Principal Product Cybersecurity Architect

4 weeks ago


Bangalore Karnataka, Karnataka, India Johnson Controls International Full time

What you will do

The future is being built today, and Johnson Controls is making that future more productive, more secure and more sustainable. We are harnessing the power of cloud, data analytics, the Internet of Things, and user design thinking to deliver on the promise of intelligent buildings and smart cities that connect communities in ways that make people’s lives – and the world – better.

In this career defining opportunity within the Global Product Security organization, you will drive continuous improvement initiatives aligned to our cybersecurity maturity framework and roadmap, ensuring proactive management of security and data privacy risk across the full lifecycle of our products, platforms, and service offerings. You will apply your expertise in secure software development practices to ensure security and privacy by design requirements are fulfilled and that products are released to market with strong cybersecurity as a core feature. In this role, you will play a pivotal role in managing cybersecurity risk, differentiating Johnson Controls, and enabling business success.

How you will do it

  • Provide cybersecurity expertise and guidance to product development teams, security champions, and business leaders throughout all phases of the software development life cycle.
  • Drive policy compliance and high quality for secure SDLC activities -- security requirements, security architectures, threat and attack models, supply chain security, code reviews, SAST, DAST, IAST, penetration testing, and security hardening.
  • Architect security and privacy by design and secure-by-default into software applications for mobile, embedded systems, and cloud.
  • Periodically assess security policies, standards, and metrics to drive improvements that help Johnson Controls adapt to evolving regulatory, customer, and threat environments.
  • Drive efforts to quantify residual product risk and identify appropriate security controls.
  • Drive efforts to advance innovative security features, capabilities, and practices.
  • Review product architectures for security design gaps and vulnerabilities and consult with product teams to remediate or mitigate cyber risk.
  • Assist coordination of third party penetration testing vendor engagements with product teams.
  • Help engineers and product managers identify solutions to meet cybersecurity requirements.
  • Help business unit leaders understand security risks and participate in project resource planning.
  • Maintain current knowledge of security threats and vulnerabilities that could impact products.
  • Support incident response operations, training, and exercises, including exploitation analysis and countermeasure testing.
  • Assist coordination and tracking of vulnerability remediation activities.
  • Raise security awareness and drive security training and certification for people and products.
  • Support periodic reporting to senior executive leadership on health and status of the product security program, cybersecurity risks, risk mitigations, and trends.
  • Use agile project management to manage resources and track milestones and deliverables.
  • Support company response to customer audits and inquiries pertaining to product security.
  • Support internal audits and assessments to identify risks and determine mitigation actions.
  • Identify cybersecurity opportunities that enhance the developer and customer experience.
  • Support product security committees, boards, councils and working groups.
  • Support cybersecurity risk and technology assessments.
  • Speak at customer-facing events and present at conferences.

What we look for

  • Technical and operational excellence, thought leadership, and integrative thinking.
  • Expert knowledge and practical product and software security experience, including secure SDLC practices, security and privacy by design architectures, and secure by default configurations.
  • Strong problem-solving skills to analyze cybersecurity issues and requirements (legal/regulatory, policy, customer, industry standards) and relate them to appropriate security controls.
  • Experience supporting software security governance and compliance activities, i.e. metrics, assessments, audits, exercises, risk frameworks, and maturity models.
  • Demonstrated ability to lead change initiatives that intelligently manage software cyber risks.
  • Proven ability to deliver results using agile methodologies and tools (e.g. Scrum/Kanban, Jira).
  • Understanding of Product Security Incident Response Team (PSIRT) processes and activities.
  • Understanding of agile software development and continuous integration/deployment.
  • Practical experience with Linux OS, programming and scripting languages (e.g. Java, Python, Perl), and security tools (e.g. Kali, Nessus, Netsparker, openVAS, BurpSuite, Metaspolit).
  • Understanding of embedded systems architectures (e.g. ARM, Cortex), embedded systems tools/emulators, RTOS/Linux, network protocols and programming languages (such as C/C++).
  • Understanding of penetration testing, reverse engineering, software attack vectors, fault injection, device fingerprinting, and tamper resistance.
  • Understanding TPM, Secure Boot, OTP, PKI, SPI/I2C bus analyzers, JTAG probing.
  • Knowledge of current security threats and techniques for exploiting software vulnerabilities.
  • Understanding of web and mobile application secure design principles such as OWASP.
  • Understanding of data protection, secure cloud, and network infrastructure design principles.
  • Familiarity with technology risk management related frameworks such as RMF, NIST 800-53, ISA/IEC 62443, UL CAP, ISO 27001, GDPR, CSL, CSA, SOC 2 and other comparable.
  • Experience with Operational Technologies (e.g. Controls Systems, Building Management) a plus.
  • Superior interpersonal, organizational, written/verbal communication, and presentation skills.
  • Ability to build trust with stakeholders and explain complex security topics to all audiences.
  • Active participation in hackathons, cybersecurity competitions, and exercises are a plus.
  • CSSLP, CISSP, CCSP, OSCP, CEH or related cybersecurity certifications.
  • Bachelors degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related technical degree. Masters degree is preferred.
  • 6-8 years of experience in software or product cybersecurity.
  • Travel is occasional at approximately 10%, including international.



  • Bangalore, Karnataka, Karnataka, India Johnson Controls International Full time

    What you will doThe future is being built today, and Johnson Controls is making that future more productive, more secure and more sustainable. We are harnessing the power of cloud, data analytics, the Internet of Things, and user design thinking to deliver on the promise of intelligent buildings and smart cities that connect communities in ways that make...


  • Bangalore, Karnataka, Karnataka, India Johnson Controls International Full time

    What you will doThe future is being built today, and Johnson Controls is making that future more productive, more secure and more sustainable. We are harnessing the power of cloud, data analytics, the Internet of Things, and user design thinking to deliver on the promise of intelligent buildings and smart cities that connect communities in ways that make...


  • Bangalore, Karnataka, India GLAXOSMITHKLINE ASIA PVT. LTD Full time

    Job Description :Hello. We're Haleon. A new world-leading consumer health company. Shaped by all who join us. Together, we're improving everyday health for billions of people. By growing and innovating our global portfolio of category-leading brands - including Sensodyne, Panadol, Advil, Voltaren, Theraflu, Otrivin, and Centrum - through a unique...

  • Principal Architect

    2 months ago


    Bangalore, Karnataka, India Squareroot Consulting Pvt Ltd Full time

    Role : Principal Architect (Individual Contributor)Experience : 15 to 20 YrsLocation : BangaloreEducation : BE/BTech/ME/MTech/PhD (Computer Science, Information Systems, or related field)Looking for Principal Architect with Sweden based MNC for their notable large-scale digital disruption Platform. Should be strong at leadership mindset, solid at-Scale...

  • Principal Architect

    4 weeks ago


    Bangalore, Karnataka, India Squareroot Consulting Pvt Ltd Full time

    Role : Principal Architect (Individual Contributor)Experience : 15 to 20 YrsLocation : BangaloreEducation : BE/BTech/ME/MTech/PhD (Computer Science, Information Systems, or related field)Looking for Principal Architect with Sweden based MNC for their notable large-scale digital disruption Platform. Should be strong at leadership mindset, solid at-Scale...


  • Bangalore, Karnataka, India WRITE YOUR DESTINY CONSULTANCY SERVICES LLP Full time

    Position : Cyber Security ArchitectLocation : Bangalore and BelgaumJob Brief :This company is a pioneer in Hardware Software Interface Management Technologies. Embedded Software is rapidly growing in all industries including Automotive, Avionics, Data Centers, etc. At company, we develop software for Automotive, EDA, Semiconductors, and Networking while...


  • Bangalore, Karnataka, India Codersbrain India Private Limited Full time

    Responsibilities :- Lead and manage a team of software engineers in the development of the fully automated, AI enabled Endpoint management software.- Collaborate with cross-functional teams, enterprise architects and product managers, to define product requirements and deliver high-quality software solutions.- Design and architect scalable and robust...

  • Principal Architect

    4 weeks ago


    Bangalore, Karnataka, India Squareroot Consulting Pvt Ltd. Full time

    Job Description :Position : Principal ArchitectExperience : 10+ yearsEducation : B.E/B.Tech/MS/M.Tech (From IIT/BITS/IIIT/NIT or Any Premium institutes )Location : Bangalore, IndiaRoles and Responsibilities :- Drive innovation in full-stack product development, while relentlessly improving performance and scalability.- Responsible for end to end...

  • Principal Architect

    2 months ago


    Bangalore, Karnataka, India Squareroot Consulting Pvt Ltd. Full time

    Job Description :Position : Principal ArchitectExperience : 10+ yearsEducation : B.E/B.Tech/MS/M.Tech (From IIT/BITS/IIIT/NIT or Any Premium institutes )Location : Bangalore, IndiaRoles and Responsibilities :- Drive innovation in full-stack product development, while relentlessly improving performance and scalability.- Responsible for end to end...


  • Bangalore, Karnataka, India BLACK BOX NETWORK SERVICES INDIA PRIVATE LIMITED Full time

    Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe 'one size does NOT fit all', so we provide tailored solutions to address clients' specific needs. With multiple Security Operation Centers (SOC) and a...


  • Bangalore, Karnataka, India PureSearch Full time

    We are seeking a highly talented and experienced Principal Software Architect specializing in Embedded Systems to join the client's team. The ideal candidate will possess a wealth of expertise in Embedded Systems, Firmware, Linux, IoT, and Industrial Automation Protocols. This role demands exceptional skills in software architecture, design, C & C++...


  • Bangalore, Karnataka, India PureSearch Full time

    We are seeking a highly talented and experienced Principal Software Architect specializing in Embedded Systems to join the client's team. The ideal candidate will possess a wealth of expertise in Embedded Systems, Firmware, Linux, IoT, and Industrial Automation Protocols. This role demands exceptional skills in software architecture, design, C & C++...

  • Black Box

    4 weeks ago


    Bangalore, Karnataka, India BLACK BOX NETWORK SERVICES INDIA PRIVATE LIMITED Full time

    Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe 'one size does NOT fit all', so we provide tailored solutions to address clients' specific needs. With multiple Security Operation Centers (SOC) and a...

  • Principal Architect

    3 weeks ago


    Bangalore, Karnataka, India Ginger Partners Full time

    Job Description :Function : IT Operations and Support - Solution Architecture / Presales Architecture, TOGAF, ZachmanResponsibilities :- Driving the strategy, technology roadmaps, key architectural decisions, and operating model across technology domains at Kmart.- Ensuring that delivery teams are clear on the architectural vision, trade-offs, risk and...

  • IT Security Architect

    2 months ago


    Bangalore, Karnataka, India Info Origin Inc Full time

    About the Role :- We are seeking a highly experienced IT Security Architect to join our team and play a critical role in safeguarding our organization's IT infrastructure and data.- You will be responsible for designing, implementing, and maintaining robust security architectures that align with industry best practices and regulatory compliance...

  • IT Security Architect

    4 weeks ago


    Bangalore, Karnataka, India Info Origin Inc Full time

    About the Role :- We are seeking a highly experienced IT Security Architect to join our team and play a critical role in safeguarding our organization's IT infrastructure and data.- You will be responsible for designing, implementing, and maintaining robust security architectures that align with industry best practices and regulatory compliance...


  • Bangalore, Karnataka, India Overture Rede Private Limited. Full time

    About the Role : We are seeking a highly experienced and skilled .NET Principal Architect to join our growing team. In this role, you will play a critical role in designing, developing, and implementing complex microservices solutions using .NET Core. You will be responsible for leading the technical vision for our projects, ensuring scalability,...

  • Black Box

    2 months ago


    Bangalore, Karnataka, India BLACK BOX NETWORK SERVICES INDIA PRIVATE LIMITED Full time

    About the job :Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe 'one size does NOT fit all', so we provide tailored solutions to address clients' specific needs with multiple Security Operation...

  • Black Box

    4 weeks ago


    Bangalore, Karnataka, India BLACK BOX NETWORK SERVICES INDIA PRIVATE LIMITED Full time

    About the job :Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe 'one size does NOT fit all', so we provide tailored solutions to address clients' specific needs with multiple Security Operation...


  • Bangalore, Karnataka, India Squareroot Consulting Pvt Ltd Full time

    Position : Java Principal EngineerLocation : Bangalore (Work From Office)Job Type : Full-timeWe are looking for a talented and experienced Java Principal Engineer to join our team. The ideal candidate will have a strong background in software engineering and architecture, with deep expertise in Java development. As a Principal Engineer, you will be...