14 Sep
|
HCLSoftware
|
Bengaluru
14 Sep
HCLSoftware
Bengaluru
Job Description
Security Architect
n
HCL Software | Office of the CISO
n
Location: India - Bangalore / Noida / Remote
n
About the Role
n
HCL Software is seeking a Security Architect to define how security is designed into our enterprise
n
and product platforms rather than inspected afterwards. This role sits in the Office of the CISO and
n
carries technical authority across cloud, identity, network, data, and AI systems.
n
You will translate risk into architecture: reference designs, control patterns, and standards that
n
engineering teams can adopt without needing to reinvent security decisions each time.
n
You will partner with enterprise IT, cloud engineering, product engineering, GRC, and security
n
operations, and you will be measured on whether your designs actually get built.
n
Key Responsibilities:
n
Architecture and Standards
n
• Define and maintain the target-state security architecture and the roadmap that gets us there,
n
with clear sequencing and dependencies.
n
• Publish reference architectures, control patterns, and secure design standards that engineering
n
teams can implement directly.
n
• Set architectural guardrails for multi-cloud (AWS, Azure, GCP), SaaS, container, and hybrid
n
environments.
n
• Evaluate security technologies against defined requirements, run proofs of concept, and make
n
evidence-based platform recommendations.
n
Threat Modeling and Design Review
n
• Lead threat modeling for major platforms, product architectures, and high-risk changes, using a
n
repeatable methodology rather than ad hoc review.
n
• Chair or contribute to architecture review, documenting risk acceptance decisions and
n
compensating controls where full remediation is not viable.
n
n
- Translate findings into prioritized, costed remediation designs with accountable owners.
n
- Build a design review process that scales through templates, self-service checklists,
and
n
n
enablement rather than bottlenecking on one person.
n
Identity, Zero Trust, and Data Protection
n
• Own the identity-centric access architecture: authentication, authorization, privileged access,
n
workload identity, and lifecycle governance.
n
• Advance segmentation and zero-trust access patterns across corporate, production, and
n
development environments.
n
• Define encryption, key management, and data protection standards aligned to classification
n
and regulatory obligations.
n
• Design for resilience: assume compromise, and architect blast-radius containment into every
n
tier.
n
AI and Emerging Technology Security
n
• Define the security architecture for AI and agentic systems, covering model access, tool and
n
connector governance, data flow controls, and monitoring.
n
• Address AI-specific threat classes including prompt injection, data poisoning, model and
n
prompt exfiltration, and unsafe autonomous action.
n
• Set architectural requirements for AI integrations built by product and internal engineering
n
teams.
n
• Track emerging regulatory and customer expectations and fold them into design standards
n
before they become audit findings.
n
Advisory and Influence
n
• Advise engineering and executive stakeholders on security implications of architectural choices
n
in business terms.
n
n
- Support customer-facing security assurance activity where architecture questions arise.
n
- Mentor engineers and analysts on secure design thinking,
growing architectural capability
n
n
beyond this role.
n
Required Qualifications
n
• 10+ years in cybersecurity with 4+ years in a dedicated security architecture or senior design
n
role.
n
• Proven ownership of enterprise security architecture across at least two of: cloud, identity,
n
network, data protection, or application platforms.
n
• Deep, current cloud security expertise in at least one major provider and working fluency
n
across the others.
n
• Solid identity and access management architecture experience, including federation,
n
privileged access, and workload identity.
n
• Demonstrated threat modeling capability using a recognized methodology (STRIDE, PASTA,
n
attack trees, or equivalent) applied to real systems.
n
• Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and SOC 2, with the ability to
n
map controls to architecture without becoming compliance-driven.
n
• Ability to write clear architecture documentation and defend design decisions in front of both
n
engineers and executives.
n
Preferred Qualifications
n
• Experience in a software or product company, including architecture for systems that ship to
n
customers rather than only internal IT.
n
n
- Hands-on background in engineering or development before moving into architecture.
n
- Familiarity with AI and LLM security frameworks such as the OWASP LLM Top 10, MITRE
n
n
ATLAS, and the NIST AI Risk Management Framework.
n
n
- Experience with software supply chain security, SBOM practice, and build integrity controls.
n
- Exposure to regulatory regimes affecting enterprise software, including the EU Cyber
n
n
Resilience Act, and their architectural consequences.
n
• Certifications valued but not required: CISSP, CCSP, SABSA, TOGAF, or major cloud security
n
certifications.
📌 Security Architect (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru