14 Sep
|
HCLSoftware
|
Bengaluru
14 Sep
HCLSoftware
Bengaluru
Security Architect
nHCL Software | Office of the CISO
nLocation: India - Bangalore / Noida / Remote
nAbout the Role
nHCL Software is seeking a Security Architect to define how security is designed into our enterprise
nand product platforms rather than inspected afterwards. This role sits in the Office of the CISO and
ncarries technical authority across cloud, identity, network, data, and AI systems.
nYou will translate risk into architecture: reference designs, control patterns, and standards that
nengineering teams can adopt without needing to reinvent security decisions each time.
nYou will partner with enterprise IT, cloud engineering, product engineering, GRC, and security
noperations, and you will be measured on whether your designs actually get built.
nKey Responsibilities:
nArchitecture and Standards
n• Define and maintain the target-state security architecture and the roadmap that gets us there,
nwith clear sequencing and dependencies.
n• Publish reference architectures, control patterns, and secure design standards that engineering
nteams can implement directly.
n• Set architectural guardrails for multi-cloud (AWS, Azure, GCP), SaaS, container, and hybrid
nenvironments.
n• Evaluate security technologies against defined requirements, run proofs of concept, and make
nevidence-based platform recommendations.
nThreat Modeling and Design Review
n• Lead threat modeling for major platforms, product architectures, and high-risk changes, using a
nrepeatable methodology rather than ad hoc review.
n• Chair or contribute to architecture review, documenting risk acceptance decisions and
ncompensating controls where full remediation is not viable.
n
n
- Translate findings into prioritized, costed remediation designs with accountable owners.
n
- Build a design review process that scales through templates, self-service checklists, and
n
nenablement rather than bottlenecking on one person.
nIdentity, Zero Trust, and Data Protection
n• Own the identity-centric access architecture: authentication, authorization, privileged access,
nworkload identity, and lifecycle governance.
n• Advance segmentation and zero-trust access patterns across corporate, production, and
ndevelopment environments.
n• Define encryption, key management, and data protection standards aligned to classification
nand regulatory obligations.
n• Design for resilience: assume compromise, and architect blast-radius containment into every
ntier.
nAI and Emerging Technology Security
n• Define the security architecture for AI and agentic systems, covering model access, tool and
nconnector governance, data flow controls, and monitoring.
n• Address AI-specific threat classes including prompt injection, data poisoning, model and
nprompt exfiltration, and unsafe autonomous action.
n• Set architectural requirements for AI integrations built by product and internal engineering
nteams.
n• Track emerging regulatory and customer expectations and fold them into design standards
nbefore they become audit findings.
nAdvisory and Influence
n• Advise engineering and executive stakeholders on security implications of architectural choices
nin business terms.
n
n
- Support customer-facing security assurance activity where architecture questions arise.
n
- Mentor engineers and analysts on secure design thinking,
growing architectural capability
n
nbeyond this role.
nRequired Qualifications
n• 10+ years in cybersecurity with 4+ years in a dedicated security architecture or senior design
nrole.
n• Proven ownership of enterprise security architecture across at least two of: cloud, identity,
nnetwork, data protection, or application platforms.
n• Deep, current cloud security expertise in at least one major provider and working fluency
nacross the others.
n• Strong identity and access management architecture experience, including federation,
nprivileged access, and workload identity.
n• Demonstrated threat modeling capability using a recognized methodology (STRIDE, PASTA,
nattack trees, or equivalent) applied to real systems.
n• Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and SOC 2, with the ability to
nmap controls to architecture without becoming compliance-driven.
n• Ability to write explicit architecture documentation and defend design decisions in front of both
nengineers and executives.
nPreferred Qualifications
n• Experience in a software or product company, including architecture for systems that ship to
ncustomers rather than only internal IT.
n
n
- Hands-on background in engineering or development before moving into architecture.
n
- Familiarity with AI and LLM security frameworks such as the OWASP LLM Top 10, MITRE
n
nATLAS, and the NIST AI Risk Management Framework.
n
n
- Experience with software supply chain security, SBOM practice, and build integrity controls.
n
- Exposure to regulatory regimes affecting enterprise software, including the EU Cyber
n
nResilience Act, and their architectural consequences.
n• Certifications valued but not required: CISSP, CCSP, SABSA, TOGAF, or major cloud security
ncertifications.
📌 Security Architect (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru