Principal Security Architect

2 weeks ago


Hyderabad, Telangana, India Kshema General Insurance Limited Full time
POSITION OVERVIEW

Kshema General Insurance is seeking a Principal Security Architect to join our security organization. This role reports to the Chief Technology Officer and will play a critical role in shaping and executing Kshema's cloud security strategy across a diverse and evolving technology landscape.

The role will work closely with development teams, product teams, and others across the organization to integrate security into the delivery lifecycle from design through deployment. This person will play a key role in defining security requirements, performing application security assessments, and providing developers with remediation advice.

DUTIES & RESPONSIBILITIES

- Work independently with developers, system/network engineers, product owners, and other colleagues to ensure secure design, development, and implementation of applications, infrastructure, and networks.
- Participate in engineering projects to identify threats and vulnerabilities in our cloud infrastructure and system architectures.
- Define cybersecurity requirements and security concepts and work with engineering teams to successfully deliver business solutions.
- Perform security design reviews of cloud systems, and networks.
- Provide remediation guidance and recommendations to systems administrators.
- Develop enterprise standards based on security best practices.
- Demonstrate deep expertise in Azure and either AWS or Google Cloud Platform (GCP), including native security services.
- Design secure cloud-native and hybrid architectures, including zero trust, micro-segmentation, and secure access patterns.
- Design secure VPCs, firewalls, VPNs, and secure connectivity between on-prem and cloud.
- Protect data utilizing Encryption (at rest, in transit, and in use), key management (KMS, HSM), tokenization, and data classification.
- Integrate security into CI/CD pipelines, infrastructure as code (IaC) scanning, and container security (e.g., Kubernetes, Docker).
- Conduct threat modeling, risk assessments, and security reviews for cloud workloads.
- Define and drive cloud security strategy aligned with business and IT goals.
- Create architecture diagrams, security design documents, and architecture decision records.
- Closely work with CISO in evaluating technology initiatives and projects to determine advanced cybersecurity requirements and controls necessary to comply with company policies, standards, and industry best practices.
- Demonstrate best practices, create proofs-of-concept and propose solutions to Customer's Software and Infrastructure Architects and provide strategic technical direction across the development and infrastructure teams.
- Build and sustain good working relationships with development and infrastructure teams and involve them in the overall application and cloud Security Technology strategy.
- Develop security related user stories and product specific threat models for products, as well as CI/CD pipelines and infrastructure-as-code.
- Develop technical security requirements for the business and see them through the development lifecycle.
- Collaborate with business contacts to ensure third-party cloud applications comply with our standards, controls, policies, and principles.

MINIMUM REQUIREMENTS

- Bachelor's degree in computer science or business with emphasis in IT or the equivalent combination of education, training and work experience.
- Requires 10+ years of experience in cybersecurity, with at least 4 years focused on cloud security architecture.
- Proven experience designing and securing solutions in Azure (preferred), and/or AWS
- Deep understanding of cloud-native services, container security (e.g., Kubernetes), and serverless architectures.
- Strong knowledge of DevSecOps practices and secure software development lifecycle (SSDLC).
- Familiarity with compliance frameworks such as NIST, ISO 27001, SOC 2, HIPAA, and PCI-DSS.
- Advanced knowledge of IAM principles, federation, SSO, RBAC/ABAC, and privileged access management.
- Relevant certifications such as AWS Certified Security – Specialty, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, or CCSP.
- Hands-on practical experience high quality threat models and knowledge of MITRE framework, STRIDE framework and kill chains.
- Deep understanding of network protocols, operating systems, databases, applied cryptography, least privilege, zero trust principles, identity & access management, and other core information security concepts.
- Hands-on experience in performing threat modeling for applications, identifying threats, and suggesting optimal mitigation strategies.
- Strong understanding of threat modeling methodologies (e.g., STRIDE, DREAD, PASTA).
- Proficiency in using threat modeling tools (e.g., Microsoft Threat Modeling Tool, Threat Modeler, OWASP Threat Dragon).
- In-depth knowledge of common security vulnerabilities (e.g., OWASP Top Ten, CVEs) and attack vectors.

-

PREFERRED EXPERIENCE

- Experience in regulated industries (e.g., financial services, insurance, healthcare).
- Strong communication and leadership skills, with the ability to influence technical and non-technical stakeholders.
- Experience leading security architecture programs or initiatives at the enterprise level.
- Experience with Container security platforms.
- Experience incorporating security policy into Infrastructure as Code.
  • Principal Architect

    3 weeks ago


    Hyderabad, Telangana, India Innovistors -Client Full time

    Job Title: Principal DBADomain: Enterprise Database Architecture, Cloud Infrastructure, Performance & Cost Optimization,and AutomationReports to: Vice President, TechOpsLocation: HyderabadJOB ROLE OVERVIEWThe Principal Database Administrator is responsible for the architecture, implementation, andoptimization of database environments across cloud and on...

  • Principal IS Architect

    17 hours ago


    Hyderabad, Telangana, India Amgen Inc Full time

    Job Description- Amgen's Clinical Computation Platform Product Team manages a core set of clinical computation solutions that support global clinical development. This team is responsible for building and maintaining systems for clinical data storage, data auditing and security management, analysis and reporting capabilities. These capabilities are pivotal...


  • Hyderabad, Telangana, India Prudent Technologies and Consulting, Inc. Full time

    Job Description:Prudent Technologies and Consulting is seeking an experienced Principal Application Security Engineer to lead our rapidly expanding web application penetration testing services. This senior-level position will play a critical role in advancing our offensive security capabilities, mentoring junior security consultants, and delivering...


  • Hyderabad, Telangana, India Prudent Technologies and Consulting, Inc. Full time

    Job Description:Prudent Technologies and Consulting is seeking an experienced Principal Application Security Engineer to lead our rapidly expanding web application penetration testing services. This senior-level position will play a critical role in advancing our offensive security capabilities, mentoring junior security consultants, and delivering...

  • Security Architect

    2 weeks ago


    Hyderabad, Telangana, India Hire Alpha Full time

    Role : Security Architect. Project Role Description : - Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. - Document the implementation of the cloud security controls and transition to cloud security-managed operations.. Must have skills : SailPoint IdentityIQ. Good to have skills :...


  • Hyderabad, Telangana, India Cubic Corporation Full time

    Job DescriptionBusiness Unit:Cubic Transportation SystemsCompany Details:When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make peoples lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led...


  • Hyderabad, Telangana, India ValueMomentum Full time

    Job Description: Cloud Security ArchitectJob Title: Cloud Security ArchitectLocation: HyderabadRole SummaryThe Cloud Security Architect will be responsible for designing, architecting, deploying, delivering, and maintaining enterprise-grade cloud security solutions across Azure, AWS, and Google Cloud environments. The role ensures alignment with...


  • Hyderabad, Telangana, India Tata Consultancy Services Full time

    Greetings from TCS Role: Enterprise Security Architect Experience: 15+ years Job Description: experience in Security Architect & Engineering Professional with architecture, design and engineering experience for enterprise security technologies (System & Network Security, Identity & Access Management, Data Security, Cloud Security, Application Security, SIEM...


  • Hyderabad, Telangana, India beBeeEnterprise Full time ₹ 1,63,07,840 - ₹ 2,03,76,400

    Immerse yourself in a transformative opportunity as we seek an accomplished SAP BTP Architect to spearhead innovative projects.Job DescriptionWe are looking for a highly skilled and experienced SAP BTP Architect to collaborate on delivering business-driven solutions. The ideal candidate will have a strong background in implementing solutions on SAP BTP, with...


  • Hyderabad, Telangana, India Diebold Nixdorf Full time US$ 1,20,000 - US$ 2,00,000 per year

    Expect more. Connect more. Be more at Diebold Nixdorf.  Our teams automate, digitize, and transform the way more than 75 million people around the globe bank and shop in this hyper-connected, consumer-centric world. Join us in connecting people to commerce in this vital, rewarding role.Position Overview:As the Applications Principal Architect, you will...