Role Overview
We are looking for a senior security leader to define and scale end-to-end Product Security across modern cloud-native and AI-driven systems.
You will own security across the full lifecycle—from secure design and threat modeling, to DevSecOps pipeline security, to AI/LLM security governance, to vulnerability management and PSIRT operations.
This is a hands-on leadership role requiring deep technical expertise and the ability to influence engineering teams at scale while enabling fast, secure product delivery.
What You Will Own (Outcomes)
1. Secure-by-Design Engineering
- Define and enforce Secure SDLC standards across product engineering teams
- Lead architecture-level security reviews for high-risk systems and features
- Drive threat modeling (STRIDE / MITRE ATT&CK)
- Establish reusable secure design patterns (identity, secrets, crypto, data protection)
2. DevSecOps at Scale
- Embed security controls into CI/CD pipelines (shift-left + shift-right)
- Operationalize SAST / SCA / Secrets scanning / IaC security
- Implement DAST and runtime security validation
- Drive SBOM generation, artifact signing, and provenance controls
- Define release security gates and remediation SLAs
Embed security controls in CI/CD pipelines (pre-commit- deploy): SAST, SCA, secret scanning, IaC/K8s policy-as-code, SBOM generation, artifact signing and provenance.
- Operationalize DAST via Veracode integration patterns and developer runbooks; track fix SLAs, break-glass criteria, and remediation metrics.
- Partner with Cloud & Platform teams to ensure telemetry, detection, and incident hooks align with SOC/SIEM runbooks.
3. AI / LLM & Data Security
- Define and implement AI/ML and LLM security controls
- Secure AI lifecycle: training, inference, deployment
- Mitigate prompt injection, data leakage, and model abuse risks
- Enforce data protection via DLP frameworks (e.g., Microsoft Purview)
- Establish AI governance, lineage, and monitoring .
- Engineer AI security guardrails: prompt/input validation, output filtering, model abuse monitoring, adversarial testing (prompt injection, data exfiltration, hallucination risk), dataset/model lineage, and access controls.
- Integrate AI security tests into CI/CD pipelines and enforce Microsoft Purview DLP policies to prevent data leakage in AI-assisted development.
4. Product Security Incident Response (PSIRT)
- Lead vulnerability intake, triage, and coordinated disclosure
- Drive patching, remediation tracking, and customer communication
- Align PSIRT with supply chain and GRC frameworks
- Track KPIs (MTTR, vuln aging, exploitability, SBOM coverage)
5. Security Leadership & Metrics
- Define product security metrics and reporting
- Influence engineering leadership and drive adoption of standards
- Act as a trusted advisor across Product, Engineering, and Security teams
Basic Qualifications
- 8+ years in Application Security / Product Security / Security Engineering
- 3+ years leading DevSecOps or AppSec programs
- Strong experience with CI/CD security (Azure DevOps / similar)
- Hands-on expertise in SAST, DAST, SCA, threat modeling
- Experience securing cloud-native systems (AWS / Azure / GCP)
Preferred Qualifications
- Experience in Product Security/AppSec roles at top-tier product companies
- Experience building or scaling PSIRT programs
- Familiarity with SBOM (SPDX / CycloneDX), SLSA, Sigstore, Cosign
- Exposure to AI/ML or LLM security in production environments
AI/ML Security Certifications & Coursework (Preferred)
- ISO/IEC 42001 Lead Implementer (AI governance and risk management for enterprise systems)
- Certified AI Risk Manager (CAIRM) (AI risk identification and mitigation)
- Training aligned to NIST AI Risk Management Framework (governance, risk, and compliance for AI systems)
Cloud AI & Security Certifications (Strong Practical Signal):
- Microsoft Certified: Azure AI Engineer Associate
- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Machine Learning – Specialty
- AWS Certified Security – Specialty
Nice to have these certifications but not mandatory or core for Product Security Manager more valuable for cloud security or AI/ML engineering roles.
Grant Thornton INDUS is the global capability center for Grant Thornton US, the U.S. member firm of Grant Thornton International Ltd., a leading global network of independent audit, tax, and advisory firms. Founded in Chicago in 1924, Grant Thornton US is one of the leading accounting and advisory firms in the U.S., bringing together $4B+ in revenue, 56 U.S. offices, and a multi-national platform spanning 20 countries with 25,000 people. It combines deep expertise, advanced technology, and a collaborative mindset to help clients solve complex challenges and grow with confidence. Since 2012, Grant Thornton INDUS has brought together 3,300+ professionals across Tax, Audit, Advisory, Client Services, Innovation, and Enabling Functions to deliver high-impact solutions for Grant Thornton US and its global network. Recognized as a Great Place To Work® for three consecutive years and among India’s Top 15 Best Workplaces™ in Professional Services 2026, INDUS offers a high-performance culture where people are trusted, supported, and empowered to grow.