HamburgerMenu
hirist

Cyber Security Architect - CISSP/CISM/CISA

Tidyhire
12 - 20 Years
Hyderabad

Posted on: 24/07/2026

Job Description

We are seeking a highly experienced Senior Product Security Architect who will be responsible for embedding security into the entire product lifecycle, from design to deployment while enabling secure innovation at scale.

Key Responsibilities:

1. Security Architecture & Strategy:

- Define and implement product security architecture frameworks and standards.

- Integrate Security-by-Design and Privacy-by-Design principles into all products.

- Establish a long-term product security roadmap aligned with business strategy.

- Lead threat modeling and risk assessments for critical products and platforms.

- Provide architectural guidance for: 1. Cloud-native applications 2. Microservices and APIs 3. SaaS and enterprise platforms.

- Drive adoption of security frameworks including: 1. NIST Secure Software Development Framework (SSDF) NIST SP 800-218 2. OWASP SAMM (Software Assurance Maturity Model).

2. Secure SDLC (Software Development Lifecycle):

- Design and implement a Secure SDLC (SSDLC) framework across teams.

- Embed security controls across: 1. Design 2. Development 3. Testing 4. Deployment.

- Define and enforce: 1. Secure coding standards 2. Secure coding practices 3. DevSecOps integration.

- Ensure adoption of: 1. SAST (Static Application Security Testing) 2. DAST (Dynamic Application Security Testing) 3. SCA (Software Composition Analysis) 4. Penetration Testing frameworks.

- Establish security maturity metrics and SSDLC governance aligned with NIST SSDF and OWASP SAMM.

3. Engineering & DevSecOps Enablement:

- Partner with engineering teams to shift security left.

- Drive adoption of DevSecOps practices and automation.

- Enable teams through: 1. Security training and awareness 2. Secure coding guidelines 3. Architecture reviews.

- Implement and govern CI/CD security controls and secure pipeline configurations.

- Act as a trusted advisor to engineering leadership.

4. Vulnerability & Risk Management:

- Oversee application and product vulnerability management lifecycle.

- Define prioritization frameworks based on: 1. Risk severity 2. Business impact.

- Drive remediation programs and SLAs.

- Conduct: 1. Penetration testing reviews 2. Security assessments.

- Interpret and prioritize findings from SAST, DAST, SCA, and penetration testing activities.

5. Cloud & Infrastructure Security:

- Provide security architecture for: 1. AWS / Azure / GCP environments 2. Container security (Docker, Kubernetes).

- Define controls for: 1. Identity & Access Management (IAM) 2. Data protection (encryption, key management) 3. Network security.

6. Regulatory Compliance & Governance:

- Ensure compliance with industry standards: 1. ISO 27001 2. SOC 2 3. GDPR and Data Privacy regulations.

- Implement audit-ready processes and controls.

- Partner with risk teams for: 1. Security audits 2. Compliance assessments.

7. Leadership & Stakeholder Management:

- Lead and mentor a team of Product Security Engineers and Architects.

- Collaborate with: 1. Engineering leadership 2. Product management 3. Cybersecurity teams 4. External vendors and partners.

- Influence senior stakeholders on: 1. Security investments 2. Risk posture 3. Strategic priorities.

8. Incident Readiness & Response:

- Support security incident handling related to product vulnerabilities.

- Define incident response playbooks for product security risks.

- Conduct post-incident reviews and improve controls.

Experience:

- 1218+ years of experience in: 1. Application Security 2. Product Security 3. Security Architecture 4. DevSecOps.

- Proven experience in a leadership role (Senior Manager / Architect level).

- Hands-on expertise in: 1. Secure application design 2. Threat modeling 3. Security architecture 4. Secure SDLC implementation.

Technical Skills:

- Strong knowledge of: 1. OWASP Top 10 2. Secure coding standards 3. API security 4. NIST Secure Software Development Framework (SSDF) SP 800-218 5. OWASP SAMM (Software Assurance Maturity Model).

- Experience with: 1. Cloud security (AWS / Azure / GCP) 2. Container and Kubernetes security 3. CI/CD pipelines and DevOps tools 4. Implementation of CI/CD security controls and secure pipeline configurations 5. DevSecOps frameworks and automation.

- Strong understanding of: 1. SAST (Static Application Security Testing) 2. DAST (Dynamic Application Security Testing) 3. SCA (Software Composition Analysis) 4. Penetration Testing methodologies and frameworks 5. Security testing and vulnerability remediation workflows.

- Familiarity with: 1. SIEM and monitoring tools 2. Security orchestration and automation tools.

Certifications (Preferred):

- CISSP (Certified Information Systems Security Professional)

- CSSLP (Certified Secure Software Lifecycle Professional)

- CISM / CISA

- AWS Security Specialty

- Microsoft Azure Security Engineer

- Relevant DevSecOps or Cloud Security certifications.

Leadership Competencies:

- Strategic thinking with strong execution focus.

- Ability to influence without authority.

- Strong stakeholder management at the leadership level.

- Problem-solving and risk-based decision making.

- Ability to translate technical risks into business impact.

- Strong communication and executive presentation skills.

Success Metrics (KPIs):

- Reduction in critical vulnerabilities across products.

- Adoption rate of Secure SDLC practices.

- Improvement in security posture and audit outcomes.

- Reduction in time-to-remediation.

- Increased awareness and secure coding adoption across teams.

- Improvement in SSDLC maturity and DevSecOps adoption.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...