← Browse all jobs

A

Head of Product Security

Accops · India

FULL TIME

Job Description

Role snapshot

Accops is hiring a hands-on Head of Product Security to own the security of every product we ship from source code to customer incident response.

Location: India (remote-friendly; Bengaluru / Pune / Delhi NCR preferred)

Experience: 10+ years total, including 5+ years in hands-on security research / pen testing

Background: Former software engineer turned security researcher

Reports to CEO / CTO

Team

Leads the product security testing team

About Accops and the role

Accops builds secure remote access and Zero Trust products, including the HySecure ZTNA line, used by enterprises, banks and government organisations. Our customers trust us to sit at the edge of their networks, so the security of our own code is the product.

You will be the single owner of product security: you decide what gets tested, find the hard bugs before attackers do, lead the response when something goes wrong, and speak for Accops to customers when they ask how secure we are.

What you'll own

Lead the security testing team

  • Build, mentor and manage the product security / pen testing team; set hiring bar, career paths and quality standards.
  • Own the security testing plan for every release across gateway, client (Windows, macOS, Linux, mobile), web portals and cloud services.
  • Define severity ratings, SLAs for fixes, and release sign-off criteria.

Secure code review and white-box testing

  • Review source code personally (C/C++, .Net, Go, Python, JavaScript and others) for high-risk areas: authentication, crypto, VPN/tunnel handling, session management, privilege boundaries.
  • Run white-box pen tests with full code and design access; write exploits and proof-of-concepts to prove impact.
  • Lead threat modelling and design reviews for new features and architecture changes.
  • Embed SAST, DAST, SCA, fuzzing and secrets scanning into CI/CD, and tune them so engineers trust the results.

Incident response and forensics

  • Lead technical investigation of security incidents involving Accops products, in-house and at customer sites.
  • Perform log, memory, disk and network forensics; establish root cause, blast radius and timeline.
  • Drive fixes, hotfixes and post-incident reviews through to closure.

Vulnerability management and disclosure

  • Run the intake and triage of vulnerabilities from researchers, customers, bug bounty and third-party audits.
  • Own CVE assignment, security advisories and coordinated disclosure.
  • Manage external pen test vendors and certification audits (e.g. CERT-In empanelled audits, ISO 27001, SOC 2 evidence).

Customer communication

  • Be the trusted security voice of Accops to customers: CISOs, bank and government security teams, and auditors.
  • Write and present clear advisories, incident reports and root-cause analyses for both technical and executive audiences.
  • Answer security questionnaires, join customer calls during incidents, and handle tough conversations with calm and transparency.
  • Brief the leadership team regularly on product security posture and risk.

What you bring (must-have skills)

  • 10+ years of experience, starting as a software engineer who shipped production code, followed by 5+ years focused on security research and penetration testing.
  • Deep hands-on skill in source code review and white-box testing; able to read unfamiliar code quickly and find logic, memory-safety and auth flaws.
  • Strong command of network and application security: TLS/PKI, VPN and tunnelling, SSO (SAML, OIDC, OAuth), MFA, OWASP Top 10, API security.
  • Experience with exploit development and PoC writing; comfortable with tools like Burp Suite, IDA/Ghidra, debuggers and fuzzers.
  • Practical incident response and forensics experience: log analysis, memory and disk forensics, attacker timeline reconstruction.
  • Proven record of leading or mentoring a security testing team.
  • Excellent written and spoken English; has handled customer-facing security discussions, advisories or incident calls with senior stakeholders.
  • High integrity and sound judgement with sensitive information.

Nice to have

  • Published CVEs, conference talks (e.g. Nullcon, c0c0n, DEF CON, Black Hat) or bug bounty hall-of-fame credits.
  • Certifications such as OSCP, OSWE, OSED, OSCE3, GXPN or GCFA.
  • Background in ZTNA, VPN, VDI, identity or endpoint security products.
  • Experience with Windows kernel/driver, macOS or Linux client internals.
  • Familiarity with Indian regulatory expectations (RBI, SEBI, CERT-In) and secure SDLC frameworks (OWASP SAMM, NIST SSDF).

What success looks like

First 90 days: a clear map of the attack surface across all products, a prioritised risk backlog, and a team operating on agreed severity SLAs.

First year:

  • Every major release passes a white-box review and sign-off before GA.
  • Critical and high findings fixed within agreed SLAs.
  • A tested incident response playbook, with customer communication templates.
  • A public vulnerability disclosure policy and advisory process in place.
  • Customers and auditors see Accops product security as a strength in deals and renewals.

Why join, and how to apply

  • Own product security end to end at a company whose products protect critical enterprise and government access.
  • Work directly with the founders, with real authority to block a release on security grounds.
  • Build and shape your own team.
  • Remote-friendly within India, with competitive pay.

To apply, send your CV and a short note on a vulnerability or incident you are proud of (CVE, write-up or talk links welcome) to careers@accops.com

Details

CompanyAccops
LocationIndia
TypeFULL TIME
Nichemarketing

Similar Jobs

A

Remote Social Media Supervisor (Volunteer/Remote)

Abuse Refuge Org

P

Remote Director, Channel Sales

Posit Ltd

A

Remote Senior Product Marketing Manager

Appfire

O

Remote Senior Product Manager, Atom Engine

Onebrief

B

Remote Mid-Market Account Executive, Remote

Block