12 Sep
|
HCLSoftware
|
Bangalore Metropolitan Area
12 Sep
HCLSoftware
Bangalore Metropolitan Area
Security Architect
HCL Software | Office of the CISO
Location: India - Bangalore / Noida / Remote
About the Role
HCL Software is seeking a Security Architect to define how security is designed into our enterprise
and product platforms rather than inspected afterwards. This role sits in the Office of the CISO and
carries technical authority across cloud, identity, network, data, and AI systems.
You will translate risk into architecture: reference designs, control patterns, and standards that
engineering teams can adopt without needing to reinvent security decisions each time.
You will partner with enterprise IT, cloud engineering, product engineering, GRC, and security
operations, and you will be measured on whether your designs actually get built.
Key Responsibilities:
Architecture and Standards
• Define and maintain the target-state security architecture and the roadmap that gets us there,
with clear sequencing and dependencies.
• Publish reference architectures, control patterns, and secure design standards that engineering
teams can implement directly.
• Set architectural guardrails for multi-cloud (AWS, Azure, GCP), SaaS, container, and hybrid
environments.
• Evaluate security technologies against defined requirements, run proofs of concept, and make
evidence-based platform recommendations.
Threat Modeling and Design Review
• Lead threat modeling for major platforms, product architectures, and high-risk changes, using a
repeatable methodology rather than ad hoc review.
• Chair or contribute to architecture review, documenting risk acceptance decisions and
compensating controls where full remediation is not viable.
• Translate findings into prioritized, costed remediation designs with accountable owners.
• Build a design review process that scales through templates, self-service checklists, and
enablement rather than bottlenecking on one person.
Identity, Zero Trust, and Data Protection
• Own the identity-centric access architecture: authentication, authorization, privileged access,
workload identity, and lifecycle governance.
• Advance segmentation and zero-trust access patterns across corporate, production, and
development environments.
• Define encryption, key management, and data protection standards aligned to classification
and regulatory obligations.
• Design for resilience: assume compromise, and architect blast-radius containment into every
tier.
AI and Emerging Technology Security
• Define the security architecture for AI and agentic systems, covering model access, tool and
connector governance, data flow controls, and monitoring.
• Address AI-specific threat classes including prompt injection, data poisoning, model and
prompt exfiltration, and unsafe autonomous action.
• Set architectural requirements for AI integrations built by product and internal engineering
teams.
• Track emerging regulatory and customer expectations and fold them into design standards
before they become audit findings.
Advisory and Influence
• Advise engineering and executive stakeholders on security implications of architectural choices
in business terms.
• Support customer-facing security assurance activity where architecture questions arise.
• Mentor engineers and analysts on secure design thinking,
growing architectural capability
beyond this role.
Required Qualifications
• 10+ years in cybersecurity with 4+ years in a dedicated security architecture or senior design
role.
• Proven ownership of enterprise security architecture across at least two of: cloud, identity,
network, data protection, or application platforms.
• Deep, current cloud security expertise in at least one major provider and working fluency
across the others.
• Strong identity and access management architecture experience, including federation,
privileged access, and workload identity.
• Demonstrated threat modeling capability using a recognized methodology (STRIDE, PASTA,
attack trees, or equivalent) applied to real systems.
• Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and SOC 2, with the ability to
map controls to architecture without becoming compliance-driven.
• Ability to write explicit architecture documentation and defend design decisions in front of both
engineers and executives.
Preferred Qualifications
• Experience in a software or product company, including architecture for systems that ship to
customers rather than only internal IT.
• Hands-on background in engineering or development before moving into architecture.
• Familiarity with AI and LLM security frameworks such as the OWASP LLM Top 10, MITRE
ATLAS, and the NIST AI Risk Management Framework.
• Experience with software supply chain security, SBOM practice, and build integrity controls.
• Exposure to regulatory regimes affecting enterprise software, including the EU Cyber
Resilience Act, and their architectural consequences.
• Certifications valued but not required: CISSP, CCSP, SABSA, TOGAF, or major cloud security
certifications.
📌 Security Architect (Bangalore Metropolitan Area)
🏢 HCLSoftware
📍 Bangalore Metropolitan Area