Product Security Lead, Security Architecture (Bengaluru)

Product Security Lead, Security Architecture (Bengaluru)

07 Sep
|
Insight Global
|
Bengaluru

07 Sep

Insight Global

Bengaluru

Job Description Insight Global is seeking an experienced Product Security Lead to provide security architecture leadership across digital products, enterprise applications, cloud services, APIs, mobile applications, and AI-enabled solutions. This role will initially focus heavily on security architecture, application analysis, and threat modeling. The Product Security Lead will assess both modern and legacy applications, identify architectural risks and security weaknesses, and provide practical recommendations for how applications should be modified, modernized, or protected. This is not a governance-only position. The successful candidate must be able to move from architecture discussions into hands-on technical analysis, including source code review, security testing, vulnerability validation, WAF analysis, and remediation support. The Product Security Lead will work directly with application developers, product teams, cloud teams, and security engineers to resolve issues rather than simply documenting findings or transferring work to another team. The ideal candidate combines the design expertise of a Security Architect with the technical execution skills of a senior Product Security or Application Security Engineer. Key Responsibilities Security Architecture and Application Analysis Lead security architecture reviews for business-critical applications, digital products, APIs, cloud services, mobile solutions, and AI-enabled platforms. Analyze current-state application architectures, including legacy applications, to identify security weaknesses, outdated design patterns, and modernization requirements. Recommend practical changes to application architecture, code, infrastructure, identity controls, integrations, and data flows. Define secure design patterns, reusable security controls, reference architectures, and architecture guardrails. Translate business requirements, technical constraints, and security risks into explicit and actionable architecture decisions. Review proposed technology changes from initial design through implementation, deployment, and major application upgrades. Evaluate architectural tradeoffs and provide defensible, risk-based recommendations. Threat Modeling Lead threat modeling sessions for new and existing applications using methodologies such as STRIDE, attack trees, abuse cases, and attack-path analysis. Identify trust boundaries, sensitive data flows, attack surfaces, misuse scenarios, and potential control gaps. Translate threat-modeling results into specific security requirements, engineering tasks, and remediation priorities. Evaluate how threats may affect legacy systems, cloud-native applications, APIs, mobile applications, integrations, and AI-enabled solutions. Maintain threat models as applications, architectures, and business capabilities evolve. Coach product and engineering teams on incorporating threat modeling into the software development lifecycle. Application Security and Source Code Analysis Conduct hands-on source code analysis and secure code reviews across applicable programming languages and frameworks. Analyze findings produced by SAST, DAST, SCA, API security, secrets detection, container security, and Infrastructure as Code scanning tools. Validate vulnerabilities, eliminate false positives, assess exploitability, and determine root causes. Work directly with application teams to develop and implement remediation plans. Provide code-level and design-level guidance to prevent recurring vulnerabilities. Validate completed remediation and confirm that identified risks have been appropriately addressed. Support manual application and API security testing when automated scanning does not provide sufficient coverage. Cloud and Platform Security Provide security architecture guidance across a multicloud environment, with a primary emphasis on Microsoft Azure and working knowledge of AWS and GCP. Review cloud-native, hybrid, containerized, Kubernetes, serverless, microservices, and event-driven architectures. Assess cloud identity, network design, data protection, secrets management, encryption, logging, monitoring, and workload security.



Evaluate cloud configurations and application deployments for security weaknesses and architectural risk. Partner with cloud and platform engineering teams to implement scalable, secure-by-design controls. Support secure modernization and cloud migration planning for legacy applications. SAST, DAST, SCA, and DevSecOps Develop risk-based application security testing strategies using SAST, DAST, SCA, source code review, API testing, container scanning, cloud security testing, and manual validation. Help integrate security testing and quality gates into CI/CD pipelines and developer workflows. Review scan configurations and results to improve testing coverage, accuracy, and actionable developer feedback. Partner with DevSecOps teams to automate security controls and remediation workflows. Define appropriate testing requirements based on application criticality, architecture, data sensitivity, and external exposure. Help engineering teams understand and address findings rather than simply routing findings to a separate security team. Web Application Firewall and Runtime Protection Review WAF architectures, policies, rule sets, coverage, logging, and application onboarding approaches. Analyze WAF findings, traffic behavior, false positives, and control gaps. Recommend and support rule changes, tuning activities, exceptions, and compensating controls. Evaluate WAF integration with API gateways, CDN services, bot management, logging platforms, and incident response processes. Partner with application owners and security engineers to ensure WAF protections align with application behavior and risk. AI and Emerging Technology Security Assess the architecture and security of AI-enabled and LLM-based applications. Perform threat modeling for AI use cases, data flows, models, integrations, agents, tools, and external AI services. Evaluate risks associated with prompt injection, insecure output handling, sensitive data exposure, excessive agency, data poisoning, model theft, and unsafe third-party dependencies. Define controls for AI model and data access, prompt and output handling, agent permissions, AI APIs, Retrieval-Augmented Generation, and ML pipelines. Partner with product, engineering, data, and AI teams to support secure innovation and practical risk reduction. Security Leadership and Consultation Serve as a trusted security advisor to product owners, application architects, developers, cloud teams, and technology leadership. Provide real-time consultation during design, development, testing, and remediation activities. Communicate technical risks and recommendations clearly to both technical and nontechnical stakeholders. Create architecture diagrams, assessment reports, security requirements, decision records, and executive-ready risk summaries. Mentor security engineers and help strengthen architecture, threat-modeling, and application security capabilities across the team. Support security incidents, root-cause analysis, and post-incident architecture improvements when required. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process,



please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/. Skills and Requirements Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline. 10 to 12 years of progressive experience across cybersecurity, Product Security, Application Security, Security Engineering, or Security Architecture. Demonstrated experience leading security architecture reviews for complex, business-critical applications. Deep, hands-on experience conducting threat modeling and translating identified threats into actionable technical requirements. Strong experience evaluating existing and legacy applications and recommending secure modification or modernization strategies. Hands-on experience with source code analysis, secure code review, vulnerability validation, and remediation. Strong working knowledge of SAST, DAST, SCA, API security testing, WAF technologies, and secure SDLC practices. Experience securing applications in multicloud environments, with strong Azure experience and working knowledge of AWS and GCP. Experience partnering directly with development teams to resolve security issues at the architecture, configuration, and code levels. Ability to operate independently and make practical, risk-based security decisions. Solid written, verbal, presentation, stakeholder-management, and consultative communication skills. The ideal candidate is a senior, hands-on Product Security leader who can assess an application architecture, facilitate a detailed threat model, review source code or testing results, and work directly with developers to address the identified risk. This individual should be comfortable setting architectural direction while remaining close to the technology. The successful candidate will be consultative, practical, and solutions-oriented, with the ability to improve security without unnecessarily slowing product delivery. Secure software architecture and secure design patterns Threat modeling, trust-boundary analysis, abuse cases, attack trees, and attack-path analysis Web, mobile, API, cloud, container, microservices, serverless, and legacy application security Source code review and analysis in one or more languages such as Java, C#/.NET, Python, JavaScript/TypeScript, Go, or Apex SAST, DAST, SCA, API security testing, container scanning, IaC scanning, and secrets detection Azure cloud security, with working knowledge of AWS and GCP WAF architecture, policy development, application onboarding, traffic analysis, and rule tuning OAuth 2.0, OpenID Connect, SAML, workload identity, least privilege, and Zero Trust CI/CD security integration using Azure DevOps and/or GitHub Encryption, key management, certificate management, secrets management, and data protection OWASP Top 10, OWASP API Security Top 10, CWE Top 25, and OWASP guidance for LLM applications Relevant Tools and Technologies Application Security: Snyk, GitHub Advanced Security, Burp Suite, Qualys, MobSF, Postman Cloud Security: Wiz and native security services within Azure, AWS, and GCP WAF and Edge Security: Fastly, Cloudflare, Akamai, or comparable enterprise WAF technologies Source Control and DevSecOps: Azure DevOps, GitHub, CI/CD security tooling Logging and Analysis: Elastic or comparable logging and security analytics platforms Architecture: Threat-modeling tools, architecture diagramming tools, data-flow diagrams, and architecture decision records Experience supporting security architecture within a large, global, matrixed enterprise. Experience modernizing or securing legacy enterprise applications. Experience with AI/LLM application security and AI-specific threat modeling. Experience integrating application security controls into developer workflows and CI/CD pipelines. Experience mentoring security engineers or providing technical leadership across Product Security initiatives. Relevant certifications such as CISSP, CSSLP, CCSP, SABSA, TOGAF, or cloud security and architecture certifications.

📌 Product Security Lead, Security Architecture (Bengaluru)
🏢 Insight Global
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: product security lead, security architecture (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: product security lead, security architecture (bengaluru) / bengaluru