Define and drive the enterprise cybersecurity architecture, security strategy, and technical roadmap aligned with business objectives.
Design secure, scalable, and resilient architectures across applications, infrastructure, networks, cloud platforms, data, and endpoints.
Develop and implement security architecture standards, principles, patterns, reference architectures, and technical controls.
Conduct security architecture reviews and ensure security requirements are incorporated throughout the SDLC and technology lifecycle.
Design and implement security solutions covering IAM, PAM, Zero Trust, network security, application security, cloud security, data protection, and endpoint security.
Perform threat modeling, security risk assessments, vulnerability assessments, and security design reviews for new and existing systems.
Partner with Engineering, Architecture, DevOps, Cloud, Product, Infrastructure, and Compliance teams to integrate security into technology solutions.
Drive DevSecOps and Secure SDLC practices, including automated security testing and security controls within CI/CD pipelines.
Define security requirements for APIs, microservices, cloud-native applications, databases, and third-party integrations.
Evaluate and recommend cybersecurity technologies, platforms, tools, and vendors based on security requirements and business needs.
Establish security controls for AWS, Azure, GCP, Kubernetes, containers, and hybrid/multi-cloud environments.
Ensure alignment with security and compliance frameworks such as ISO 27001, NIST, CIS Controls, SOC 2, PCI DSS, and applicable regulatory requirements.
Collaborate with Security Operations teams on SIEM, SOC, incident response, threat detection, vulnerability management, and security monitoring.
Identify security gaps and technical risks and develop remediation strategies and long-term security improvements.
Provide technical leadership and guidance to Security Engineers, Architects, Developers, DevOps teams, and other technical stakeholders.
Strong understanding of threat modeling, risk assessment, vulnerability management, penetration testing, incident response, and security controls.
Working knowledge of SIEM, SOC, SOAR, IDS/IPS, WAF, firewalls, DLP, EDR, and security monitoring technologies.
Strong understanding of DevSecOps, Secure SDLC, application security, API security, and security automation.
Experience with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, SOC 2, PCI DSS, and GDPR.
Ability to conduct architecture reviews, security assessments, threat modeling, and risk analysis and translate findings into actionable technical solutions.
Strong experience collaborating with Engineering, Cloud, DevOps, Infrastructure, Product, Compliance, Risk, and senior leadership teams.
Excellent technical leadership, communication, stakeholder management, analytical, and problem-solving skills.
Ability to influence security decisions across teams and balance security, business requirements, performance, scalability, and cost.
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Electronics, or a related technical discipline.
B.E./B.Tech/MCA/M.Tech or equivalent qualification preferred.
Certifications such as CISSP, CCSP, CISM, OSCP, CEH, Security+, AWS Security Specialty, Azure Security Engineer, or Google Cloud Security are an added advantage.