We are seeking an Associate Architect for Product Security to define and enforce secure coding standards and best practices. Responsibilities include threat modeling, security architecture reviews, code analysis, and designing/implementing secure CI/CD pipelines with integrated security controls. The role involves automating security testing (SAST, DAST, IAST, SCA, container scanning) within the SDLC, evaluating and integrating security tools, and leading DevSecOps programs. Additionally, you will build automation for efficiency, leverage ASPM, implement Infrastructure as Code (IaC) security and cloud-native security controls, monitor and respond to security incidents, and collaborate with development teams for vulnerability remediation. Training and awareness programs will be developed, and you will stay current with emerging threats and security technologies, ensuring compliance with industry standards like OWASP and NIST.
Good To Have:- Experience supporting developer tools as a security professional (IDE integration, PR checks)
- Performing risk-based security reviews meeting OWASP, SOC2, GDPR requirements
- Providing security scan reports
Must Have:- 10+ years of experience in application security
- 6+ years in Application security, preferably in fintech
- Strong understanding of web, mobile, API, cloud architectures
- Experience with code reviewing in Java, JavaScript, .Net, C#, Python, or IaC
- Hands-on experience with SCA, SAST, DAST, IAST, SBOM, ASPM, Apigee, WAF
- Deep understanding of DevSecOps practices and CI/CD automation
- Knowledge of cloud platforms (AWS, Azure) and Kubernetes, Docker
- Experience building security controls for NIST CSF and SSDF frameworks
- Ability to identify and summarize operational procedures and write SOPs
- Good understanding of full stack software development best practices
- Ability to collaborate cross-functionally and communicate effectively
- Certifications such as CSSLP, OSWE, or CEH