Senior Software- Security Agent Architect (India)

Senior Software- Security Agent Architect (India)

06 Aug
|
SISA
|
India

06 Aug

SISA

India

About the Role

We build a distributed, agent-based endpoint security platform for the payment ecosystem, combining an endpoint agent (a core runtime plus pluggable security modules, built entirely in Go), an on-premise management component deployed at the customer site, a local telemetry relay component, and a cloud backend. Kernel-level components that hook into the OS are written in C/C++, as is standard for driver-level development. We're looking for a Senior/Principal Architect to own end-to-end architecture across this stack — from the control-plane protocol on the endpoint, through on-premise components, to secure egress into the cloud backend. This is a hands-on architecture role: you will be expected to review code and low-level design, not just produce diagrams.

Key Responsibilities

- Define the architecture for kernel-level components on the endpoint (drivers/kernel modules used for real-time monitoring, hooking, or enforcement), including their interaction with and isolation from the user-mode agent runtime and its modules.
- Own architectural decisions across the full platform: the endpoint agent (core runtime + pluggable security modules), the on-premise management component, the on-premise telemetry relay component, and the cloud backend.
- Define and evolve the control-plane (gRPC/Protobuf) and data-plane transport strategy between the endpoint agent, the on-premise management component, and the telemetry relay component.
- Own version compatibility strategy across independently-versioned components (agent, core runtime, modules, management component, cloud backend).
- Design secure, outbound-only, multi-tenant deployment topology — mTLS and certificate lifecycle management, IPSec/VPN egress design — suitable for PCI-regulated payment industry clients.
- Own the client-facing security architecture narrative: per-hop network/port/protocol documentation, PCI-DSS scoping discussions,



and direct engagement with client InfoSec/audit teams.
- Architect the security-module lifecycle: subscription entitlement enforcement, binary distribution, staged/canary rollout and rollback, resource governance across concurrently running modules, and failure isolation so a single module cannot take down the core agent runtime.
- Define HA/DR strategy for on-premise components deployed inside customer environments that are not directly operated by us.
- Evaluate and decide on the design of any bi-directional channel between the cloud backend and on-premise components, ensuring it doesn't undermine the outbound-only security posture documented to clients.
- Run architecture reviews, mentor senior and mid-level engineers, and own technical roadmap and tech-debt prioritization.
- Represent the company in high-stakes architecture and security review calls with enterprise client stakeholders.

Required Technical Skills

- 15–20+ years in software engineering, including 8+ years in architecture or senior technical leadership roles.
- Deep expertise in distributed systems design; direct experience with agent-based security products (EDR/XDR, endpoint protection, DLP, or similar) is strongly preferred.
- Solid hands-on background in Go — the agent runtime and its modules are built entirely in Go — plus working proficiency in C/C++ for reviewing and guiding kernel-level driver work. Able to review code and low-level design in depth, not just at a diagram level.
- Solid understanding of kernel-level/OS-internals development (e.g., Windows kernel drivers/minifilters, Linux kernel modules/eBPF)



sufficient to architect and review how endpoint agents hook into the OS for real-time monitoring or enforcement, and to reason about the security and stability risks that come with it.
- Expert-level knowledge of gRPC, Protocol Buffers, and HTTP/2, including streaming and multiplexing trade-offs at scale.
- Strong grasp of mTLS/PKI design: certificate issuance, rotation, and revocation for large, distributed fleets.
- Solid understanding of network security fundamentals: IPSec/VPN tunnel design, NAT/firewall traversal, and outbound-only architecture patterns for customer-premise deployments.
- Experience architecting multi-tenant SaaS products with components deployed partially on customer premises, not just in a vendor-controlled cloud.
- Working knowledge of PCI-DSS (or equivalent frameworks such as ISO 27001/SOC 2) and their direct implications on network and data-flow architecture.

Preferred / Nice to Have

- Prior architecture role at a cybersecurity product company (EDR, XDR, SIEM, DLP, or breach-and-attack simulation).
- Direct exposure to active security-testing or breach-and-attack simulation style products.
- Cloud infrastructure experience (AWS/Azure/GCP) for the backend/cloud side of the platform.
- Track record presenting architecture directly to enterprise client security/audit teams.

What Success Looks Like in This Role

- A documented, defensible security architecture narrative that survives client InfoSec audits without surprises.
- A version compatibility and module-lifecycle strategy that prevents fleet-wide breakage from a single bad rollout.
- A mentored engineering team capable of making sound architectural trade-offs independently.

Education

Bachelor's or Master's degree in Computer Science, Engineering, or a related field. Equivalent hands-on experience will be given full weight over formal qualifications.

📌 Senior Software- Security Agent Architect (India)
🏢 SISA
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior software- security agent architect (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: senior software- security agent architect (india) / india