{"id":1525870,"url":"https://alion.io/job/sunovaa-tech-lead-product-security-engineer-cloudkubernetes-security","title":"Lead Product Security Engineer - Cloud/Kubernetes Security","company":{"id":3800722,"name":"Sunovaa Tech","domain":"sunovaa.com","url":"https://alion.io/company/sunovaa-tech","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":25000,"max_usd":59000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":9},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Checkmarx","optional":false},{"name":"CI/CD","optional":false},{"name":"Docker","optional":false},{"name":"Fortify","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Prisma Cloud","optional":false},{"name":"Snyk","optional":false},{"name":"SonarQube","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Trivy","optional":false},{"name":"Veracode","optional":false}],"status":"live","first_seen_at":"2026-09-30T12:17:10Z","employer_posted_date":null,"last_verified_at":"2026-09-30T12:17:10Z","board_verified":false,"closed_at":null,"days_open":1,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":1},"description":"Role & Responsibilities:\n\n- Lead Application Security and Product Security initiatives across the complete Secure SDLC.\n\n- Own security strategy and technical direction for products, applications and cloud-native platforms.\n\n- Lead Threat Modeling and Risk Assessment for application, API, cloud and product architectures.\n\n- Define and implement security controls across design, development, CI/CD, deployment and production.\n\n- Lead SAST, DAST, SCA and vulnerability management programs and drive remediation with engineering teams.\n\n- Review application and solution architectures from a security perspective and provide actionable recommendations.\n\n- Lead security assessments for AWS/Azure cloud environments, including IAM/RBAC, network security, encryption, secrets management and monitoring.\n\n- Drive Container and Kubernetes Security, including image security, RBAC, secrets, network policies and runtime controls.\n\n- Establish and improve DevSecOps practices, integrating automated security checks into CI/CD pipelines.\n\n- Define security standards, guidelines and best practices aligned with OWASP and industry security frameworks.\n\n- Work closely with Software Engineering, DevOps, Cloud, Architecture and Product teams to resolve security risks.\n\n- Prioritize vulnerabilities based on technical and business risk and drive timely remediation.\n\n- Mentor and provide technical guidance to security engineers and development teams.\n\n- Lead security reviews, audits, risk reporting and security improvement initiatives.\n\n- Stay current with emerging application, cloud, container and product security threats and technologies.\n\nPreferred Candidate Profile:\n\n- 7 - 12 years of experience in Application Security, Product Security, Cloud Security, DevSecOps or Cybersecurity, with demonstrated technical leadership.\n\n- Strong hands-on expertise in Application/Product Security and Secure SDLC.\n\n- Proven experience leading Threat Modeling and Risk Assessment activities.\n\n- Strong knowledge of AWS and/or Azure Cloud Security.\n\n- Strong hands-on experience with Docker, Kubernetes and Container Security.\n\n- Excellent understanding of SAST, DAST, SCA, OWASP Top 10 and vulnerability management.\n\n- Experience designing and implementing DevSecOps and CI/CD security controls.\n\n- Strong understanding of IAM/RBAC, API Security, secrets management, encryption and cloud security architecture.\n\n- Experience with security tools such as Snyk, Checkmarx, Fortify, Veracode, SonarQube, Trivy, Burp Suite, Prisma Cloud, Aqua or equivalent.\n\n- Ability to review security architecture and translate security risks into practical technical solutions.\n\n- Demonstrated experience leading technical discussions, mentoring engineers and influencing development/architecture teams.\n\n- Strong communication, stakeholder-management and problem-solving skills.\n\n- Must have hands-on implementation experience in addition to security leadership experience.\n\nSkills\nCloud Security, Kubernetes, DevSecOps, AWS, Azure, Applications Security, Security, Threat Modeling, SAST, DAST, Vulnerability Management","description_format":"text","description_chars":3089,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Security","AI Consulting & Integration","Analytics & BI Consulting"],"lifecycle":[{"event":"open","at":"2026-09-30T14:00:00Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":24,"reasons":["seen:0","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/sunovaa-tech-lead-product-security-engineer-cloudkubernetes-security","json_url":"https://alion.io/job/sunovaa-tech-lead-product-security-engineer-cloudkubernetes-security.json","meta":{"generated_at":"2026-10-02T00:53:05Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":934,"day_limit":5000,"remaining_today":4066,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}