Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Application Security Compliance Specialist @ NCR Corporation

Home > Software Development

 Application Security Compliance Specialist

  •   Hyderabad,Telangana, Gurugram,Haryana

Job Description

Title: Application Security Compliance Specialist

Location: Gurgaon or Hyderabad, India

About NCR Atleos Corporation

NCR Atleos (NYSE: NATL) is a leader in facilitating banks and retailers to deliver best-in-class self-service banking experiences for consumers. NCR Atleos helps customers expand their reach, provide greater financial access for customers and reduce operational complexity through industry-leading technologies, unmatched global services capabilities, the largest surcharge-free network and expertise in running ATM networks. NCR Atleos is headquartered in Atlanta, Georgia, with 20,000 employees globally.

Application Security Compliance Specialist

In this critical role as a Compliance Specialist, you will serve as NCRs Application Security (AppSec) compliance expert in support of enterprise-wide applications and services. You will be part of a dynamic global application security team, working with security architects, privacy professionals and software development groups to establish, enable and improve the security of our software solutions, with a particular focus on compliance with applicable legislation and standards.

As the AppSec Compliance Specialist, you will be primarily responsible for organization-level activities to guide and support our software development teams in achieving and retaining PCI Software Security Framework (SSF) certification for all in-scope products. This will include maintaining and improving our Secure Software Lifecycle (SLC), and coordination with internal groups and PCI Qualified Security Assessors (QSA) as needed to ensure success for both external validation and self-attestation (as an SLC-approved vendor) of our go-to-market products.

Key Responsibilities

  • Maintain and improve the NCR Secure SDLC (NCRs instantiation of a Secure SLC)
  • Ensure compliance with all relevant laws, regulations and industry standards
  • Guide, support and collaborate with cross-functional stakeholders to achieve and retain PCI SSF certification for in-scope products
  • Network with other key contacts within NCR to align activities for applicable PCI standards
  • Stay current with industry developments in this domain and advise leadership as required
  • Provide (or source) training and guidance to employees on compliance matters
  • Communicate and facilitate across all levels within NCR and liaise with external assessors as required
  • Be the subject matter expert for complaints and investigations related to compliance; work with NCR Law and cross-functional groups as required
  • Be a thought leader within the App Sec team for compliance, secure development practices, data protection and privacy by design, and support the team as needed.

Skills and Qualifications

  • Bachelors Degree in a relevant subject or equivalent work experience and professional qualifications
  • Experienced in developing, maintaining, governing a Secure Software Lifecycle
  • Technical understanding and experience of secure development practices and tooling, Secure SDLC, Threat Modeling, Security Architecture Review, SAST/DAST OWASP, PCI DSS.
  • Experience managing compliance activities; experience with validation activities for PCI SSF highly desirable (and/or prior experience with PA-DSS or PCI DSS)
  • Development and delivery of training materials in this domain
  • One or more directly applicable qualifications with related experience advantageous (e.g. CISSP, CSSLP)
  • Knowledge and experience with the payment card industry advantageous
  • Knowledge and experience with privacy and data protection requirements of a global software provider (e.g. aligned with GDPR, CCPA); Privacy certification preferable (i.e. CIPP, CIPT or CIPM)
  • Knowledge and experience with OWASP SAMM and the NIST Cybersecurity Framework
  • Other related qualifications and experience advantageous, for instance: in compliance, security, secure development, data protection, privacy
  • Excellent interpersonal skills and ability to communicate effectively at all levels, and with external assessors (confident and prepared to challenge results when needed)
  • Excellent analytical and problem-solving skills
  • Strong attention to detail and capable of working autonomously but, also skilled in collaborative working.


Job Classification

Industry: Software Product
Functional Area: Software Product
Role Category: Software Development
Role: Software Development - Other
Employement Type: Full time

Contact Details:

Company: NCR Corporation
Location(s): Multi-City, India

+ View Contactajax loader


 Fraud Alert to job seekers!

₹ Not Disclosed

Similar positions

Application Developer

  • Accenture
  • 3 - 5 years
  • Hyderabad
  • 1 month ago
₹ Not Disclosed

Application Developer - Bengaluru/Bangalore

  • Accenture
  • 10 - 12 years
  • Bengaluru
  • 1 month ago
₹ Not Disclosed

Application Lead - Chennai - Accenture - 3 to

  • Accenture
  • 3 - 7 years
  • Chennai
  • 1 month ago
₹ Not Disclosed

PTC Windchill-Application Developer - Pune

  • Accenture
  • 2 - 5 years
  • Pune
  • 1 month ago
₹ Not Disclosed

NCR Corporation

At NCR, we make the everyday easier. We do this by listening to our customers, keeping their best interests in mind, and always working to make interacting with your business an exceptional experience. Read on to learn more about the people who lead our team, our company by the numbers, and h...