Now hiring

TC-CS-CTM-AppSec-Manager (Bengaluru, KA, IN, 560016) @ EY Global Services

Bengaluru, KA, IN, 560016OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. </span></span></p> <p> </p> <p> </p> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>TEM Manager – DevSecOps</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">As part of our Cyber Security team, you will lead and drive Secure SDLC (SSDLC) practices across the software development lifecycle, ensuring security is embedded into design, development, testing, and deployment processes. You will be responsible for defining security standards, processes, and governance for applications, infrastructure, and enterprise systems, while guiding teams on secure engineering practices. Working closely with DevOps, Architects, Developers, and QA teams, you will enable the delivery of secure, resilient applications, oversee security assessments, and provide clear, actionable insights on risks, findings, and remediation strategies.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>The opportunity</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We’re looking for a Manager – Application Security &amp; DevSecOps with strong consulting and leadership experience. This role offers the opportunity to drive end-to-end AppSec and DevSecOps programs, working with clients and engineering teams to embed security across CI/CD pipelines. You will lead teams, engage stakeholders, and enable secure adoption of AI-driven and GenAI solutions, helping organizations scale modern, future-ready security practices.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your Key Responsibilities</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead application security consulting engagements, working closely with clients to define, design, and implement scalable AppSec and DevSecOps programs aligned to business objectives.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Manage and oversee large-scale, enterprise applications ensuring security is embedded across the SDLC.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Drive end-to-end application security program development, including governance, tooling strategy, operating model, and maturity roadmap.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform current-state DevSecOps and AppSec maturity assessments (OWASP SAMM, NIST SSDF, BSIMM), identify gaps, and provide actionable recommendations to clients.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Architect and implement DevSecOps programs, integrating security controls into CI/CD pipelines (SAST, SCA, DAST, secrets scanning, IaC, container security).</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Provide technical leadership and team management, guiding and mentoring junior consultants, reviewing deliverables, and ensuring quality outcomes.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Engage directly with client stakeholders (technical and executive), communicating risks, strategies, and security posture improvements effectively.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Translate complex security concepts into business-aligned insights for senior leadership and non-technical stakeholders.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead secure SDLC enablement, including secure coding practices, source code reviews, and vulnerability remediation guidance.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Design and implement automation strategies for security tools (SAST/DAST reporting, pipeline integrations, dashboards).</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Drive adoption of agile and lean product development principles, embedding security into iterative development cycles.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Define and implement AppSec governance frameworks, policies, standards, and metrics for continuous improvement.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support business development activities</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Develop custom security solutions and accelerators to proactively mitigate risks across the organization.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Integrate AI/ML capabilities into application security programs, including risk prioritization, anomaly detection, and intelligent vulnerability management.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead initiatives around AI security and secure adoption of GenAI/LLMs, including threat modeling, prompt security, and secure integration into enterprise environments.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Skills and Attributes for Success</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven experience in application security consulting and advisory, including client-facing program delivery.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.) updated and familiarized with the latest exploits and security trends.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong expertise in building and scaling AppSec/DevSecOps programs in enterprise environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Hands-on experience with manual and automated Threat modeling, SAST, DAST, and SCA assessments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong team management and leadership skills, with experience mentoring and managing distributed teams.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Excellent client communication and stakeholder management skills, including interaction with senior leadership.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience in designing and implementing DevSecOps CI/CD pipelines using both open-source and enterprise tools.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proficiency in scripting/programming (Python, PowerShell, Java, etc.) with awareness of latest exploits and security trends.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Familiarity with DAST tools (Acunetix, WebInspect, AppScan, Burp Suite), SAST,SCA tools (Checkmarx, Fortify, Veracode, Coverity), container and cloud security tools.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience in performing Threat modeling using STRIDE methodologies.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience integrating security into SCM platforms (GitHub, GitLab, Bitbucket) using webhooks, actions, and pipeline controls.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong knowledge of web application security (OWASP Top 10) and secure coding practices.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience across container security, IaC security, and compliance-as-code implementations.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to optimize DevSecOps pipelines and define security maturity models and KPIs.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong understanding of Agile, DevOps, and Lean development practices.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Exposure to AI/ML and GenAI technologies, including their usage in secure SDLC, automation, and developer productivity.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Understanding of AI/ML security risks (model poisoning, prompt injection, data leakage) and mitigation techniques.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience or familiarity with AI-assisted security tools (e.g., AI-driven code analysis, automated triaging, LLM-based secure coding support).</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>To qualify for the role, you must have</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">BE/ B.Tech/ MCA.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Minimum of 10 years of work experience in application security, Secure SDLC and DevSecOps.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications: Mandatory to have any one of the below certifications,</span> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Azure Security Architect (Az-500)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">AWS security speciality certification (SCS-C01)</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge of Windows, Linux, UNIX, any other major operating systems.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong Excel and PowerPoint skills.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Ideally, you’ll also have</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Project management skills</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications: CSSLP, CISSP, Certified DevSecOps Professional</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>What we look for</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A candidate who can design and build a complete DevSecOps programme and work around a maturity model, optimizing the pipeline to integrate the best tools according to the client requirement.</span></li> </ul><p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"><b>EY | Building a better working world </b> </span></span></p> <p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. </span></span></p> <p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.</span></span></p> <p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. </span></span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores