
Job Description
Ovii's Interpretation of the Role
The Manager, Application Security leads InMobi's AppSec program, combining hands‑on security testing with team leadership. You will define strategy, drive automation, and secure AI/ML pipelines across web, mobile, API and cloud products.
Role Snapshot
- Define and own AppSec strategy & roadmap
- Hands‑on security testing (SAST/DAST, pen‑testing)
- Manage and mentor AppSec engineers
- Secure AI/ML and GenAI systems
- Partner with engineering, product and data teams
- Drive remediation governance and reporting
Must-Have Requirements
- SAST
- DAST
- Penetration testing
- Manual code review
- Vulnerability assessment
- Secure SDLC integration
- AI/ML security testing
- Threat modeling
- Secure coding guidelines
- Security architecture reviews
- Remediation governance
- Stakeholder management
- Leadership & team management
- Metrics & reporting
- Checkmarx
- Burp Suite Enterprise
- OWASP ZAP
- MobSF
- Application Security
- DevSecOps
- Software Security Engineering
- AI/ML security
Nice-to-Have Signals
- OSCP
- GWAPT
- GPEN
- CAISP (AI security certification)
- Garak or PyRIT (AI security testing tools)
- Python scripting
- Bash scripting
- PowerShell scripting
- Docker
- Kubernetes
- Building or scaling AppSec programs
- AI security certifications
- CAISP
Work Setup
- Location: Bengaluru
- Employment type: Full-Time
Not Specified in JD
- Salary range
- Visa sponsorship
- Remote eligibility
- Education requirement
- Relocation
- Travel
- Security clearance
- Coding test
- Portfolio
- GitHub
- Writing sample
- Cover letter
What You'll Likely Work On
- Lead the organization‑wide Application Security program, set strategy, roadmap and measurable KPIs
- Manage, mentor and prioritize work for a team of AppSec engineers
- Conduct hands‑on SAST, DAST, manual code reviews, penetration testing and vulnerability validation across web, mobile, API and cloud platforms
- Assess security of AI/ML and GenAI systems, including LLM applications, model endpoints and agentic workflows
- Embed security controls early in the SDLC and ML/AI lifecycle through automation, guardrails and secure‑by‑design practices
- Own remediation governance: triage, track, report vulnerabilities and enforce SLA‑based closure
- Perform security architecture and design reviews for new applications, APIs and AI/ML integrations
- Define and enforce secure coding standards, threat‑modeling processes and model‑hardening guidelines
- Collaborate with GRC, Incident Response and compliance teams for audit readiness and incident support
- Research emerging AppSec and AI security technologies and drive continuous improvement
Good Fit If You Have
- Experience building or scaling AppSec programs is a strong plus
- Security certifications such as OSCP, GWAPT, GPEN are advantageous
- Familiarity with CI/CD automation and container security tools is beneficial
Skills
- Application Security (SAST/DAST, pen‑testing)
- Secure SDLC integration
- Threat modeling & secure coding guidelines
- AI/ML security testing
- AppSec tooling (Checkmarx, Burp Suite Enterprise, OWASP ZAP, MobSF)
- Leadership & team management
- Metrics, reporting & KPI tracking
- Python/Bash/PowerShell scripting (optional)
- Docker & Kubernetes container security (optional)