Application Security Compliance Lead
NCR Atleos · Gurgaon, India +1 · 8d ago
About NCR Atleos
NCR Atleos, headquartered in Atlanta, is a leader in expanding financial access. Our dedicated 20,000 employees optimize the branch, improve operational efficiency and maximize self-service availability for financial institutions and retailers across the globe.
Title: Application Security Compliance Lead
Location: Gurgaon or Hyderabad, India
About NCR Atleos
NCR Atleos Corporation (NYSE: NATL) is a global technology company that enables financial access and commerce through assisted and self-service solutions and comprehensive support services. NCR Atleos serves financial and public-sectororganizationsin more than 100 countries and is headquartered in Atlanta, Georgia, USA.
The opportunity
As an Application Security Compliance Lead, you will help ensure that NCR Atleos software products and development practices meet applicable security,privacyand regulatory requirements. Working within our global Application Security team, you will turn complex requirements into practical guidance, prepare teams forassessments,and helpdemonstratethat security and privacy are embedded throughout the software lifecycle.
A major focus isorganization-levelPCI Software Security Framework(SSF)activities: support product teams to achieve andretainPCI Secure Software Standard listings andmaintainvalidation of our Secure Software Lifecycle practices. This role suits someone who combines complianceexpertisewith software development and application security knowledge.
What you will do
Govern the Secure SDLC. Maintain and improve practices aligned with thePCI Secure SLC Standard.
Enable PCI SSF validation. Guide teams through externalassessment, self-assessment, annualattestationand periodic revalidation activities.
Interpret requirements. Translate security, privacy, legal and industry requirements into clear, proportionate guidance.
Assess readiness and close gaps. Coordinate reviews, evidence, gap analysis,remediationand resolution of findings.
Engage and influence. Partner with engineering, Legal, risk,complianceand security teams,QSAsand the PCI SSC.
Build capability. Create training and reusable guidance; monitor developments and communicate material changes.
Drivecontinual improvement.Useindustry changes, stakeholder feedback, internal audits,assessment outcomes, recurringfindings,and incidentsto strengthen controls and processes.
What you will bring
Essential experience and capabilities
Typically,7+ years of relevant experiencein application security, software security assurance, secure software development, technology risk, privacy, compliance,or audit.
Practical experience developing,operating,governingor assessing aSecure SDLC.
Experience interpreting security or compliance requirements and supporting assessments, evidence collection, gapanalysisand remediation.
Working knowledge of threat modelling, vulnerability management, securitytesting,and risk-based decision-making.
Technical understanding of cloud services, source-codemanagement,and CI/CD practicessufficientto engage credibly with engineering teams.
Ability to convert complex requirements into pragmatic guidance and make evidence-based recommendations.
Strong stakeholder management, communication, analytical and problem-solving skills, including the ability to influence without direct authority.
Ability to work independently and effectively within a globally distributed team.
Comfortable using AI assistants, such asCopilot, responsibly in day-to-day work to improve personal productivity, quality,and speed of delivery.
A bachelor’s degree in a STEM discipline, orequivalentrelevant professional experience and qualifications.
Desirable experience and capabilities
Direct experience ofPCI SSFvalidationor a comparable software security assurance framework.
Knowledge ofpayment-card security,GDPRrequirements,NIST CSF and OWASPstandards andguidance.
Experience delivering application security or compliance-relatedtraining.
Knowledge of security and governance for AI-enabled software developmentandproducts.
A relevant certification, such as CISSP, CSSLP, CIPP, CIPT or CIPM.
How you will succeed
Teams receive clear,timely,and actionable compliance guidance.
PCI SSF validation activities are well planned, appropriatelyevidenced,and progressed effectively.
Compliance gaps and findings are clearly owned, prioritized,tracked,and resolved.
Secure SDLC requirementsremainpractical,current,and consistently understood.
Assessment and incident lessons lead to sustainable improvements and strong stakeholder relationships.
Evidence we value
In your application, we would particularly welcome examples of how you have interpreted a security standard, prepared a product ororganizationfor assessment, resolved a significant compliance gap, or influenced an engineering team to adopt a more effective security practice.
Offers of employment are conditional upon passage of screening criteria applicable to the job.
EEO Statement
NCR Atleos is an equal-opportunity employer. It is NCR Atleos policy to hire, train, promote, and pay associates based on their job-related qualifications, ability, and performance, without regard to race, color, creed, religion, national origin, citizenship status, sex, sexual orientation, gender identity/expression, pregnancy, marital status, age, mental or physical disability, genetic information, medical condition, military or veteran status, or any other factor protected by law.
Statement to Third Party Agencies
To ALL recruitment agencies: NCR Atleos only accepts resumes from agencies on the NCR Atleos preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Atleos employees, or any NCR Atleos facility. NCR Atleos is not responsible for any fees or charges associated with unsolicited resumes.