Lead the Application Security program at InMobi, managing and mentoring a team while performing hands-on security testing including SAST, DAST, penetration testing, and AI/ML security assessments. Define strategy, roadmap, and KPIs for AppSec and AI security maturity. Collaborate with cross-functional teams to embed security controls early in development lifecycles. Drive remediation governance and conduct security architecture reviews. Require 10-14 years experience with proven leadership in AppSec or DevSecOps, deep knowledge of security testing tools and frameworks, AI/ML security expertise, scripting skills, and strong stakeholder management. Certifications like OSCP, GWAPT, GPEN preferred. Location: Bengaluru, India.
What you'll do
Lead the Application Security program across products, platforms, and engineering teams
Define strategy, roadmap, and measurable KPIs for AppSec and AI security maturity
Manage and mentor a team of AppSec engineers
Similar jobs
More roles worth a look
Related opportunities based on specialty and working model so candidates can keep momentum.
Perform hands-on SAST, DAST, manual code review, penetration testing, and vulnerability validation across web, mobile (Android and iOS), API, and cloud platforms
Perform security assessments of AI/ML and GenAI systems, including LLM applications, model endpoints, RAG pipelines, and agentic workflows
Partner with Engineering, Product, Cloud, DevOps, and Data Science teams to embed security controls early in the SDLC and ML/AI development lifecycle
Drive remediation governance: triage, track, and report on vulnerabilities with accountability across stakeholders
Conduct security architecture and design reviews for new applications, APIs, integrations, and AI/ML systems
Define and enforce secure coding guidelines, threat modeling practices (including AI/LLM threat models), and application and model hardening standards
Collaborate with GRC and Incident Response teams to ensure audit readiness, compliance evidence and support during incidents
Research and adopt emerging AppSec and AI security technologies, frameworks, and practices
Drive metrics and reporting to senior leadership on AppSec performance, risk posture, and progress against roadmap goals
Requirements
10 to 14 years of experience
Proven leadership experience in Application Security, DevSecOps, or Software Security Engineering
Deep hands-on understanding of SAST, DAST, and secure SDLC integration
Experience implementing and scaling security testing automation
Working knowledge of AI/ML and LLM security, threat modeling and testing against frameworks such as OWASP Top 10 for LLM Applications, OWASP ML Security Top 10, and MITRE ATLAS
Familiarity with securing GenAI/agentic applications and AI pipelines
Strong stakeholder management skills
Experience managing AppSec tooling stack like Checkmarx, Burp Suite Enterprise, OWASP ZAP, MobSF, and open-source frameworks
Exposure to AI security testing tooling (e.g., Garak, PyRIT) is a plus
Solid grasp of secure coding, vulnerability exploitation, and mitigation techniques across web, mobile, API, and AI/ML layers
Familiarity with CI/CD automation, scripting (Python, Bash, PowerShell), and container security (Docker/Kubernetes)
Strong understanding of OWASP Top 10, SANS Top 25, OWASP LLM Top 10, and industry best practices
Excellent communication, reporting, and presentation skills
Certifications such as OSCP, GWAPT, GPEN, or equivalent preferred; AI security certifications (e.g., CAISP) are a plus
Prior experience in building or scaling AppSec or AI security programs and driving measurable security improvements is a strong plus
Tech stack
SASTDASTCheckmarxBurp Suite EnterpriseOWASP ZAPMobSFPythonBashPowerShellDockerKubernetesAI/ML security testing tools (e.g., Garak, PyRIT)
Benefits
Continuous learning and career progression through InMobi Live Your Potential programEqual Employment Opportunity employerReasonable accommodations for qualified individuals with disabilities
Apply now
Ready to take the next step in your career? Click the button below to continue to the application process.