HamburgerMenu
hirist

Sunovaa Tech - Cyber Security Subject Matter Expert

Sunovaa Tech
8 - 15 Years
Pune

Posted on: 15/07/2026

Job Description

About the Role :

We are looking for an experienced Cybersecurity Subject Matter Expert (SME) to drive security-by-design across enterprise software products, cloud platforms, and containerized environments. The ideal candidate will have hands-on experience in Application Security, Product Security, Cloud Security (Azure/AWS), Kubernetes Security, Threat Modeling, and Secure SDLC.

This role requires someone who can partner with architects, engineering teams, DevOps, QA, and product management to embed cybersecurity throughout the software development lifecycle.

Key Responsibilities :

- Lead cybersecurity architecture reviews and provide security design recommendations.

- Perform Threat Modeling, Threat & Risk Assessments (TRA), and security architecture reviews.

- Drive implementation of Secure Software Development Lifecycle (SSDLC) practices.

- Secure cloud-native applications running on Azure or AWS.

- Review and secure Kubernetes and containerized workloads.

- Lead vulnerability management, remediation tracking, and security risk assessments.

- Coordinate penetration testing and support remediation activities.

- Guide engineering teams on secure coding practices and security-by-design principles.

- Work closely with DevOps teams to integrate security into CI/CD pipelines.

- Provide governance for SAST, DAST, SCA, and SBOM as part of the application security lifecycle.

- Ensure compliance with OWASP Top 10, NIST, ISO 27001/27002, and other industry security standards.

- Mentor engineering teams on cybersecurity best practices.

Mandatory Skills :

- 8+ years of experience in Product Security, Application Security, Security Architecture, or Cybersecurity Engineering.

- Strong experience in Threat Modeling and Threat & Risk Assessments.

- Hands-on experience securing cloud environments on Azure and/or AWS.

- Strong experience with Kubernetes Security, Docker, and container security best practices.

- Experience implementing Secure SDLC (SSDLC).

- Strong understanding of Vulnerability Management and Penetration Testing.

- Experience with :

1. SAST

2. DAST

3. Software Composition Analysis (SCA)

4. SBOM

- Knowledge of :

1. OWASP Top 10

2. NIST

3. ISO 27001/27002

4. Security Architecture Principles

- Experience collaborating with software engineering, DevOps, QA, and architecture teams.

Preferred Skills :

- CISSP / CSSLP / CCSP / CEH / CKS certifications.

- Experience in healthcare, medical devices, or other regulated industries.

- DevSecOps implementation experience.

- Infrastructure as Code (Terraform/Bicep/CloudFormation).

- CI/CD security and automation.

What We're Looking For :

We are specifically looking for professionals who have hands-on experience designing and implementing security solutions, rather than candidates whose work has been limited to security tool administration, report generation, or vulnerability scanning.

The ideal candidate should have demonstrated experience in :

- Product Security

- Cloud Security

- Kubernetes Security

- Security Architecture

- Threat Modeling

- Secure SDLC

- Application Security Reviews

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...