Application Security Compliance Lead

Lead
Companyncratleos.com
LocationGURGAON, IND, HYDERABAD, IND
CategorySecurity
SeniorityLead
Workplace-
Posted2026-09-18
Viaworkday

Description

About NCR Atleos

NCR Atleos, headquartered in Atlanta, is a leader in expanding financial access. Our dedicated 20,000 employees optimize the branch, improve operational efficiency and maximize self-service availability for financial institutions and retailers across the globe.

Title: Application Security Compliance Lead

Location: Gurgaon or Hyderabad, India

About NCR Atleos

NCR Atleos Corporation (NYSE: NATL) is a global technology company that enables financial access and commerce through assisted and self-service solutions and comprehensive support services. NCR Atleos serves financial and public-sector   organizations   in more than 100 countries and is headquartered in Atlanta, Georgia, USA.

The opportunity

As an Application Security Compliance Lead, you will help ensure that NCR Atleos software products and development practices meet applicable security,   privacy   and regulatory requirements. Working within our global Application Security team, you will turn complex requirements into practical guidance, prepare teams for   assessments,   and help   demonstrate   that security and privacy are embedded throughout the software lifecycle.

A major focus is   organization -level   PCI Software Security Framework   (SSF)   activit ies : support product teams to achieve and   retain   PCI Secure Software Standard listings and   maintain   validation of our Secure Software Lifecycle practices. This role suits someone who combines compliance   expertise   with software development and application security knowledge.

What you will do

-
Govern the Secure SDLC.  Maintain and improve practices aligned with the   PCI Secure SLC Standard .

-
Enable PCI SSF validation.  Guide teams through external   assessment , self-assessment, annual   attestation   and periodic revalidation activities.

-
Interpret requirements.  Translate security, privacy, legal and industry requirements into clear, proportionate guidance.

-
Assess readiness and close gaps.  Coordinate reviews, evidence, gap analysis,   remediation   and resolution of findings.

-
Engage and influence.  Partner with engineering, Legal, risk,   compliance   and security teams ,   QSAs   and the PCI S SC .

-
Build capability.  Create training and reusable guidance; monitor developments and communicate material changes.

-
Drive   continual improvement.   Use   industry changes, stakeholder feedback, internal audits,   assessment outcomes, recurring   findings,   and incidents   to strengthen controls and processes.

What you will bring

Essential experience and capabilities

-
Typically,   7 + years of relevant experience   in application security, software security assurance, secure software development, technology risk, privacy, compliance ,   or audit.

-
Practical e xperience developing,   operating ,   governing   or assessing a   Secure SDLC .

-
Experience interpreting security or compliance requirements and supporting assessments, evidence collection, gap   analysis   and remediation.

-
Working knowledge of threat modelling, vulnerability management, security   testing,   and risk-based decision-making.

-
Technical understanding of cloud services, source-code   management,   and CI/CD practices   sufficient   to engage credibly with engineering teams.

-
Ability to convert complex requirements into pragmatic guidance and make evidence-based recommendations.

-
Strong stakeholder management, communication, analytical and problem-solving skills, including the ability to influence without direct authority.

-
Ability to work independently and effectively within a globally distributed team.

-
Comfortable using AI assistan ts , such as   Copilot, responsibly in day-to-day work to improve personal productivity, quality ,   and speed of delivery.

-
A bachelor’s degree in a STEM discipline, or   equivalent   relevant professional experience and qualifications.

Desirable experience and capabilities

-
Direct experience of   PCI SSF   validation   or a comparable software security assurance framework.

-
Knowledge of   payment-card security ,   GDPR   requirements,   NIST CSF and OWASP   standards and   guidance.

-
Experience delivering application security or compliance -related   training.

-
Knowledge of security and governance for AI-enabled software development   and   products.

-
A relevant certification, such as CISSP, CSSLP, CIPP, CIPT or CIPM.

How you will succeed

-
Teams receive clear,   timely ,   and actionable compliance guidance.

-
PCI SSF validation activities are well planned, appropriately   evidenced ,   and progressed effectively.

-
Compliance gaps and findings are clearly owned, prioritized,   tracked,   and resolved.

-
Secure SDLC requirements   remain   practical,   current,   and consistently understood.

-
Assessment and incident lessons lead to sustainable improvements and strong stakeholder relationships.

Evidence we value

In your application, we would particularly welcome examples of how you have interpreted a security standard, prepared a product or   organization   for assessment, resolved a significant compliance gap, or influenced an engineering team to adopt a more effective security practice.

Offers of employment are conditional upon passage of screening criteria applicable to the job.

EEO Statement
NCR Atleos is an equal-opportunity employer. It is NCR Atleos policy to hire, train, promote, and pay associates based on their job-related qualifications, ability, and performance, without regard to race, color, creed, religion, national origin, citizenship status, sex, sexual orientation, gender identity/expression, pregnancy, marital status, age, mental or physical disability, genetic information, medical condition, military or veteran status, or any other factor protected by law.

Statement to Third Party Agencies

To ALL recruitment agencies: NCR Atleos only accepts resumes from agencies on the NCR Atleos preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Atleos employees, or any NCR Atleos facility. NCR Atleos is not responsible for any fees or charges associated with unsolicited resumes.