Security Lead
The Security Lead owns application and platform security across all delivery pods — secure-SDLC standards, vulnerability management, and security governance — providing the technical security direction that engineering and DevOps teams implement day to day.
Experience · 10+ years in information security with 4+ years in a security leadership role.
Cyber Security
Thiruvananthapuram, Kerala
Employment
Work from office
Immediate
About the role
What you’ll be working on and why this role matters.
The Security Lead is responsible for defining and governing application, platform, and software security across all Scrum pods, ensuring that security is embedded throughout the software development lifecycle.
The role establishes Secure SDLC standards, secure coding practices, security controls, and vulnerability management processes, covering application architecture, authentication, authorisation, data protection, dependencies, APIs, infrastructure, and deployment.
Working closely with the Enterprise Architect, Engineering Leader, DevOps Lead, QA Lead, and development teams, the Security Lead identifies security risks and vulnerabilities, coordinates security testing and remediation, and ensures that appropriate security controls are implemented before release. The role also provides security governance and technical direction to all delivery pods, ensuring consistent security practices, compliance with defined policies, and timely resolution of identified risks.
Ultimately, the Security Lead acts as the programme-wide technical security authority, guiding engineering and DevOps teams in implementing secure, resilient, and compliant software and platform environments.
Responsibilities
Day-to-day ownership and impact areas.
Own the platform's security control framework, aligned to ISO 27001 and applicable government security standards.
Other open roles
Explore more opportunities at Triwinz
Define secure-SDLC standards — SAST/DAST gates, dependency scanning, threat modelling — for all delivery pods.
Direct vulnerability management — scanning cadence, triage, and remediation tracking across pods.
Own IAM and data-protection design inputs — authentication, authorization, encryption, key management.
Lead security reviews, penetration-test scoping, and remediation verification.
Provide technical security direction to the DevOps Lead on pipeline security-gate implementation.
Support audit, accreditation, and client security assurance activities.
Maintain the security risk register and escalate material risks to the Engineering Manager.
Requirements
Skills and experience that will help you succeed.
Experience: 10+ years in information security with 4+ years in a security leadership role.
Architecture: Working command of IAM, cryptography/key management, and application/infrastructure security.
Standards: Practical implementation of ISO 27001 controls; familiarity with government security accreditation.
SDLC: Secure development lifecycle design — SAST/DAST, threat modelling, CI/CD security gates.
Risk: Formal security risk assessment and treatment planning.
Leadership: Prior technical leadership of security workstreams across multiple teams.
Qualifications and certifications
Education and credentials that support this role.
Bachelor's degree in Computer Science, IT, or related field.
CISSP required or equivalent seniority demonstrable; ISO 27001 LA/LI preferred.
Nice to have
Bonus strengths — not required, but valued.
CISSP, CISM, or equivalent certification.
National-security-adjacent or border/identity platform experience.
HSM and PKI design experience.
Interested in this role?
Submit your application and our team will get back to you soon.
Code Review Expert
Thiruvananthapuram, Kerala · WFH · Contract