26 Aug
|
Acme Services Private
|
India
26 Aug
Acme Services Private
India
Job Description:
1. Security Architecture & Design
- Develop and maintain enterprise security architecture standards, patterns, reference architectures, and roadmaps.
- Embed security principles across cloud, on-premises, application, data, network, and endpoint environments.
- Review solution designs and provide recommendations covering cloud security, encryption, network segmentation, identity, and monitoring.
- Translate business and technology requirements into secure, scalable, compliant, and cost-effective architectures.
- Promote Secure-by-Design principles across projects and engineering teams.
2. Security Governance & Assurance
- Conduct security architecture assessments, design reviews, and security evaluations for current initiatives and major technology changes.
- Validate cybersecurity tool configurations and integrations against enterprise architecture standards.
- Ensure alignment with frameworks and regulatory requirements such as ISO 27001, NIST CSF, CIS, GDPR, RBI/SEBI guidelines, and applicable risk-management requirements.
- Ensure security architecture remains aligned with enterprise strategy and organizational risk appetite.
3. Cybersecurity Domain Expertise
The candidate should have broad architecture-level knowledge across:
- Cloud Security: AWS, Azure, GCP, cloud landing zones, IAM, segmentation, security policies, monitoring, Prisma Cloud, Wiz, Microsoft Defender for Cloud, AWS Security Hub, and container security.
- Endpoint & Workload Security:
Crowd Strike, Microsoft Defender, Sentinel One, EDR/XDR, endpoint security baselines, threat prevention, and OS hardening.
- Network & Perimeter Security: Palo Alto, Fortinet, Cisco firewalls, proxies, VPN, DNS security, Zero Trust, and IDS/IPS.
- Application & API Security: Threat modeling, Dev SecOps, secure application architecture, WAF, API Gateway, SAST/DAST, and API security.
- Data Security: Encryption, DLP, data classification, tokenization, KMS, HSM, CASB, and data-access governance.
- Zero Trust: Identity-first access, micro-segmentation, continuous validation, session risk assessment, and telemetry-driven security decisions.
4. Stakeholder Management & Advisory
- Act as a trusted security advisor to IT, Cloud, Infrastructure, Application, Security Operations, and Business teams.
- Conduct architecture walkthroughs and provide technical guidance to project managers, engineers, and operations teams.
- Participate in vendor evaluations and security due diligence for third-party solutions.
- Influence stakeholders to adopt secure and risk-aligned technology designs.
5. Security Architecture Documentation
- Create and maintain HLD/LLD documents, architecture blueprints, security patterns, and integration diagrams.
- Document architecture gaps, security risks, mitigations, and recommendations.
- Maintain reusable security reference architectures and enterprise security templates.
📌 Security Architect and engineering (India)
🏢 Acme Services Private
📍 India