 revenue, up 3.2% Q-o-Q and 16.2% Y-o-Y growth. Our 27,500+ global team members, located in 18 countries, have been instrumental in helping the market leaders transform their industries. We have been recognized as the Fastest Growing IT Services Brand Globally in the 2026 Brand Finance IT Services 25 Report. We named a Leader in the Everest Group Private Equity (PE) Services PEAK Matrix Assessment 2026 and Software Product Engineering PEAK Matrix Assessment 2026. About Position: We are seeking a highly skilled and hands-on Application Security Lead to strengthen and support the enterprise-wide Application Security Program. The ideal candidate will possess deep expertise in Application Security, Secure Software Development Lifecycle (Secure SDLC), DevSecOps, Cloud Security, Vulnerability Management, and Secure Architecture practices. In this role, you will be responsible for embedding security throughout the software development lifecycle, driving security automation, enhancing vulnerability management processes, and partnering with development, cloud, DevOps, and architecture teams to reduce cyber risk across enterprise applications. You will serve as a trusted security advisor and help establish best-in-class application security practices across modern cloud-native and enterprise environments. Role: Application Security Lead Location: Pune Experience: 8 to 12 Years Job Type: Full-Time Employment What You'll Do: Support the implementation and continuous improvement of the enterprise Application Security Program. Define, maintain, and enforce secure coding standards, security policies, and application security governance practices. Establish application security controls aligned with business and regulatory requirements. Collaborate with Cyber Security, Cloud Security, Enterprise Architecture, DevOps, and Engineering teams to integrate security across the development lifecycle. Track and report application security KPIs, KRIs, risk metrics, and remediation progress. Drive security awareness and promote a security-first culture across development teams. Embed security controls across all phases of the Software Development Lifecycle (SDLC). Integrate security testing capabilities into CI/CD pipelines. Implement and enforce risk-based security gates for application releases. Drive adoption of DevSecOps practices across development and engineering teams. Automate security testing, vulnerability management, policy enforcement, and reporting workflows. Support continuous improvement of secure development practices and release processes. Conduct secure code reviews and application security assessments. Lead threat modeling exercises and architecture security reviews. Perform web application, mobile application, API security, and cloud-native application security assessments. Review findings from penetration tests and validate remediation efforts. Identify security weaknesses and provide actionable remediation recommendations. Support security investigations, root cause analysis, and post-incident reviews where required. Evaluate application designs and implementation approaches from a security perspective. Secure cloud-native applications deployed across AWS, Azure, and GCP environments. Conduct security reviews of containers, Kubernetes platforms, microservices, APIs, serverless applications, and Infrastructure-as-Code deployments. Partner with cloud platform teams to implement secure architecture patterns and preventive security controls. Support cloud security posture improvement initiatives. Evaluate security controls across modern application architectures and distributed environments. Own the end-to-end application vulnerability management lifecycle. Review findings from SAST, DAST, SCA, API Security, Container Security, and Penetration Testing tools. Validate vulnerabilities and prioritize remediation activities based on risk and business impact. Track remediation progress and ensure timely closure of security findings. Conduct vulnerability governance reviews with application and engineering teams. Escalate critical security risks and remediation delays when required. Support exception management and risk acceptance processes. Act as the primary Application Security advisor for development and engineering teams. Conduct secure coding workshops, developer training sessions, and security awareness programs. Provide guidance on secure design, architecture, and implementation practices. Work with third-party vendors and development partners to ensure compliance with security requirements. Communicate security risks and recommendations to technical and business stakeholders. Expertise You'll Bring: Bachelor's or Master's degree in Computer Science, Cyber Security, Information Security, Information Technology, Engineering, or a related discipline. 8-12 years of overall experience in IT, Cyber Security, Application Development, or Information Security. Minimum 7 years of experience in Application Security, Product Security, DevSecOps, or Secure Engineering. Strong expertise in Secure SDLC and application security best practices. Deep understanding of DevSecOps methodologies and security automation. Hands-on experience with threat modeling and architecture security reviews. Experience conducting secure code reviews and application security testing. Strong knowledge of web application security, API security, mobile security, and microservices security. Experience implementing and governing vulnerability management programs. Strong understanding of OWASP Top 10 vulnerabilities and secure coding principles. Hands-on experience with SAST, DAST, SCA, API Security, and penetration testing tools. Experience with security tools such as Checkmarx, Veracode, Fortify, Burp Suite, Snyk, and similar platforms. Working knowledge of programming languages including Java, .NET, Python, JavaScript, Node.js, and React. Experience reviewing REST APIs, application integrations, and distributed architectures. Understanding of cloud security principles across AWS, Azure, and GCP. Knowledge of CI/CD pipelines and security integration within software delivery processes. Experience with Security Configuration Management and security controls in cloud environments. Strong analytical, troubleshooting, and risk assessment skills. Excellent communication and stakeholder management capabilities. Ability to communicate complex security concepts to both technical and non-technical audiences. Experience mentoring engineering teams and driving security transformation initiatives. Benefits: Competitive salary and benefits package Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications Opportunity to work with cutting-edge technologies Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards Annual health check-ups Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents Values-Driven, People-Centric & Inclusive Work Environment: Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds. We support hybrid work and flexible hours to fit diverse lifestyles. Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities. If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment Let's unleash your full potential at Persistent - persistent.com/careers “Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”

Requirements

["Security Configuration Management - Cloud", "Cloud Security"]

Roles & responsibilities

[]

About

All jobs →