An Architect - Product Security is responsible for defining and enforcing secure coding standards, performing security reviews, and designing secure CI/CD pipelines. This role involves automating security testing, leading DevSecOps initiatives, and integrating security tools. The ideal candidate will have over 10 years of experience in application security, a strong understanding of web, mobile, API, and cloud architectures, and hands-on experience with various security tools and cloud platforms. They will ensure compliance with industry standards and collaborate with development teams to remediate vulnerabilities.
Good To Have:- Perspective of supporting developer tools (e.g., integrating security tools with IDE, PR checks)
- Ability to identify and summarize practical operational procedures
- Ability to write standards or SOPs
- Ability to provide security scan reports
- Good understanding of full stack software development
- Best practices for developing software (version control, branching, automation, IaC, documentation, testing)
- Ability to collaborate cross-functionally
- Ability to communicate effectively with highly technical teams
- Ability to provide written assessment reports as needed
- Certifications such as CSSLP, OSWE, or CEH
Must Have:- Define and enforce secure coding standards and best practices.
- Perform threat modeling, security architecture reviews, and code analysis.
- Design and implement secure CI/CD pipelines with integrated security controls.
- Automate security testing (SAST, DAST, IAST, SCA, container scanning) in SDLC process.
- Lead DevSecOps program in collaboration with DevOps, Operations and Engineering teams.
- Build automation focused on efficiency (e.g., increase triaging efficiency, manage false positives).
- Leverage ASPM and build workflows and reports.
- Evaluate and integrate security tools and platforms.
- Implement Infrastructure as Code (IaC) security and cloud-native security controls.
- Monitor and respond to security incidents in development and production environments.
- Collaborate with development teams to remediate vulnerabilities and design secure applications.
- Develop and deliver secure coding training and awareness programs.
- Stay current with emerging threats, vulnerabilities, and security technologies.
- Ensure compliance with industry standards (e.g., OWASP, NIST).
- Overall 10+ years of experience in application security, software development, or related roles.
- 6+ years of work experience in Application security, preferably in a fintech or financial services domain.
- Strong understanding of web, mobile, API and cloud application architectures.
- Experience of code reviewing or code contributing in Java, JavaScript, .Net, C#, Python, or IaC scripting.
- Hands-on experiences running SCA, SAST, DAST, IAST, SBOM, ASPM, Apigee, WAF.
- Deep understanding of DevSecOps practices and experience in CI/CD automation for Gitlab, GitHub or Azure DevOps.
- Knowledge of cloud platforms (AWS, Azure) and container orchestration (Kubernetes, Docker).
- Experience in building security controls for a system that follows NIST CSF and SSDF frameworks.
- Performing the risk-based security reviews that meet the OWASP, SOC2, GDPR requirements.