Back to jobs
CZ
Hiring companyCarl Zeiss

Verified today

Product Security Lead

Bangalore, India Full-time On-site

About the role

Product Security Lead at Carl Zeiss India (Bangalore) responsible for designing and validating security controls for services, applications, and emerging technologies. Lead security assessments, penetration testing, and threat modeling across the secure development life‑cycle (SDLC). Deploy, migrate, and maintain product security solutions in alignment with company policies, working closely with project security engineers. Resolve infrastructure vulnerabilities and product security issues. Requires a college degree or equivalent, 8‑10 years of related experience, and at least 5‑6 years in two technical disciplines such as cloud, network, application, or mobile security, secure development, identity management, or system administration. Strong experience in security assessments, networking protocols (TCP/IP, UDP, SSL/TLS, IPSEC, HTTP, HTTPS, BGP), cryptography, web service frameworks, mobile and service architectures, reverse engineering, vulnerability research, and programming languages (Java, C++, Ruby, Python, Perl). Demonstrated ability to conduct threat modeling, design reviews, and communicate technical risk decisions to diverse audiences. Experience with enterprise architecture and cross‑functional team collaboration is essential.

What you’ll do

  • Design security controls and help validate that our services, applications, and emerging technologies are designed and implemented to the highest security standards and applicable best practices
  • Analyze the security of applications and services, discovering and addressing security issues, building security automation, and appropriately identifying the action(s) to mitigate emerging threats throughout a full secure development life-cycle (SDLC).
  • Deploying, Migration to and Maintaining solutions in accordance with company security policies and best practices in product security in closely working with the Security Engineers of the Projects respectively
  • Identifying, analyzing, and resolving infrastructure vulnerabilities and product security issues in closely working with the Security Engineers of the Projects respectively

What you’ll bring

College degree or / equivalent and 8-10 years related work experience, required

Skills

cloud securitynetwork securityapplication securitymobile securitysecure development methodologiessoftware developmentcodingidentity managementauthenticationauthorizationnetwork architecturesystem administrationsystems engineeringpenetration testingTCP/IPUDPSSL/TLSIPSECHTTPHTTPSBGPcryptographyweb service frameworksmobile application architecturesservice architectures (event-driven, service-oriented, serverless)reverse engineeringvulnerability researchphysical/infrastructure/hardware securityJavaC++RubyPythonPerlthreat modelingdesign reviewsenterprise architecturecross-functional team collaboration

Education

Bachelor's