Padmi

AVP - Security Architect

MumbaiPosted 13 months ago
CybersecurityStaff+
Apply at Protean eGov Technologies

Opens the source posting on naukri.com

Source description

About the role

View original

Years of Experience :- +15 Years Job Location: Pune Job Overview: 15+ years of experience in designing tailored security architectures that address client needs, present technical solutions to stakeholders Responsibilities: 1. Security Architecture & Design: Design and architect robust, scalable, and resilient security solutions across on-premises and cloud infrastructures. Develop security architecture frameworks and policies that ensure compliance with regulatory requirements (e.g., GDPR, ISO 27001, HIPAA). Identify security vulnerabilities and design proactive measures to mitigate risks in systems, applications, and networks. Collaborate with software development, IT operations, and network teams to integrate security best practices into the overall architecture. Lead security assessments and design reviews for new and existing systems to ensure the highest levels of security. 2. Threat Intelligence & Incident Response: Establish and manage a threat intelligence program to monitor and respond to emerging cyber threats and vulnerabilities. Develop incident response protocols, ensuring rapid detection and remediation of security incidents. Lead root cause analysis, forensic investigations, and post-incident reviews to identify and resolve systemic security issues. Implement intrusion detection and prevention systems (IDS/IPS) to defend against external and internal threats. 3. Security Technology & Tools Implementation: Select, implement, and manage security technologies such as firewalls, VPNs, SIEMs (Security Information and Event Management), endpoint security, and encryption systems. Design and implement Identity and Access Management (IAM) solutions, ensuring robust authentication, authorization, and auditing controls. Lead the implementation of encryption technologies for data at rest, in transit, and during processing. Deploy vulnerability scanning, security auditing, and penetration testing tools to identify weaknesses and ensure proactive risk management. 4. Risk Management & Compliance: Develop and maintain the organizations risk management framework to assess, manage, and mitigate security risks. Ensure compliance with regulatory standards and best practices such as PCI-DSS, NIST, ISO, and other relevant security frameworks. Conduct regular security audits, vulnerability assessments, and penetration testing to ensure compliance with industry regulations. Develop and document security governance policies and procedures to ensure all security controls are properly enforced. 5. Cloud & Hybrid Security: Develop and implement security strategies for multi-cloud and hybrid cloud environments, ensuring data protection, access controls, and compliance across all platforms. Ensure cloud services (AWS, Azure, GCP) are configured to meet stringent security and compliance requirements. Oversee the implementation of cloud-native security solutions, such as cloud access security brokers (CASBs) and cloud workload protection platforms (CWPPs). Monitor and secure APIs, cloud storage, and containerized environments, ensuring full security coverage. 6. Security Awareness & Training: Lead and promote security awareness training programs for employees at all levels to ensure best security practices are followed. Stay up-to-date with the latest cybersecurity trends, threats, and regulatory changes, ensuring the organization adapts to new risks. Provide ongoing training and mentorship to junior security engineers, fostering a culture of security across the organization. 7. Disaster Recovery & Business Continuity: Design and implement security measures that ensure business continuity during disruptions or disasters. Develop comprehensive disaster recovery strategies that include secure data backups, failover systems, and redundancy plans. Test and regularly review disaster recovery procedures to ensure rapid recovery of critical systems in the event of an incident. Qualifications: Proven track record of delivering complex security solutions for clients in diverse industries, ensuring successful implementation and post-deployment support. Strong knowledge of security frameworks such as ISO 27001, NIST, PCI-DSS, GDPR, and their application in real-world environments. Strong understanding of cryptography, firewalls, VPN, IDS/IPS, SIEM, IAM, and endpoint protection technologies. Knowledge of regulatory requirements, such as GDPR, HIPAA, PCI-DSS, and SOX compliance. Excellent problem-solving skills, with the ability to manage complex projects and large-scale systems. Strong leadership and communication skills, able to articulate security concepts to both technical and non-technical stakeholders. Familiarity with security aspects of IT systems, including virtualization, containers, microservices, and software-defined networks (SDN).

One address, no account. We’ll tell you when matching roles go live.

More at Protean eGov Technologies

Related open roles

View all roles