# Security Engineering Manager

**Company:** [Smartstream Limited](http://jobs.workable.com/companies/xrHunSPFFf6yxYNqT477c2.md)
**Location:** Bengaluru, India
**Workplace:** hybrid
**Employment type:** Full-time
**Department:** Product Management

[Apply for this job](http://jobs.workable.com/view/b7b3c94e-8435-4513-ba99-f915e6cdef4e)

## Description

The Security Engineering Manager leads day-to-day operations of the Smartstream Security Engineering organisation - a Centre of Excellence team, that closely collaborates with embedded Security Engineers aligned to product lines, and a Security Champions community across engineering and business applications - owning execution of Secure SDLC, AppSec, and product-side cloud security across the product portfolio.

This is a player-manager role: set strategy and run the team but also engage personally with the most complex security initiatives, customer audits, regulatory exchanges, and incident escalations.

## Requirements

•      **Team leadership.** Lead and grow a multi-disciplinary Security Engineering team across the Centre of Excellence and embedded engineer pods. Own hiring, performance, and career development; inspire and actively mentor the team.

•      **Secure SDLC governance** Own and govern the Secure SDLC framework across the product portfolio, including security policies, standards, controls, and integration of security requirements throughout the software development lifecycle.

•      **Drive adoption of secure engineering practices,** including SAST, SCA, AI-assisted code reviews, LLM-driven vulnerability scanning, and threat modelling, while advancing security maturity aligned with OWASP SAMM / BSIMM practices.

•      **Threat modelling & risk assessment.** Sponsor early-stage architectural evaluations and threat-modelling reviews for new features, products, and material design changes - identifying and mitigating risks before code ships.

•      **VulnOps.** Oversee the unified vulnerability-operations function - a single risk-scored backlog consolidating findings from SAST, DAST, SCA, container/IaC, secret scanning, CSPM, and pen testing. Drive remediation through ASPM/RBVM-powered prioritisation (exploitability, reachability, business impact), deduplication, automated fixes, and SLA-driven cadence with engineering - reducing noise to engineering and bringing down mean-time-to-remediate.

•      **Supply chain security.** Establish and drive the software supply chain security strategy, including dependency management, SBOM governance, and third-party component risk management. Provide security oversight and remediation guidance while Product teams are responsible for implementing approved actions.

•      **Customer Security Assurance (Technical SME).** Act as the technical security-controls SME for financial-institution customer security audits, vendor risk questionnaires, and contractual evidence requests - covering Secure SDLC, AppSec, VulnOps, threat modelling, pen testing, cloud security, supply-chain security, and incident response.

•      **External pen testing & regulatory evidence.** Scope and drive third-party (external) penetration testing engagements requested by financial-institution customers. Maintain the technical evidence base for product alignment with SOC 2, ISO 27001, PCI DSS, DORA, and applicable data-protection laws (e.g., GDPR).

•      **Incident response.** Own product-security incident command - direct remediation, internal triage, and customer communication for product CVEs and security incidents.

•      **Programme reporting.** Run program dashboards for AppSec/cloud posture, finding burndown, SLA breach, MTTR, coverage, and pen-test status. Present to CISO, CTO, engineering leadership, and Board sub-committees.

•      **Security evangelism & mentorship.** Educate engineering, product, and QA teams on secure coding, threat modelling, and secure-by-design. Sponsor and govern the Security Champions network (BSIMM Satellite model).

•      **Vendor & tooling ownership.** Own the AppSec and product-security toolchain across SAST, DAST, SCA, ASPM/RBVM, SBOM, secret scanning, LLM-assisted code scanning, and CSPM.

•      **Engineering partnership.** Partner with engineering leads and business operations; ensure embedded SEs are integrated into sprint planning, release gating, and change management.

### Required qualifications

•      10+ years in application / product and cloud security, including 4+ years leading AppSec or Security Engineering teams.

•      Direct experience running secure SDLC programs for a B2B software vendor selling into regulated financial services.

•      Hands-on familiarity with at least two of the following security frameworks and maturity models: OWASP SAMM, BSIMM, OWASP DSOMM, AWS Security Reference Architecture (AWS SRA), or equivalent cloud security frameworks.

•      Strong knowledge of AWS cloud security and cloud vulnerability management, including S3 bucket misconfigurations, IAM risks, and CVE remediation. Working knowledge of DORA, PCI DSS v4.0.1, ISO 27001, SOC 2 Type 2, and GDPR and how each translates into engineering controls.

•      Proven experience integrating security tooling into CI/CD pipelines at scale, and coaching engineers through threat-modelling methodologies (STRIDE, PASTA, LINDDUN, or equivalent).

•      Practical knowledge of the OWASP Top 10 for LLM Applications and OWASP AI Security & Privacy, with hands-on experience securing GenAI/LLM features against prompt injection, insecure output handling, data poisoning, and excessive agency.

•      Understanding of Model Context Protocol (MCP) security - server/client auth, scoped tool permissions, secret handling, tool poisoning, and indirect prompt injections.

•      Demonstrated ability to lead financial-institution customer audit responses and engage with customer security teams and regulators.

•      Strong grounding in modern AppSec tooling (SAST, DAST, SCA, ASPM, SBOM, secret-scanning) and cloud security posture management.

•      Excellent written and verbal communication; comfortable presenting to CISO, engineering leadership, and external auditors.

### Preferred qualifications

•      CISSP, CISM, CSSLP, GIAC GSLC, or equivalent.

•      Experience operating a Security Champions / BSIMM Satellite model.

•      Experience with LLM-assisted threat modelling and code scanning at scale.

•      Working knowledge of AI/ML security frameworks (NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, Google SAIF)

### Key Skills

 AppSec, Secure SDLC, BSIMM, OWASP SAMM, DORA, ISO 27001, SOC 2, PCI DSS, Threat Modelling, SAST, DAST, SCA, ASPM, RBVM, CSPM, SBOM, Vulnerability Management, CI/CD Security, Supply-Chain Security, AWS Cloud Security, IAM, Security Hub, GuardDuty, Cloud & Container Security, IaC Security, FSI / Financial Services, Incident Response, Team Leadership, Security Champions.

### Desired Skills

CISSP, CISM, CSSLP, GIAC GSLC, LLM-assisted Security, AI Agent Security, Agentic Remediation, BSIMM Satellite Model, Cloud Security Posture Management, GDPR.
