Talent Apply
Log in
All jobs
AV

Application Security Specialist

AB Volvo
Bangalore, IN, 562122
On-site

About this role

Volvo Group Application Security Specialist

Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.

The Application Security Specialist helps improve application security maturity across Volvo Group by translating governance requirements into practical, usable guidance for Stable Teams.

The role supports the operationalization of application security baselines, tiered requirements, and security maturity medals. It focuses on enabling teams through clear guidance, education, adoption support, and continuous improvement, rather than enforcement alone.

Mission

Advance application security maturity across Digital Product teams by making security requirements clear, practical, and adoptable.

Support Stable Teams in understanding their application security obligations, improving their maturity level, and applying secure-by-design practices in the way they design, build, and operate Digital Products.

Key Accountabilities

Application Security Governance Enablement

  • Operationalize application security baselines, tiered requirements, and maturity models across Stable Teams.
  • Contribute to the development and continuous improvement of application security governance frameworks.
  • Translate governance expectations into practical guidance, patterns, playbooks, and team-facing materials.
  • Identify gaps in adoption and propose improvements to increase consistency, scalability, and usability.

Stable Team Enablement

  • Provide clear and actionable guidance to Stable Teams on application security principles and secure design practices.
  • Deliver workshops, training, and awareness activities to support adoption of application security requirements.
  • Act as a trusted advisor to teams, helping them interpret requirements and apply them appropriately in context.
  • Promote secure-by-design thinking through education, consultation, and continuous engagement.

Security Maturity Medals

  • Support the implementation and evolution of application security maturity levels and security maturity medals.
  • Help Stable Teams understand their current maturity level and the steps needed to progress.
  • Contribute to maturity assessments, improvement roadmaps, and structured enablement approaches.
  • Support consistent adoption of maturity expectations across teams and Digital Product areas.

Metrics & Continuous Improvement

  • Contribute to defining and tracking application security KPIs, adoption metrics, and maturity progression.
  • Analyze trends in governance adoption, maturity improvement, and security control implementation.
  • Provide insights to improve the effectiveness of application security governance capabilities.
  • Support reporting on application security posture, adoption, and maturity evolution.

DevSecOps & Golden Path Alignment

  • Partner with Application Security Engineering and DevSecOps teams to align governance requirements with CI/CD, automation, and Golden Path capabilities.
  • Promote security-by-default, automation, and scalable security practices.
  • Help translate technical security capabilities into practical adoption guidance for Stable Teams.

Expected Outcomes

  • Stable Teams clearly understand application security requirements and how to apply them.
  • Application security baselines and tiered requirements are consistently adopted.
  • Security maturity medals are understood and used to drive measurable improvement.
  • Application security governance capabilities are practical, scalable, and continuously improved.
  • Metrics provide useful insight into adoption, maturity progression, and risk reduction.
  • Security governance is translated into practical outcomes that support secure-by-design delivery.

Scope of Responsibility

The role contributes to the development, operationalization, and continuous improvement of application security governance capabilities. It works closely with Stable Teams, Digital Product Owners, Application Security Engineering, DevSecOps, and security governance stakeholders.

The role is responsible for enabling and supporting activities related to:

  • Application Security Governance
  • Tiered Security Requirements
  • Secure Application Design Guidance
  • Security Maturity Models and Medals
  • Application Security Metrics and Reporting
  • Security Enablement and Training
  • Application Risk Reduction

Required Skills

  • 6+ years of experience in application security fundamentals, secure SDLC, and OWASP Top 10.
  • Ability to translate security requirements into practical guidance for product teams.
  • Experience with application security governance, baselines, controls, or maturity models.
  • Good understanding of DevSecOps concepts, CI/CD, security automation, and developer workflows.
  • Ability to advise engineering teams on secure-by-design practices.
  • Strong communication skills, including workshops, training, playbooks, and written guidance.
  • Ability to work with metrics, adoption tracking, maturity reporting, and continuous improvement.
  • Risk-based mindset with the ability to prioritize based on business and product context.
  • Strong stakeholder collaboration across product, engineering, DevSecOps, and security teams.
  • Familiarity with frameworks such as OWASP SAMM, DSOMM, ISO 27001, or NIST is preferred.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →