HamburgerMenu
hirist

Job Description

Role : Product Security Architect Bengaluru.

The candidate should currently be in Bengaluru.

3 days a week, work from office.

What you'll do :

As Principal, Product Security Architect, you will define and govern secure-by-design architecture across products, platforms, cloud services, and enterprise integrations. You will lead threat modeling and security design reviews, establish reusable security patterns and control requirements, and guide engineering teams in reducing architectural risk throughout the product and software development lifecycle.

How you'll make an impact :

- Design secure end-to-end architectures across applications, APIs, cloud, infrastructure, data, identity, and connected-product environments, balancing security, usability, interoperability, resilience, and cost.

- Lead threat modeling and abuse-case analysis using methodologies such as STRIDE, attack trees, MITRE ATT&CK, and tools such as IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool, or equivalent.

- Define security reference architectures and patterns for identity, encryption, key management, secrets, network segmentation, API security, data protection, logging, and secure communications.

- Embed secure architecture reviews into the SDLC and partner with DevSecOps teams on SAST, DAST, SCA, SBOM, container, IaC, and cloud-security controls using enterprise tooling such as Checkmarx, Veracode, Snyk, Black Duck, or equivalents.

- Assess product and platform designs against medical-device and software-security expectations including IEC 81001-5-1, AAMI TIR57, NIST SSDF, FDA cybersecurity guidance, and applicable enterprise standards.

- Review cloud and container architectures across AWS/Azure/GCP, Kubernetes, microservices, APIs, and third-party integrations for security design gaps and control effectiveness.

- Guide risk treatment and remediation for architectural findings, product vulnerabilities, attack paths, and control deficiencies with engineering and business owners.

- Develop architecture standards, technical memoranda, decision records, and governance artifacts for the internal architecture and product-security community.

- Evaluate emerging security technologies and patterns and provide technical leadership, coaching, and design guidance to senior engineering stakeholders.

What you'll bring :

Skills Required :

- 8+ years of experience in security architecture, solution architecture, product security, or related engineering roles designing secure end-to-end solutions.

- Deep knowledge of secure-by-design principles, threat modeling, security architecture patterns, risk assessment, and control design across applications, cloud, infrastructure, and identity.

- Experience with secure SDLC / DevSecOps practices and security testing disciplines including SAST, DAST, SCA, SBOM, API security, secrets, and container/IaC security.

- Strong understanding of modern cloud-native architectures, APIs, Kubernetes, identity protocols, encryption/PKI, logging, and network-security controls.

- Ability to analyze complex solution constraints and ensure compatibility, interoperability, stability, usability, and security across multiple systems and platforms.

- Strong technical writing, architecture documentation, risk communication, and executive-level stakeholder skills.

- Bachelor's degree in Computer Science, Engineering, Information Security, or a related technical discipline.

Preferred :

- Experience in medical-device, healthcare, or life-sciences product security and familiarity with FDA cybersecurity guidance, IEC 81001-5-1, AAMI TIR57, and NIST SSDF.

- Experience with threat-modeling platforms and security architecture governance at enterprise scale.

- CISSP, CSSLP, SABSA, CCSP, cloud-security, or comparable product/security architecture certification.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...