Manager- Application Security

inMobi

  • Bengaluru, CA
  • 5 days ago

    Highlights

    This role combines technical leadership and hands-on execution: you will spend ~60% of your time performing application security testing, vulnerability assessments and penetration testing, code reviews, AI/ML security testing, and automation, and ~40% of your time managing the AppSec domain, leading the team, defining strategy, and coordinating with stakeholders. Experience managing AppSec tooling stack like Checkmarx, Burp Suite Enterprise, OWASP ZAP, MobSF, and open-source frameworks; exposure to AI security testing tooling (e.g., Garak, PyRIT, or equivalent) is a plus.

    Numbers & Facts

    LocationBengaluru, CA

    Description

    About the job

    Who are we and What do we do?

    InMobi Group's mission is to power intelligent, mobile-first experiences for enterprises and consumers. Its businesses across advertising, marketing, data and content platforms are shaping consumer experience in a world of connected devices. InMobi Group has been recognized on both the 2018 and 2019 CNBC Disruptor 50 list and as one of Fast

    What does the team do?

    Opportunity is part of the evolving cyber security group which is laser focussed on setting up industry benchmarks in managing & guarding against digital risks in a "Cloud Native- DevOps Only" environment. It is a lean-mean-special action group where every cyber sentinel gets an opportunity to work across domain, has an independence to challenge status quo & evolve cyber practises to next level of maturity. Our core competencies revolve around "Product & Platform security", "Cloud Native Risk Management" and "Detection & Response".

    What will you be doing?

    This role combines technical leadership and hands-on execution: you will spend ~60% of your time performing application security testing, vulnerability assessments and penetration testing, code reviews, AI/ML security testing, and automation, and ~40% of your time managing the AppSec domain, leading the team, defining strategy, and coordinating with stakeholders.

    • Lead the Application Security program across products, platforms, and engineering teams, defining strategy, roadmap, and measurable KPIs for AppSec and AI security maturity.
    • Manage and mentor a team of AppSec engineers, ensuring effective prioritization, workload management, and continuous skill development.
    • Perform hands-on SAST, DAST, manual code review, penetration testing, and vulnerability validation across web, mobile (Android and iOS), API, and cloud platforms.
    • Perform security assessments of AI/ML and GenAI systems, including LLM applications, model endpoints, RAG pipelines, and agentic workflows.
    • Partner with Engineering, Product, Cloud, DevOps, and Data Science teams to embed security controls early in the SDLC and ML/AI development lifecycle through automation, guardrails, and secure-by-design principles.
    • Drive remediation governance: triage, track, and report on vulnerabilities with accountability across stakeholders; ensure closure within defined SLAs.
    • Conduct security architecture and design reviews for new applications, APIs, integrations, and AI/ML systems to ensure alignment with enterprise security standards.
    • Define and enforce secure coding guidelines, threat modeling practices (including AI/LLM threat models), and application and model hardening standards.
    • Collaborate with the GRC and Incident Response teams to ensure audit readiness, compliance evidence and support during incidents.
    • Research and adopt emerging AppSec and AI security technologies, frameworks, and practices to continuously strengthen defenses and developer experience.
    • Drive metrics and reporting to senior leadership on AppSec performance, risk posture, and progress against roadmap goals.

    What is expected of you?

    • 10 to 14 years of experience.
    • Proven leadership experience in Application Security, DevSecOps, or Software Security Engineering, with the ability to lead a high-performing team while staying technically hands-on.
    • Deep hands-on understanding of SAST, DAST, and secure SDLC integration; prior experience implementing and scaling security testing automation.
    • Working knowledge of AI/ML and LLM security, threat modeling and testing against frameworks such as the OWASP Top 10 for LLM Applications, OWASP ML Security Top 10, and MITRE ATLAS; familiarity with securing GenAI/agentic applications and AI pipelines.
    • Strong stakeholder management skills to influence and collaborate with product, engineering, cloud, and data science teams for timely triage and remediation.
    • Experience managing AppSec tooling stack like Checkmarx, Burp Suite Enterprise, OWASP ZAP, MobSF, and open-source frameworks; exposure to AI security testing tooling (e.g., Garak, PyRIT, or equivalent) is a plus.
    • Solid grasp of secure coding, vulnerability exploitation, and mitigation techniques across web, mobile, API, and AI/ML layers.
    • Familiarity with CI/CD automation, scripting (Python, Bash, PowerShell), and container security (Docker/Kubernetes).
    • Strong understanding of OWASP Top 10, SANS Top 25, OWASP LLM Top 10, and industry best practices.
    • Excellent communication, reporting, and presentation skills for technical and executive audiences.
    • Certifications such as OSCP, GWAPT, GPEN, or equivalent are preferred; AI security certifications (e.g., CAISP) are a plus.
    • Prior experience in building or scaling AppSec or AI security programs and driving measurable security improvements is a strong plus.

    Similar Jobs

    DICK'S Sporting Goods

    Store Manager

    • San Luis Obispo, CA
    11 days ago
    See more jobs