Source description
About the role
Product Cybersecurity Engineer / Security Architect Pune, India | Hybrid | Full-Time | 7+ Years Build Secure Products. Not Security Reports. At L4B, we build Android and Linux-based platforms used in medical, automotive, industrial, and future-generation embedded systems. We're looking for a cybersecurity engineer who thinks like a system designer, not just a vulnerability scanner. This role exists to make sure our products are secure before they reach customers, not after. You will work across architecture, platform engineering, product teams, cybersecurity, compliance, and release engineering to ensure security is designed into the product from the beginning. If your first instinct after finding a vulnerability is to ask: How should this system have been designed differently rather than Which scanner found it Why This Role Exists Security at L4B is becoming a product capability, not a compliance exercise. We need an engineer who can own: • Security architecture • Threat modelling • Secure-by-design reviews • Product security requirements • Risk analysis • Security controls • Secure development practices This role complements offensive security, build/release security, and platform engineering. Your job is to ensure security decisions are made before products ship. What You'll Own Security Architecture • Drive architecture-level security reviews • Define security requirements for Android, Linux, embedded, cloud-connected and IoT products • Review product designs before implementation • Identify trust boundaries and attack surfaces • Recommend appropriate security controls Threat Modelling Own and facilitate: • STRIDE analysis • Attack trees • Abuse cases • Data-flow analysis • Trust-boundary reviews • Risk assessments Translate threats into engineering tasks and requirements. Product Security Engineering Establish and maintain: • Secure SDLC processes • Security checkpoints • Security acceptance criteria • Security review workflows • Product security baselines Ensure security becomes part of engineering, not a separate activity. Embedded & Platform Security Work with Android, Linux and firmware teams on: • Secure Boot • Android Verified Boot (AVB) • SELinux • OTA security • Secure update mechanisms • Trusted Execution Environments (TEE) • Secure Element integration • Hardware root of trust Vulnerability & Risk Management Work closely with Product Security and DevSecOps teams to: • Assess vulnerability impact • Review CVE applicability • Drive risk remediation • Support security decision-making • Approve compensating controls where required Regulatory & Product Compliance Support Support product security requirements relating to: • IEC 62304 • ISO 14971 • IEC 81001-5-1 • FDA Cybersecurity Guidance • EU MDR You do not need to be an auditor. You do need to understand how security decisions influence product architecture, risk management and compliance. What We're Looking For Required • 7+ years in Product Security, Embedded Security, Security Engineering, Security Architecture or related fields • Hands-on threat modelling experience • Security architecture ownership experience • Secure product development experience • Strong communication and documentation skills • Ability to translate security risks into engineering requirements Must have experience with at least one of: • Embedded Linux • Android Platform • Medical Devices • Automotive Systems • Industrial IoT • Connected Products Strong Plus • STRIDE • Attack Trees • Threat Modelling Frameworks • Secure Boot • AVB • SELinux • TrustZone / TEE • Secure Elements • Product Risk Management • Medical Device Cybersecurity • Security Review Boards Not A Fit For This role is generally not suitable for: • SOC Analysts • Security Operations Engineers • Vulnerability Assessment Only Profiles • Compliance Auditors • Governance/Risk/Compliance Specialists without engineering experience • Penetration Testers without architecture responsibility • Cloud Security Engineers with no product-security background These are valuable disciplines, but this role is focused on secure product engineering and architecture. Success After 12 Months You have successfully: • Established threat modelling practices across products • Defined and maintained product security requirements • Embedded security reviews into engineering workflows • Reduced architecture-level security risks • Enabled secure-by-design decision making • Strengthened Android and Linux platform security posture • Built a repeatable product-security framework for future products Work Model This is a Hybrid role based in Pune. While day-to-day collaboration may be a mix of remote and office-based work, periodic in-person collaboration with architects, platform engineers, compliance teams, and product stakeholders is expected. Why Join L4B You will work directly with: • Security Engineers • Platform Architects • Embedded Linux Engineers • Android Engineers • DevSecOps Engineers • Quality & Compliance Teams to influence how products are designed, built, validated, released, and maintained. This is a hands-on security engineering role with real impact on product architecture, cybersecurity strategy, and long-term platform direction.