HamburgerMenu
hirist

Security Architect - Vulnerability & Risk Management

BG Consultants
8 - 14 Years
Delhi NCR

Posted on: 25/06/2026

Job Description

Overview :

We are looking for an experienced Security Architect to join the Engineering organization and drive a security-first culture across our platforms, products, and infrastructure. This role will serve as the primary security leader within Engineering, partnering closely with Infrastructure, DevOps, Cloud, Product, and Development teams to ensure security is embedded throughout the software development lifecycle and cloud operations.

The ideal candidate must possess strong expertise in both Application Security and Infrastructure/Cloud Security, with the ability to challenge, influence, and guide teams toward secure architectural decisions while balancing business and delivery objectives.

This role will be responsible for establishing security as a first-class citizen across engineering initiatives, defining security standards, governing implementation, and driving continuous security improvements.

As the organization expands its investments in AI-enabled platforms, intelligent automation, and agentic workflows, this role will also be responsible for defining the security strategy and governance model for emerging AI technologies. The Security Architect will ensure that security controls evolve alongside modern engineering practices, enabling safe adoption of AI-powered applications, autonomous agents, and next-generation software delivery capabilities.

Key Responsibilities :

1. Security Architecture & Governance :

- Define and maintain enterprise-wide security architecture principles, standards, and best practices.

- Review and approve application, platform, cloud, and infrastructure designs from a security perspective.

- Establish secure-by-design and secure-by-default engineering practices.

- Develop and maintain security reference architectures, patterns, and reusable controls.

2. Application Security :

- Drive security throughout the Software Development Lifecycle (SDLC).

- Define and implement secure coding standards and security guardrails.

- Lead threat modeling exercises for critical applications and platforms.

- Oversee SAST, DAST, dependency scanning, container scanning, and software supply chain security initiatives.

- Partner with development teams to remediate vulnerabilities and security findings.

- Review APIs, microservices, authentication mechanisms, and data protection strategies.

3. Infrastructure & Cloud Security :

- Partner with Infrastructure and Cloud teams to design secure cloud-native architectures.

- Drive implementation of security controls across AWS, Azure, and hybrid environments.

- Review network architecture, IAM, WAF, load balancers, VPNs, firewalls, and segmentation strategies.

- Establish security baselines for servers, containers, Kubernetes clusters, and cloud services.

- Ensure compliance with security policies, standards, and regulatory requirements.

4. DevSecOps & Security Automation :

- Integrate security controls into CI/CD pipelines.

- Drive automation of security testing and compliance validation.

- Define metrics, KPIs, and dashboards to measure security posture.

- Promote Infrastructure-as-Code and Policy-as-Code security practices.

5. Vulnerability & Risk Management :

- Establish vulnerability management processes across applications and infrastructure.

- Prioritize remediation based on risk and business impact.

- Lead security reviews and risk assessments for new initiatives.

- Provide security sign-off for production releases and critical architectural decisions.

6. Security Leadership & Collaboration :

- Act as the primary security representative within Engineering.

- Partner closely with Infrastructure, DevOps, Enterprise Architecture, Product Management, and Engineering Leadership.

- Challenge designs and implementation decisions when security risks are identified.

- Mentor engineering teams on security best practices.

- Drive security awareness and cultivate a security-first engineering culture.

7. AI, Agentic & Emerging Technology Security :

- Define security principles, standards, and governance frameworks for AI-enabled applications and agentic platforms.

- Establish security guardrails for autonomous agents, intelligent workflows, and machine-to-machine interactions.

- Assess risks associated with Large Language Models (LLMs), AI services, model integrations, and third party AI platforms.

- Develop controls around prompt security, data privacy, access management, context handling, and auditability.

- Collaborate with Architecture and Engineering teams to implement secure AI adoption practices.

- Drive governance and monitoring mechanisms for AI-driven decision making and automated workflows.

- Evaluate emerging AI security threats including prompt injection, data leakage, model abuse, excessive agent permissions, and supply chain vulnerabilities.

- Partner with Engineering Excellence and Platform Engineering teams to establish secure AI development standards.

- Provide architectural guidance for AI-assisted software development and secure use of developer productivity tools.

Required Qualifications :

- 8- 10+ years of experience in Information Security, Security Architecture, Application Security, or Cloud Security.

- Strong hands-on experience with both Application Security and Infrastructure Security.

- Deep understanding of secure software development practices.

- Experience securing cloud environments such as AWS and/or Azure.

- Experience implementing security controls in CI/CD pipelines.

- Ability to perform threat modeling and security architecture reviews.

- Strong stakeholder management and influencing skills.

Preferred Qualifications :

- Security certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, Azure Security Engineer, TOGAF, or equivalent.

- Experience in highly regulated environments.

- Experience establishing security programs within engineering organizations.

- Familiarity with compliance frameworks such as ISO 27001, SOC 2, PCI-DSS, NIST, or CIS Controls.

- Exposure to Generative AI, Large Language Models (LLMs), Agentic AI frameworks, or intelligent automation platforms.

- Understanding of AI security concepts including model security, prompt injection risks, data governance, and AI risk management.

- Familiarity with emerging AI governance and security frameworks.

Success Measures :

- Security is embedded into every stage of the engineering lifecycle.

- Security reviews become a standard part of architecture and release processes.

- Vulnerability remediation timelines improve significantly.

- Cloud and infrastructure environments adhere to defined security baselines.

- Security tooling and automation are integrated into CI/CD pipelines.

- Engineering teams proactively consider security requirements during design and implementation.

- Security becomes a shared responsibility and a first-class citizen across the organization.

- AI and agentic platform initiatives are launched with appropriate governance, security controls, and risk management processes.

- Security standards and guardrails are established for AI-assisted development and autonomous workflow platforms.

- Emerging AI-related risks are proactively identified and mitigated before production adoption.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...