Overview
Principal Security Architect for Product and Application Security, defining and embedding security architecture into the product lifecycle and advising engineering/product teams with security and risk guidance.
What you'll do
- Maintain awareness of product and application architectures and their alignment to threat landscape, regulatory requirements, and business risk tolerance.
- Provide subject-matter expertise in application security architecture for web applications, APIs, microservices, and distributed systems.
- Define and drive adoption of secure design patterns, reference architectures, policies/standards, and secure coding guidelines.
- Integrate application security controls into SDLC and CI/CD pipelines (e.g., SAST, DAST, SCA, secret scanning, IaC/PaC/SaC where applicable).
- Partner early with product and engineering teams to perform architecture and design reviews.
- Coordinate integration of security services into internally and externally-facing solutions and manage remediation for security gaps.
What you'll need
- Typically 12+ years of related experience.
- At least 6 years in a security role.
- 3 years in a defensive application security role working directly with software engineering teams.
- Experience designing and reviewing secure application and API architectures.
- Experience driving application security tooling implementation (SAST, DAST, SCA, API security, secrets management).
- Experience integrating security into CI/CD pipelines and developer workflows.
- Practical knowledge of security frameworks including NIST CSF and OWASP SAMM.
Details
- Location: Hyderabad, Telangana, India.
- Work mode: 100% in office.
Read the full description and apply on the company’s own careers page.