10 Sep
|
Waisl
|
New Delhi
Security Architect
WAISL, On-Site, Bangalore, Full-time
About the Role
We are seeking a hands-on Security Architect to define, implement, and govern security architecture across a next-generation airport operations and intelligence platform. The role spans cloud-native, hybrid cloud + on-prem, OT/IoT, real-time streaming, AI/ML, and critical airport infrastructure environments. This is a technical role requiring practical architecture skills, not purely governance or compliance.
Key Responsibilities
Security Architecture & Platform Security
- Define enterprise security architecture for hybrid cloud, on-prem, and edge deployments
- Design secure architectures for Kubernetes platforms, event-driven streaming, data lakehouse, AI/ML workloads, and real-time systems
- Build zero-trust patterns; establish security reference architectures and standards
- Perform architecture reviews and threat modeling for new products and integrations
IAM, SSO & Access Governance
- Architect enterprise IAM using Keycloak, Microsoft Entra ID / Azure AD, OAuth2, OIDC, SAML, and JWT
- Design RBAC and multi-tenant isolation across data, API, UI, and streaming layers
- Define service-to-service authentication, secrets management, and certificate strategies
Cloud & Kubernetes Security
- Define security controls for AWS and Kubernetes: network segmentation, service mesh, API gateway, WAF, runtime security, container scanning, supply chain
- Establish DevSecOps pipelines and hardening standards for Kubernetes, APIs, databases, etc.
Data & Streaming Security
- Secure large-scale platforms built on Apache Kafka, Flink, Iceberg, and NiFi
- Define encryption, tokenization, data masking, PII protection, lineage, and secure multi-tenancy
OT / IoT / Airport Systems Security
- Design secure IT/OT/IoT integration patterns; secure SCADA, BMS, PLCs, OPC-UA, MQTT, and CCTV/VMS systems
- Define IEC 62443-aligned OT segmentation zones and secure edge ingestion architectures
Security Operations & Governance
- Define logging, monitoring, audit, and incident response architecture
- Support SIEM, SOC, IDS/IPS, and threat detection integration
- Conduct threat modeling, risk assessments, vulnerability remediation guidance, and compliance audits
Required Skills & Experience
Core Experience
- 10+ years in cybersecurity, platform security, or security architecture
- Strong hands-on experience in cloud-native and hybrid infrastructure security
- Experience in critical infrastructure, airports, or OT environments preferred
Technical Skills
Cloud & Infrastructure
- AWS/Azure security architecture
- Kubernetes & container security
- VPN and hybrid connectivity
- Linux hardening
Data & Streaming
- Kafka security
- Secure API architecture
- Data governance & encryption
- Real-time platform security
IAM & Identity
- Keycloak, Azure AD / Entra ID
- OAuth2 / OIDC / SAML
- RBAC / ABAC
- PKI & certificate management
OT/IoT Security
- IEC 62443
- SCADA / ICS security
- OT network segmentation
- Industrial protocols & gateways
DevSecOps & Tooling
Vault, Kong/API gateways, Wazuh/Falco/Zeek, Trivy, Prometheus/Grafana, ELK/OpenSearch, SIEM platforms
Positive to Have
- Application, Cloud, System architecture experience
- Experience in airport, transportation, smart city, or critical infrastructure domains
- Exposure to AI/ML, Digital Twin, GIS, or operational intelligence platforms
- Knowledge of NIST, ISO 27001, CERT-In, and IEC 62443 frameworks
Qualifications
- Bachelor's or Master's in Computer Science, Cybersecurity, Information Security, or related field
- Preferred certifications: CISSP, CCSP, CISM, AWS Security Specialty, Kubernetes Security, IEC 62443
What We're Looking For
- Strong systems thinking
- Practical engineering mindset
- Bridge OT + IT + Cloud + Data + AI ecosystems
- Collaborative across architects, developers, DevOps, and customers
- Strong documentation skills
- Comfortable in fast-moving platform environments
📌 Security Architect (New Delhi)
🏢 Waisl
📍 New Delhi