20 days ago
Hyderābād, IndiaStaff+
Responsibilities
- Define and drive adoption of secure design patterns, reference architectures, policies, standards, and secure coding practices for product and application development.
- Perform architecture and design reviews for web applications, APIs, microservices, distributed systems, and cloud-native applications.
- Integrate application security controls, including SAST, DAST, SCA, secret scanning, and IaC/PaC/SaC controls, into SDLC, CI/CD pipelines, and developer workflows.
- Partner with product and engineering teams to provide architectural guidance, risk insight, and design feedback throughout the Value Creation Process.
- Coordinate integration of security services into internally and externally facing solutions and manage remediation of product and application security gaps.
- Maintain awareness of product, application, and cloud architectures in relation to threats, regulatory requirements, compliance, and business risk.
- Contribute to security policies, standards, and guidelines; research leading practices; and recommend process and control improvements through automation and developer enablement.
- Communicate security project and issue status to security, technology, engineering, and executive leadership.
Requirements
- Bachelor’s degree in computer engineering, cybersecurity, or a related field; a master’s degree is preferred.
- Typically 12+ years of related experience, including at least 6 years in security, 3 years in a defensive application security role working directly with software engineering teams, and 3 years as a security architect.
- Experience designing and reviewing secure application and API architectures.
- Experience implementing application security tooling, including SAST, DAST, SCA, API security, and secrets management.
- Experience integrating security into CI/CD pipelines and developer workflows.
- Experience with cloud-native application architectures such as microservices and Kubernetes as they relate to application security.
- Experience presenting to and influencing engineering leadership and executives, and collaborating across globally distributed teams.
- Practical knowledge of NIST CSF, CIS Critical Security Controls v8, OWASP SAMM, OWASP ASVS, OWASP Top 10, and the MITRE ATT&CK framework.
- Knowledge of identity, authentication, authorization, secure API design, risk management, and balancing security with business outcomes.
- At least one application security or secure development certification, such as CSSLP, GWEB, or CASE.
- Cloud or Kubernetes security certification, such as CKS, CCSK, CCSP, or GCSA, is preferred.
- General security certification, such as CISSP or GIAC, and security architecture certification, such as SABSA SCF or ISSAP, are preferred.
Benefits
- 100% in-office work environment.
- Master’s degree and cloud, Kubernetes, general security, and security architecture certifications are preferred.
- TriNet is an equal opportunity employer and provides reasonable accommodations during the application process.