Security Architect (India)

Security Architect (India)

12 Sep
|
HCLSoftware
|
India

12 Sep

HCLSoftware

India

Remote: Hybrid

Security ArchitectHCL Software | Office of the CISOLocation: India - Bangalore / Noida / RemoteAbout the RoleHCL Software is seeking a Security Architect to define how security is designed into our enterpriseand product platforms rather than inspected afterwards. This role sits in the Office of the CISO andcarries technical authority across cloud, identity, network, data, and AI systems.You will translate risk into architecture: reference designs, control patterns, and standards thatengineering teams can adopt without needing to reinvent security decisions each time.You will partner with enterprise IT, cloud engineering, product engineering, GRC, and securityoperations, and you will be measured on whether your designs actually get built.Key Responsibilities:Architecture and Standards• Define and maintain the target-state security architecture and the roadmap that gets us there,with clear sequencing and dependencies.• Publish reference architectures, control patterns, and secure design standards that engineeringteams can implement directly.• Set architectural guardrails for multi-cloud (AWS, Azure, GCP), SaaS, container, and hybridenvironments.• Evaluate security technologies against defined requirements, run proofs of concept, and makeevidence-based platform recommendations.Threat Modeling and Design Review• Lead threat modeling for major platforms, product architectures, and high-risk changes, using arepeatable methodology rather than ad hoc review.• Chair or contribute to architecture review, documenting risk acceptance decisions andcompensating controls where full remediation is not viable.• Translate findings into prioritized, costed remediation designs with accountable owners.• Build a design review process that scales through templates, self-service checklists,



andenablement rather than bottlenecking on one person.Identity, Zero Trust, and Data Protection• Own the identity-centric access architecture: authentication, authorization, privileged access,workload identity, and lifecycle governance.• Advance segmentation and zero-trust access patterns across corporate, production, anddevelopment environments.• Define encryption, key management, and data protection standards aligned to classificationand regulatory obligations.• Design for resilience: assume compromise, and architect blast-radius containment into everytier.AI and Emerging Technology Security• Define the security architecture for AI and agentic systems, covering model access, tool andconnector governance, data flow controls, and monitoring.• Address AI-specific threat classes including prompt injection, data poisoning, model andprompt exfiltration, and unsafe autonomous action.• Set architectural requirements for AI integrations built by product and internal engineeringteams.• Track emerging regulatory and customer expectations and fold them into design standardsbefore they become audit findings.Advisory and Influence• Advise engineering and executive stakeholders on security implications of architectural choicesin business terms.• Support customer-facing security assurance activity where architecture questions arise.• Mentor engineers and analysts on secure design thinking,



growing architectural capabilitybeyond this role.Required Qualifications• 10+ years in cybersecurity with 4+ years in a dedicated security architecture or senior designrole.• Proven ownership of enterprise security architecture across at least two of: cloud, identity,network, data protection, or application platforms.• Deep, current cloud security expertise in at least one major provider and working fluencyacross the others.• Strong identity and access management architecture experience, including federation,privileged access, and workload identity.• Demonstrated threat modeling capability using a recognized methodology (STRIDE, PASTA,attack trees, or equivalent) applied to real systems.• Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and SOC 2, with the ability tomap controls to architecture without becoming compliance-driven.• Ability to write explicit architecture documentation and defend design decisions in front of bothengineers and executives.Preferred Qualifications• Experience in a software or product company, including architecture for systems that ship tocustomers rather than only internal IT.• Hands-on background in engineering or development before moving into architecture.• Familiarity with AI and LLM security frameworks such as the OWASP LLM Top 10, MITREATLAS, and the NIST AI Risk Management Framework.• Experience with software supply chain security, SBOM practice, and build integrity controls.• Exposure to regulatory regimes affecting enterprise software, including the EU CyberResilience Act, and their architectural consequences.• Certifications valued but not required: CISSP, CCSP, SABSA, TOGAF, or major cloud securitycertifications.

📌 Security Architect (India)
🏢 HCLSoftware
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security architect (india) / india