Manager- Application Security
Job description
About the role
InMobi is looking for a Manager of Application Security to lead the application security program across the organization. This role is based in Bengaluru and involves overseeing security assessments, vulnerability management, and secure development practices for all customer-facing and internal applications. The Manager will work closely with engineering teams to embed security into every phase of the software development lifecycle. Reporting to senior leadership, this position shapes the security strategy for InMobi's applications and platforms while mentoring a growing team of security professionals.
Key facts
What you'll do
Lead the application security strategy and roadmap for InMobi's product portfolio across all development teams.
Conduct and coordinate application security assessments including static analysis, dynamic analysis, and penetration testing activities.
Manage a team of security engineers and analysts responsible for identifying and remediating application vulnerabilities.
Collaborate with product and engineering managers to integrate security requirements into sprint planning and release cycles.
Own the vulnerability management lifecycle from discovery through triage, remediation tracking, and verification of fixes.
Develop and maintain secure coding guidelines, threat modeling frameworks, and security architecture review processes.
Drive security awareness and training programs for developers, testers, and product owners across the organization.
Establish key performance indicators and reporting dashboards to measure application security posture and improvement over time.
Serve as the primary point of contact for application security matters with external auditors and compliance teams.
Evaluate and recommend application security tools, platforms, and services to strengthen the overall security ecosystem.
Partner with the incident response team to conduct root cause analysis and implement preventive measures for security breaches.
Review and approve architectural designs and technical specifications to ensure security controls are properly integrated before deployment.
Requirements
Bachelor's or Master's degree in Computer Science, Information Security, or a related technical discipline.
Minimum of eight years of experience in application security, cybersecurity, or a closely related field.
At least three years of people management experience leading a team of security professionals or engineers.
Strong understanding of OWASP Top Ten vulnerabilities, secure software development practices, and common attack vectors.
Hands-on experience with application security testing tools such as SAST, DAST, and interactive application security testing platforms.
Familiarity with cloud security concepts, API security, and mobile application security testing methodologies.
Excellent written and verbal communication skills for presenting findings to both technical and non-technical stakeholders.
Experience working in a fast-paced technology company with multiple concurrent projects and shifting priorities.
Proven track record of managing application security programs in a regulated or compliance-driven technology environment.
Strong problem-solving abilities and the capacity to communicate complex security concepts to diverse audiences effectively.
Nice to have
Certified Information Systems Security Professional or Offensive Security Certified Professional certification.
Experience with DevSecOps pipelines and integrating security tooling into continuous integration and continuous deployment workflows.
Prior exposure to mobile advertising, ad-tech, or fintech industry security domains.
Knowledge of regulatory frameworks such as GDPR, PCI DSS, or ISO 27001 and their application to software products.
Experience with security automation using scripting languages or infrastructure-as-code tools for repetitive security tasks.
Skills & tools
Proficiency in application security frameworks including OWASP, SANS, and NIST cybersecurity standards.
Experience with security testing tools like Burp Suite, Nessus, Qualys, or similar vulnerability scanners.
Familiarity with programming languages such as Java, Python, JavaScript, or Kotlin for code review purposes.
Working knowledge of cloud platforms including AWS, Azure, or Google Cloud and their security controls.
Understanding of containerization technologies like Docker and Kubernetes for securing microservices architectures.
Ability to use issue tracking and security orchestration platforms such as Jira, ServiceNow, or DefectDojo.
Knowledge of identity and access management protocols, OAuth, OpenID Connect, and SAML for securing application authentication flows.
Practical notes
This role is based in InMobi's Bengaluru office and requires on-site presence during standard business hours.
The Manager will report to the Director or Vice President of Information Security within the InMobi leadership structure.
The position involves regular interaction with cross-functional teams including product, engineering, compliance, and risk management departments.
Candidates should be prepared to participate in on-call rotation for handling urgent security incidents and production issues.
The role may involve occasional travel to InMobi offices in other cities or to vendor and partner locations for security reviews.