Architect - Product Security

5 days ago


Bengaluru Karnataka, India NeST Digital Full time

Minimum Required Experience : 10 years

Full Time

**Skills**:

- Cvss- Cyber Security- Security Architecture- Dast- Cryptography- Risk Analysis- Sast- Software Composition Analysis- White-Box Testing- Oauth 2.0- Vulnerability Assessments- Penetration Testing- Pki- Threat Modelling- Risk Mitigation- Owasp- FipsDescription

**Job Description - Product Security Architect**

**Experience Range & Quantity**

12+ YOE, 1 No

**Location Requirement**

Bangalore - Whitefield [Hybrid - at least 3 days a week]

**Fulfilment date**

ASAP

**Responsibilities**
- Provide privacy and security technical expertise supporting the product team throughout product development, design change, and life-cycle management.
- Work with the Product Security Leader (PSL) to support the product team with process expertise for Healthcare Product Cybersecurity Standards and life-cycle management.
- Product cybersecurity development responsibilities:

- Assess the privacy and cybersecurity state of the product and define product roadmap features/enhancements with stakeholder approval.
- Responsible for security architecture and coordination of product development for cybersecurity features and enhancements.
- Assess product components and SBoM are integrated into the product.
- Perform defect management for cybersecurity issues.
- Identify operational responsibilities and adherence to cloud standards for cloud-based products.
- Responsible for Product and Security Manual and MDS2 documentation.
- In coordination with the PSL, own and deliver Product Cybersecurity Standard artefacts, which include:

- Design input activities to identify, evaluate, roadmap, and drive cybersecurity and privacy features and enhancements within product development programs.
- Create Design Engineering Privacy and Security (DEPS) artefacts for privacy and security risk assessments to engage in domain-specific product threat modelling, attack surface analysis, risk management and reduction.
- Coordinates with the PSL to support the product team in scheduling and performing vulnerability scans and cybersecurity assessments.
- Lead product Security Technical Design Reviews
- Along with the product Lead System Designer (LSD), responsible for the Product Cybersecurity Standard compliance and other pertinent standards and processes.
- The released products shall comply with required regulatory standards & compliance (like FDA, HIPPA, GDPR etc.)
- Works with the Product Security team and Quality Assurance & Regulatory Assurance (QARA) on released product life cycle, including:

- Participate in post-market product vulnerability monitoring.
- Participate as a Subject Matter Expert to determine product vulnerability impact, investigation, and risk assessment.
- Responsible for product vulnerability mitigation and design change.
- Responsible for vulnerability tool updates to ensure accurate customer communication.
- Address customer and Sales RFP privacy and security feedback/questions.
- Provide technical expertise on customer concerns, complaints, and CSO escalations.
- Create/Maintain responsible product records within product cybersecurity tools.

**Mandatory Soft Skills**
- Should be able to contribute as an individual contributor
- Should be able to execute his/her responsibility independently
- Focus on self-planning activities

**Mandatory Skills**
- **Security Engineering**
- Globally recognized Cyber Security Certifications (Advanced/Expert Level).
- Firm with knowledge of OWASP, CVSS, FIPS 140-2/140-3 and DoD RMF
- The Architect shall be capable of not only finding risks/issues but shall also suggest the best route to remediation, knowing the compensatory controls & guiding the product team for its closure.
- Sound understanding of security technologies/techniques like
- Cryptography, Algorithms, Public key Infrastructure (PKI) Certificate Authority (CA),
- Hardware/embedded authentication, OAuth, 2-factor authentication, and
- white-box code analysis.
- Experience with a range of security tools related to
- SAST (Static Application Security Assessment),
- DAST (Dynamic Application Security Assessment),
- Vulnerability Management,
- SCA (Software Composition Analysis),
- Penetration Testing
- Threat Modelling Tools etc.
- **Product Engineering**
- Experience in working in a Product sector environment
- Knowledge of Cloud Infrastructure [Platform as a Service]

**Nice-to-have Skills**
- **Medical Software/Device Engineering**
- MDS2 documentation
- Experience in the Healthcare domain.
- **Standard Software Engineering**
- Experience in Micro Services using RESTful frameworks
- **Security Engineering**
- Penetration Testing in Web Applications, Thick Clients, Mobile Applications, REST/SOAP
- Infrastructure Penetration Testing
- Experience in Red Teaming Activities (add-on)
- Recognition for CVE or Wall-of-Fame through Bug-Bounty (add-on)


  • Security Architect

    2 weeks ago


    Bengaluru, Karnataka, India Sanumas Solutions Full time

    Client: ITES/BPO **Location**: Bangalore **Experience**: 8+ Years Title: Security Architect **Salary**: 25 LPA - 30 LPA Position Summary: We are seeking a talented Security Architect specializing in cloud technologies to join our dynamic team. The Security Architect will be responsible for designing, implementing, and maintaining robust security solutions...


  • Bengaluru, Karnataka, India Bottomline Full time

    **Why Choose Bottomline?**: Are you ready to transform the way businesses pay and get paid? Bottomline is a global leader in business payments and cash management, with over 30 years of experience and moving more than $10 trillion in payments annually. We're looking for passionate individuals to join our team and help drive impactful results for our...

  • Architect Security

    2 weeks ago


    Karnataka, India Empower Full time

    Our vision for the future is based on the idea that transforming financial lives starts by giving our people the freedom to transform their own. We have a flexible work environment, and fluid career paths. We not only encourage but celebrate internal mobility. We also recognize the importance of purpose, well-being, and work-life balance. Within Empower and...


  • Bengaluru, Karnataka, India Netskope Full time

    **About Netskope**: Today, there's more data and users outside the enterprise than inside, causing the network perimeter as we know it to dissolve. We realized a new perimeter was needed, one that is built in the cloud and follows and protects data wherever it goes, so we started Netskope to redefine Cloud, Network and Data Security. **About the...

  • Security Architect

    2 weeks ago


    Bengaluru, Karnataka, India Ethos Life Full time

    **About Ethos** Ethos was built to make it faster and easier to get life insurance for the next million families. Our approach blends industry expertise, technology, and the human touch to find you the right policy to protect your loved ones. We leverage deep technology and data science to streamline the life insurance process, making it more accessible...

  • Security Architect

    2 weeks ago


    Bengaluru, Karnataka, India Sanumas Solutions Full time

    **Security Architect - Cloud Networks** **Experience: 8+ Years** **Work Locatio**n: Bangalore **Salary**: 25 LPA 9 30LPA - We are seeking a talented **Security Architect with 8+ Years pf experience specializing in cloud technologies** to join our dynamic team. - The Security Architect will be **responsible for designing, implementing, and maintaining...

  • Security Architect

    10 hours ago


    Bengaluru, Karnataka, India ANZ Banking Group Full time

    **Req ID**: 92663 **Department**: Tech Security Advisory & Engineering **Division**: Technology **Location**: Bengaluru About Us About the Role As a Security Partner in Security Domain, you’ll play a key role in making ANZ a safe and more secure place by ensuring our corporate and customer information is secured. The Security Domain has group-wide...

  • Security Architect

    2 weeks ago


    Bengaluru, Karnataka, India Sanumas Solutions Full time

    Client: ITES/BPO **Location**: Bangalore **Experience**: 8+ Years Title: Security Architect - Cloud **Salary**: 25 LPA - 30 LPA Position Summary: We are seeking a talented Security Architect specializing in cloud technologies to join our dynamic team. The Security Architect will be responsible for designing, implementing, and maintaining robust security...


  • Bengaluru, Karnataka, India Fluence Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Fluence (Nasdaq: FLNC) is a global market leader delivering intelligent energy storage and optimization software for renewables and storage. Our solutions and operational services are helping to create a more resilient grid and unlock the full potential of renewable portfolios. With gigawatts of successful implementations across nearly 50 markets, we are...

  • Security Architect

    10 hours ago


    Bengaluru, Karnataka, India Capgemini Full time

    Security Architects design, build and oversee the implementation of security structures. They provision secure IT systems; design, operate and maintain the integrity and effectiveness; protect and defend from risks and threats; investigate events/crimes and illegal actions/evidence; collect and operate the latest updates to proactively evolve our methods and...