02 Oct
|
Acesoft Labs
|
Hyderabad
02 Oct
Acesoft Labs
Hyderabad
Description: Information Security Architect
Location: Bangalore, India
Experience: Minimum 6 years in information/product security
.
Key Responsibilities
- Lead security architecture design across our product portfolio, spanning cloud-native and on-premise deployments.
- Conduct threat modeling using SD Elements, STRIDE, PASTA, or similar frameworks to identify and remediate design-level risks.
- Integrate security across DevSecOps processes, including CI/CD automation, SAST/DAST, container scanning, infrastructure-as-code security, and secrets management.
- Define and enforce security patterns, controls, and reference architectures across product teams.
- Perform secure design reviews, architecture risk assessments, and propose mitigation plans.
- Review designs, code, third-party libraries, and cloud configurations for compliance with secure architecture principles.
- Collaborate with product, engineering, QA, and DevOps to embed security early in development cycles.
- Provide subject matter expertise, guidance, and training on security best practices.
- Stay abreast of emerging threats, vulnerabilities, and tooling for product security.
- Partner with governance, risk, and compliance teams to support audits and ensure alignment with security standards like ISO 27001, NIST, and OWASP.
Must-Have Qualifications
- Minimum 6 years experience in information security architecture, product security, or related roles.
- Hands-on experience with product security, including vulnerability analysis, design reviews, and architecture hardening.
- Proven track record securing CI/CD pipelines , including tooling for SAST/DAST, container scanning, and secrets detection.
- Demonstrated experience with threat modeling (especially using SD Elements) and security frameworks (STRIDE, PASTA).
- CISSP certification is mandatory.
- Robust collaboration across cross-functional teams (Dev, Ops, QA).
- Excellent communication skills, with ability to translate technical risks to business stakeholders.
Nice-to-Have Skills
- Cloud security architecture ( AWS, Azure, GCP ).
- Familiarity with SD Elements security risk management platform.
- Experience with secure infrastructure-as-code (Terraform, CloudFormation).
- Exposure to agile DevSecOps practices and tooling integrations.
- Additional certifications: CCSP, CSA CCSK, CISM , etc.Enable Skills-Based Hiring No
Preferred candidate profile
Immediate joiners can send CV to
Follow/connect me on linkedln : https://www.linkedin.com/in/aman-b056091b1/
📌 Information Security Architect (Hyderabad)
🏢 Acesoft Labs
📍 Hyderabad