- Location
- Chennai
- Type
- Full-time
- Department
- Engineering
- Experience
- 5+ years
- Closing date
- Today
- Source
- CareersPage
Description
Job Title: Product Security Architect (Threat Modeling)
Experience: 5–8 Years
Job Type: Contract
Notice Period: Immediate to 15 Days
Work Location: Remote
About the Role
We are seeking an experienced Product Security Architect (Threat Modeling) to join our Product Security Architecture team. In this role, you will partner with engineering and product teams throughout the Software Development Lifecycle (SDLC) to identify security risks early, perform threat modeling, conduct security architecture reviews, and provide practical security guidance.
You will play a key role in helping development teams design secure applications and cloud-native services by embedding security into the product development process. This position is ideal for a security professional who enjoys collaborating with cross-functional teams, solving complex technical challenges, and driving secure-by-design initiatives.
Key Responsibilities
- Conduct security design reviews and perform threat modeling exercises for new products, applications, services, and platform capabilities.
- Partner with software engineering and product teams to identify security risks and recommend practical mitigation strategies during the design and development lifecycle.
- Serve as a trusted security advisor by providing guidance on secure architecture, secure coding practices, and implementation patterns.
- Review application architectures, system designs, APIs, data flows, infrastructure, and deployment models to identify security vulnerabilities and recommend secure design improvements.
- Collaborate with engineering teams developing AI and Machine Learning solutions to assess emerging security risks and recommend secure implementation practices.
- Develop, maintain, and improve security standards, reference architectures, best practices, and technical documentation.
- Build or enhance security automation, tooling, and workflows to streamline threat modeling, architecture reviews, and security assessments.
- Perform application security assessments and assist in investigating security concerns identified during software development.
- Contribute to developer security enablement through documentation, workshops, office hours, and security awareness initiatives.
- Support security incident investigations and conduct root cause analysis for application security issues.
- Work closely with Product Security, Engineering, DevOps, Cloud, and Infrastructure teams to integrate security into the Software Development Lifecycle (SDLC).
Required Skills & Experience
- 5–8 years of experience in Application Security, Product Security, Security Architecture, or a related cybersecurity role.
- Strong understanding of Secure Software Development Lifecycle (SSDLC/SDLC).
- Hands-on experience conducting:
- Security Architecture Reviews
- Threat Modeling
- Application Security Assessments
- Risk Assessments
- Strong knowledge of:
- OWASP Top 10
- API Security
- Authentication & Authorization
- Cryptography
- Secrets Management
- Secure Design Principles
- Experience reviewing application architectures, cloud deployments, APIs, system integrations, and technical designs.
- Ability to assess security risks, prioritize findings, and provide practical, business-focused remediation recommendations.
- Experience reading and understanding source code in one or more modern programming languages.
- Experience developing scripts, tools, or automation to improve security engineering processes.
- Strong documentation and technical writing skills.
- Excellent communication and stakeholder management skills with the ability to explain complex security concepts to technical and non-technical audiences.
- Experience collaborating with software engineering, product, and infrastructure teams.
- Familiarity with modern cloud platforms, preferably AWS, and cloud-native application architectures.
Preferred Skills
- Experience with threat modeling methodologies such as:
- STRIDE
- PASTA
- Attack Trees
- MITRE ATT&CK (preferred)
- Familiarity with AI-assisted software development, AI-powered applications, and AI security considerations.
- Experience creating developer-facing security documentation, secure coding standards, and architectural guidance.
- Knowledge of security tools including:
- SAST
- DAST
- Software Composition Analysis (SCA)
- Infrastructure as Code (IaC) Scanning
- Vulnerability Management Platforms
- Exposure to DevSecOps practices and CI/CD security integration.
Technical Skills
- Product Security Architecture
- Threat Modeling (STRIDE, PASTA)
- Secure SDLC / SSDLC
- Application Security
- Security Architecture Review
- Risk Assessment
- Secure Design Principles
- OWASP Top 10
- API Security
- Authentication & Authorization
- Cryptography
- Secrets Management
- AWS Cloud Security
- Cloud-Native Security
- DevSecOps
- CI/CD Security
- SAST
- DAST
- SCA
- IaC Security
- Security Automation
- AI Security
- Source Code Review
- Security Documentation
Soft Skills
- Excellent communication and presentation skills
- Strong analytical and critical thinking abilities
- Problem-solving and risk assessment skills
- Cross-functional collaboration
- Technical mentoring and stakeholder engagement
- Strong documentation and technical writing skills
- Ability to influence engineering teams on secure design decision.