IS Service Owner for Application Security

Posted:
3/1/2026, 6:38:15 PM

Location(s):
Karnataka, India ⋅ Bengaluru, Karnataka, India

Experience Level(s):
Senior

Field(s):
IT & Security

At ABB, we help industries run leaner and cleaner—and every person here makes that happen. You’ll be empowered to lead, supported to grow, and proud of the impact we create together. Join us and help run what runs the world.

This Position reports to:

Business Title IS Service Owner for Application Security


 

Your role and responsibilities

In this role, you will lead the Application Security Service end‑to‑end, driving the design, development, and continuous improvement of service lifecycle roadmaps. You will be accountable for ensuring the effective and efficient delivery of all application security services in scope, working closely with dedicated internal teams and global external suppliers. Each day, you will be responsible for defining, implementing, and maintaining the governance and operational framework required to deliver the service on time, within budget, and in alignment with business and security expectations. You will also leverage your expertise to manage multiple third‑party global vendor contracts, ensuring high‑quality service delivery, operational excellence, and ongoing cost optimization.

The work model for the role is: #Hybrid

This role is contributing to the IS Application Security Service in India.

You will be mainly accountable for:
  • Designing and implementing IS Domain service operations in collaboration with IS Service Owners, Application managers, Application owners, Stakeholders, and Solution Architects, ensuring alignment with business needs and technical standards.
  • Creating and managing Service Level Agreements (SLA) and Operational Level Agreements (OLA) to increase transparency between the service provider and Service Owner, and providing feedback about the service’s performance, availability, etc.
  • Creating effort, time, and cost estimates for demand requests (projects, solutions, deployments, and handover to operational vendor), and ensuring that service reaches its targets with an increase in performance year after year.
  • Serving as the escalation point in case of a severe problem in the service and working with the service line to get the service back on track.
  • Deciding on the execution of changes in services and applications as part of accountability toward the Change Advisory Board.
  • Owns the end‑to‑end Application Security Service, including strategy, governance, operational health, roadmap, and continuous improvement of the service.
  • Acts as the primary accountable owner for application security testing, Web application scanning, Vulnerability Discloser Program and secure development enablement across the enterprise.
  • Leads definition and enforcement of application security policies, standards, SLAs, KPIs, and service performance metrics.
  • Ensures the Application Security Service aligns with enterprise cybersecurity frameworks, regulatory requirements, and audit expectations.
  • Manages the full lifecycle of application security services such as SAST, DAST, SCA, Penetration Testing, API Security Testing, VDP, Threat Modeling, and Cloud Application Security.
  • Owns the service catalogue description, RACI, operating model, service onboarding process, escalation structure, and reporting framework.
  • Governs multiple vendors, MSSPs, and security partners to ensure performance, quality, and contract adherence.
  • Monitors vendor deliverables, SLA adherence, capacity, staffing, and quality KPIs; drives corrective actions and escalations when required.
  • Defines multi‑year service roadmap, budget planning, technology upgrades, tool rationalization, and investment cases.
  • Collaborates with Product Owners, Architects, DevOps owners, and Platform teams to integrate security by design into all phases of SDLC.
  • Ensures security tooling is effectively integrated into CI/CD pipelines and works closely with DevOps to maintain automation and coverage.
  • Drives strategic programs such as shift‑left, secure coding adoption, application hardening, API security, and continuous scanning maturity.
  • Oversees enterprise-wide application vulnerability posture; publishes executive dashboards, KPI reports, SLA metrics, and risk summaries.
  • Ensures findings are triaged, prioritized, assigned, and resolved within defined SLAs; drives cross‑functional alignment on remediation goals.
  • Owns decision-making for risk acceptance, compensating controls, and remediation exceptions, ensuring alignment with governance bodies.
  • Facilitates threat modeling initiatives for critical applications and helps product teams incorporate security requirements early in design.
  • Partners with Cloud Security, IAM, Infra Security, and Product Security teams to ensure unified coverage of application risks.
  • Functions as the escalation point for critical security findings, zero‑day events, application-related incidents, and regulatory escalations.
  • Drives maturity assessments, gap analysis, and implementation of security controls based on OWASP, NIST, SANS, CIS, and ISO 27001 standards.
  • Provides leadership, mentorship, and guidance to operational teams, internal stakeholders, and developers on secure coding and remediation.
  • Ensures readiness for internal audits, external audits, customer due‑diligence requests, and compliance assessments.
  • Champions adoption of secure SDLC and DevSecOps practices across all engineering teams; leads enterprise-wide training and awareness.
  • Manages annual financial planning for the service, including licensing, renewal strategies, vendor contracts, and operational budgets.
  • Defines and drives KPIs such as MTTR, SLA adherence, vulnerability aging reduction, coverage metrics, automation levels, and false positive reduction.
  • Collaborates with enterprise architecture to evaluate and approve new application technologies and ensure they meet security baselines.
  • Continuously evaluates the threat landscape to update service controls, policies, and preventive security capabilities.
  • Ensures all service assets, runbooks, SOPs, and workflows are documented, versioned, and kept up to date.
  • Leads periodic service reviews with business units, application owners, and leadership teams to ensure alignment and transparency.
  • Maintains strong stakeholder relationships across business units and drives accountability for remediation and secure development practices.

 
Qualifications for the role (Mandatory)
  • 12+ years of total IT experience with at least 8–10 years dedicated to Application Security, Product Security, or DevSecOps leadership.
  • Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or an equivalent engineering discipline.
  • Proven experience owning or managing end‑to‑end application security services at scale (SAST, SCA, DAST, Pen Testing, API Security, Threat Modeling, Secure SDLC).
  • Strong expertise in vulnerability management governance, SLA enforcement, risk-based prioritization, and enterprise remediation workflows.
  • Hands-on understanding of secure SDLC methodologies, DevSecOps practices, and integration of security tooling into CI/CD pipelines.
  • Deep knowledge of application architectures including APIs, microservices, cloud-native workloads, containerized applications, and modern development patterns.
  • Strong understanding of vulnerability scanning tools, application security testing platforms, and enterprise ticketing/reporting systems.
  • Experience managing bug bounty programs or vulnerability disclosure programs (VDP).
  • Familiarity with cloud platforms (Azure, AWS, GCP) and their native application security features, policies, and shared responsibility models.
  • Excellent communication, negotiation, and stakeholder management skills with the ability to influence non‑security teams.
  • Certifications such as OSCP, OSWE, GWAPT, GWEB, CEH, or ITIL v4 Foundation.

More about us

Our mission in ABB IS (Information Systems) is to harness the power of information technology to deliver valuable, reliable, and competitive IS services for ABB. If you have a strong technical skills, analytical mind, and the drive to help us stay ahead of the competition, you are the one we are looking for.


Building a cleaner, smarter future takes all kinds of minds: the curious, the courageous, and the creative. We welcome people from all backgrounds and experiences.

Ready to make an impact? Apply today or visit www.abb.com to learn more about the impact of our solutions across the globe.

Recruitment Fraud Warning

ABB never asks for payment from job applicants. All genuine job offers follow a formal application and interview process.

View current job openings and apply at: https://careers.abb/global/en/home

For more information, read our full fraud warning notice at: https://global.abb/group/en/careers/how-to-apply/fraud-warning