Associate Architect - Product Security

1 Month ago • 10 Years + • Product

Job Summary

Job Description

We are seeking an Associate Architect for Product Security to define and enforce secure coding standards and best practices. Responsibilities include threat modeling, security architecture reviews, code analysis, and designing/implementing secure CI/CD pipelines with integrated security controls. The role involves automating security testing (SAST, DAST, IAST, SCA, container scanning) within the SDLC, evaluating and integrating security tools, and leading DevSecOps programs. Additionally, you will build automation for efficiency, leverage ASPM, implement Infrastructure as Code (IaC) security and cloud-native security controls, monitor and respond to security incidents, and collaborate with development teams for vulnerability remediation. Training and awareness programs will be developed, and you will stay current with emerging threats and security technologies, ensuring compliance with industry standards like OWASP and NIST.
Must have:
  • 10+ years of experience in application security
  • 6+ years in Application security, preferably in fintech
  • Strong understanding of web, mobile, API, cloud architectures
  • Experience with code reviewing in Java, JavaScript, .Net, C#, Python, or IaC
  • Hands-on experience with SCA, SAST, DAST, IAST, SBOM, ASPM, Apigee, WAF
  • Deep understanding of DevSecOps practices and CI/CD automation
  • Knowledge of cloud platforms (AWS, Azure) and Kubernetes, Docker
  • Experience building security controls for NIST CSF and SSDF frameworks
  • Ability to identify and summarize operational procedures and write SOPs
  • Good understanding of full stack software development best practices
  • Ability to collaborate cross-functionally and communicate effectively
  • Certifications such as CSSLP, OSWE, or CEH
Good to have:
  • Experience supporting developer tools as a security professional (IDE integration, PR checks)
  • Performing risk-based security reviews meeting OWASP, SOC2, GDPR requirements
  • Providing security scan reports

Job Details

Description

  • Responsibilities

    • Define and enforce secure coding standards and best practices.
    • Perform threat modeling, security architecture reviews, and code analysis. 
    • Design and implement secure CI/CD pipelines with integrated security controls. 
    • Automate security testing (SAST, DAST, IAST, SCA, container scanning) in SDLC process. 
    • Evaluate and integrate security tools and platforms  
    • Lead DevSecOps program in collaboration with DevOps, Operations and Engineering teams 
    • Build automation focused on efficiency (E.g. increase triaging efficiency, manage false positives etc.) 
    • Leverage ASPM and build workflows and reports  
    • Evaluate and integrate security tools and platforms 
    • Implement Infrastructure as Code (IaC) security and cloud-native security controls. 
    • Monitor and respond to security incidents in development and production environments. 
    • Collaborate with development teams to remediate vulnerabilities and design secure applications. 
    • Develop and deliver secure coding training and awareness programs. 
    • Stay current with emerging threats, vulnerabilities, and security technologies. 
    • Ensure compliance with industry standards (e.g., OWASP, NIST etc).   
Requirements 
    • Overall 10+ years of experience in application security, software development, or related roles. 
    • 6+ years of work experience in Application security, preferably in a fintech or financial services domain  
    • Strong understanding of web, mobile, API and cloud application architectures. 
    • Experience of code reviewing or code contributing in Java, Java Script, .Net. C#, Python, or IaC scripting. 
    • Hands-on experiences running SCA, SAST, DAST, IAST, SBOM, ASPM, Apigee, WAF etc., with approaches or optimizations for the tools to efficiently enforce the enterprise S-SDLC policies. 
    • Deep understanding of DevSecOps practices and experience in CI/CD automation for  one of the popular platforms, such as Gitlab, GitHub or Azure DevOps. 
    • Knowledge of cloud platforms (AWS, Azure) and container orchestration (Kubernetes, Docker). 
    • Perspective of supporting developer tools as a security professional (E.g. integrating security tools with IDE, PR checks etc.) 
    • The experiences in building security controls for a system that follows NIST CSF and SSDF frameworks and  performing the risk-based security reviews that meet the OWASP, SOC2, GDPR requirements.  
    • Ability to identify and summarize practical operational procedures, write standards or SOPs, and provide security scan reports. 
    • A good understanding of full stack software development and best practices for developing software (version control, branching, automation, IaC, documentation, testing, etc.)  
    • Ability to collaborate cross-functionally and communicate effectively with highly technical teams and provide written assessment reports as needed. 
    • Certifications such as CSSLP, OSWE, or CEH. 
     

Similar Jobs

Patreon - Staff Full Stack Engineer, Payments

Patreon

San Francisco, California, United States (Hybrid)
4 Weeks ago
cyara - Sales Operations Analyst – Data

cyara

Hyderabad, Telangana, India (Hybrid)
7 Months ago
Saviynt - IAM Technical Architect, Professional Services

Saviynt

Atlanta, Georgia, United States (Remote)
1 Year ago
Tesla - Store Supervisor

Tesla

Moravian-Silesian Region, Czechia (On-Site)
5 Months ago
Mcdonalds - Learning & Development Delivery Manager

Mcdonalds

Mexico City, Mexico (On-Site)
4 Days ago
Morning Star - Product Specialist

Morning Star

Mumbai, Maharashtra, India (Hybrid)
1 Month ago
Relax Gaming - Game Product Owner

Relax Gaming

Malmö, Skåne County, Sweden (Hybrid)
3 Months ago
Inwave - Product Owner

Inwave

(On-Site)
5 Months ago
Miro - Principal Account Executive - New Product Specialist

Miro

London, England, United Kingdom (On-Site)
1 Week ago
Tesla - Cell New Product Introduction (NPI) Technician

Tesla

Brandenburg, Germany (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

WebTech Corporation - Technical Product Manager

WebTech Corporation

Pilsen, Plzeň Region, Czechia (On-Site)
3 Days ago
Qualcomm - Staff Software Engineer, Game Developer Technologies

Qualcomm

Tokyo, Japan (On-Site)
2 Months ago
Sony Pictures Entertainment - Systems & Data Analytics Intern, US TV Production – Fall 2025

Sony Pictures Entertainment

Culver City, California, United States (On-Site)
1 Day ago
Gigamon - Sales Engineer

Gigamon

Orange, California, United States (On-Site)
5 Months ago
Sabre India - Software Engineer IV

Sabre India

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Scanline VFX - Project Manager

Scanline VFX

Los Angeles, California, United States (Hybrid)
4 Months ago
Nintendo - Associate Digital Operations Specialist - Publisher and Developer Relations

Nintendo

Redmond, Washington, United States (Hybrid)
4 Months ago
SSC Technologies - Client Support Representative

SSC Technologies

Jacksonville, Florida, United States (Hybrid)
5 Days ago
NXP - Assembly Back End Process Engineering Sr Manager

NXP

Bangkok, Thailand (On-Site)
1 Month ago
Scopely - VP, GM - Direct to Consumer

Scopely

Culver City, California, United States (Hybrid)
8 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Thiruvananthapuram, Kerala, India

Zelis  - Quality Assurance Engineer

Zelis

Hyderabad, Telangana, India (On-Site)
1 Year ago
luxsoft - Business Analyst with Custody and Settlements

luxsoft

Pune, Maharashtra, India (On-Site)
4 Weeks ago
Accurate - Candidate Screening Coordinator

Accurate

Thane, Maharashtra, India (On-Site)
2 Weeks ago
Trek - Senior Software Engineer

Trek

Haryana, India (Hybrid)
5 Days ago
Capgemini - Netapp Storage Administration

Capgemini

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Insignia consultancy services - Adobe Illustrator Lead

Insignia consultancy services

India (Remote)
1 Year ago
Dentsu - Paid Social - Senior Analyst

Dentsu

Chennai, Tamil Nadu, India (On-Site)
1 Month ago
Capgemini - Automation Engineer

Capgemini

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Trek - Product Support Analyst (ERP)

Trek

Haryana, India (On-Site)
5 Months ago
Capgemini - Manual Tester

Capgemini

Mumbai, Maharashtra, India (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Product Jobs

Ansys - Product Sales Executive - Digital Engineering Systems

Ansys

Canonsburg, Pennsylvania, United States (On-Site)
2 Months ago
entrata - Product Owner

entrata

Pune, Maharashtra, India (Hybrid)
9 Months ago
Amanotes - Game Product Owner (New Games - Hybrid Casual Game)

Amanotes

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
6 Months ago
CyberArk - Product Owner – Secure AI Agent Access Platform

CyberArk

Israel (Hybrid)
2 Months ago
Polygon Labs - Product Marketing Lead

Polygon Labs

United States (Remote)
3 Months ago
Mercury - Associate General Counsel, Product and Privacy

Mercury

San Francisco, California, United States (On-Site)
2 Months ago
Capgemini - PRODUCT DATA ORCHESTRATION

Capgemini

Kolkata, West Bengal, India (On-Site)
2 Months ago
reversing labs  - Vice President, Product Marketing

reversing labs

United States (Remote)
1 Month ago
Sprinkler - Senior Product Education Facilitator

Sprinkler

Texas, United States (Remote)
1 Year ago
Alpha Sense - Product Specialist, Corporate

Alpha Sense

United States (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Thiruvananthapuram, Kerala, India (On-Site)

Raleigh, North Carolina, United States (Hybrid)

Berwyn, Pennsylvania, United States (Hybrid)

Berwyn, Pennsylvania, United States (Hybrid)

Berwyn, Pennsylvania, United States (Remote)

Thiruvananthapuram, Kerala, India (On-Site)

Thiruvananthapuram, Kerala, India (On-Site)

Denver, Colorado, United States (On-Site)

Boston, Massachusetts, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Yodlee

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug