Senior Application Security Engineer

Volvo GroupBengaluru, KarnatakaOn-siteFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.

Role Purpose

The Application Security Engineer is responsible for building, evolving, and scaling the organization’s third-party and software supply chain security capabilities across Volvo Group.

This role contributes directly to the development of governance models, operating frameworks, risk methodologies, and enablement structures that allow Stable Teams to securely consume third-party software, SaaS services, APIs, open-source components, and external technology providers.

The focus of the role is capability building: designing how supply chain and third-party security is governed, understood, and adopted across the organization, and enabling its execution through guidance, education, and scalable frameworks.

Mission

Develop and mature enterprise-wide capabilities for third-party and supply chain security by translating governance and risk objectives into scalable frameworks, practical guidance, and structured enablement models.

Enable Stable Teams to make informed, risk-based decisions when consuming external software and services, while continuously improving the organization’s ability to govern, assess, and manage third-party and supply chain risks.

Key Accountabilities

Capability Building – Third-Party & Supply Chain Security Governance

- Contribute to the design, development, and evolution of third-party and supply chain security governance capabilities.

- Help define scalable operating models, frameworks, and standards for managing external software and supplier risk.

- Develop and refine tiered risk models and governance structures for third-party and supply chain security.

- Ensure governance capabilities are practical, adoptable, and aligned with how Stable Teams consume external technology.

Capability Enablement for Stable Teams

- Build enablement structures that allow Stable Teams to understand and apply third-party and supply chain security requirements.

- Develop playbooks, and decision frameworks for managing external software and vendor risk.

- Design and deliver workshops and enablement programs that build organizational capability in supply chain security.

- Enable teams to make consistent, risk-informed decisions when adopting third-party software and services.

Security Maturity & Capability Progression

- Design and evolve maturity models specifically for third-party and supply chain security capabilities.

- Define what “good” looks like across different maturity levels in managing external dependencies and supplier risk.

- Develop structured maturity assessment approaches and capability roadmaps.

- Identify gaps in organizational capability and define initiatives to close them at scale.

- Support progression from ad-hoc third-party risk handling to structured, repeatable governance capabilities.

Metrics, Insights & Capability Measurement

- Define metrics that measure maturity and effectiveness of third-party and supply chain security capabilities.

- Develop indicators for capability adoption, governance effectiveness, and risk reduction across external dependencies.

- Analyze trends to identify where capability gaps exist and where governance improvements are needed.

- Provide insights that guide the evolution of supply chain security capabilities over time.

Ecosystem Capability Integration

- Collaborate with application security team to embed supply chain security capabilities into tooling, automation, and workflows.

- Contribute to defining scalable patterns for secure consumption of third-party components within delivery pipelines.

- Support the evolution of “Golden Path” for safe and standardized use of external software and services.

Advisory & Influence

- Provide expert input into third-party and supply chain security decisions across DV/BA/GF.

- Influence adoption of governance models and security practices through guidance and early engagement.

- Translate complex supply chain risk concepts into understandable and actionable guidance for Stable Teams.

- Stay current on emerging supply chain threats and ensure they are reflected in capability evolution.

Expected Outcomes

Capability Development Ownership

- Owns and contributes to the development of enterprise capabilities for third-party and supply chain security.

- Supports the evolution of governance models, operating structures, and maturity frameworks.

- Ensure capabilities are scalable, reusable, and aligned with organizational technology consumption patterns.

- Identifies opportunities to improve or introduce new capabilities in response to emerging risks and business needs.

Stakeholder Engagement

- Works closely with Stable Teams, Digital Product Owners (DPOs), Procurement, Vendor Management, Architecture, and Security Governance stakeholders.

- Acts as a bridge between governance design and real-world adoption of third-party security capabilities.

- Build strong relationships to ensure capability adoption and long-term sustainability.

Security Domains

Responsible for capability development and enablement across:

- Third-Party Risk Management Capability

- Software Supply Chain Security Capability

- Vendor & SaaS Security Governance

- External API & Integration Security

- Open Source & Dependency Risk Management

- Security Maturity Frameworks (Third-Party Focus)

- Security Governance Operating Models

- Security Enablement & Education Systems

- Risk Metrics & Capability Measurement

Ready for the next move?

Are you excited to bring your skills and disruptive ideas to the table? We can’t wait to hear from you. Apply today!

At Volvo Group, we believe in the value of in-person collaboration and connection. Our general principle is that employees work from the office.

Volvo Group never requests any form of payment or fees from candidates at any stage of the recruitment process. Any such demand is a scam. To view the authentic job description and apply securely, please visit: Jobs at Volvo Group

We value your data privacy and therefore do not accept applications via mail.

Who we are and what we believe in

We are committed to shaping the future landscape of efficient, safe, and sustainable transport solutions. Fulfilling our mission creates countless career opportunities for talents across the group’s leading brands and entities.

Applying to this job offers you the opportunity to join Volvo Group . Every day, you will be working with some of the sharpest and most creative brains in our field to be able to leave our society in better shape for the next generation. ​We are passionate about what we do, and we thrive on teamwork. ​We are almost 100,000 people united around the world by a culture of care, inclusiveness, and empowerment.

Volvo Group Digital Technology & Operations (DTO) is a new division. The organizational set up is structured around domains, digital products with functions for digital excellence to deliver outstanding customer experience.

Joining the new DTO division means being part of a fast-moving digital product-oriented organization where teams truly own what they build from idea to delivery. In DTO, we work in agile, cross-functional teams, mastering the latest technology, and creating outstanding digital experiences that make a real difference for our colleagues and Volvo Group customers around the world. We put people first and build our culture on trust, passion, customer success, change, and performance. If you want to grow, collaborate across functions and entities, and help shape the future of digital products within Volvo Group, DTO is a great place to be.

In some countries and for specific positions within Volvo Group Digital Technology & Operations, background checks (verification of selected information provided by the candidate) may be required, in accordance with local laws & regulations. If this is applicable to the role you have applied for, you will be informed.