Padmi

Principal Product Security Architect

IndiaPosted 2 months ago
CybersecurityStaff+Full Time; Regular
Apply at Qualys

Opens the source posting on shine.com

Source description

About the role

View original

As a Principal Product Security Architect, you will play a vital role in driving security excellence across the product portfolio by combining hands-on technical leadership with strategic security guidance. Your responsibilities will include partnering with engineering teams early in the design process to embed security controls, conducting comprehensive architecture reviews, and developing secure design patterns for common use cases. Additionally, you will collaborate with various teams to identify security gaps, usability issues, and opportunities for security improvements. Key Responsibilities: - Partner with engineering teams to embed security controls and minimize remediation costs - Conduct comprehensive architecture reviews and threat modeling exercises - Author risk assessment reports for executive leadership and stakeholders - Create secure code snippets, libraries, and design patterns - Maintain a library of security patterns addressing common vulnerabilities - Actively use products to identify security gaps and provide feedback to teams - Represent Product Security in technical design reviews and risk committees - Drive cross-functional initiatives to improve security posture while maintaining development velocity Qualifications: Requirements: - 13+ years of experience in information security with a focus on product security or security architecture - Expertise in secure software development lifecycle practices and modern development frameworks - Ability to write production-quality code and create technical security guidance - Strong understanding of common vulnerability classes and secure coding practices - Excellent communication skills with the ability to tailor messaging for technical and executive audiences Preferred Qualifications: - Experience with cloud-native architectures and container security - Knowledge of cryptography, authentication protocols, and identity management - Background in security compliance frameworks - Certifications such as CISSP, CISSP-ISSAP/TOGAF would be advantageous Skills: - Communication: Strong verbal and written communication skills - Languages: Proficiency in Java, Python, Go, React - Security Tools: Experience with threat modeling tools, SAST/DAST scanners - Architecture: Deep understanding of microservices, APIs, event-driven systems - Security Controls: Expertise in authentication, encryption, and secure communications - Methodologies: Familiarity with threat modeling, risk frameworks, and secure design principles As a Principal Product Security Architect, you will play a vital role in driving security excellence across the product portfolio by combining hands-on technical leadership with strategic security guidance. Your responsibilities will include partnering with engineering teams early in the design process to embed security controls, conducting comprehensive architecture reviews, and developing secure design patterns for common use cases. Additionally, you will collaborate with various teams to identify security gaps, usability issues, and opportunities for security improvements. Key Responsibilities: - Partner with engineering teams to embed security controls and minimize remediation costs - Conduct comprehensive architecture reviews and threat modeling exercises - Author risk assessment reports for executive leadership and stakeholders - Create secure code snippets, libraries, and design patterns - Maintain a library of security patterns addressing common vulnerabilities - Actively use products to identify security gaps and provide feedback to teams - Represent Product Security in technical design reviews and risk committees - Drive cross-functional initiatives to improve security posture while maintaining development velocity Qualifications: Requirements: - 13+ years of experience in information security with a focus on product security or security architecture - Expertise in secure software development lifecycle practices and modern development frameworks - Ability to write production-quality code and create technical security guidance - Strong understanding of common vulnerability classes and secure coding practices - Excellent communication skills with the ability to tailor messaging for technical and executive audiences Preferred Qualifications: - Experience with cloud-native architectures and container security - Knowledge of cryptography, authentication protocols, and identity management - Background in security compliance frameworks - Certifications such as CISSP, CISSP-ISSAP/TOGAF would be advantageous Skills: - Communication: Strong verbal and written communication skills - Languages: Proficiency in Java, Python, Go, React - Security Tools: Experience with threat modeling tools, SAST/DAST scanners - Architecture: Deep understanding of microservices, APIs, event-driven systems - Security Controls: Expertise in authentication, encryption, and secure communications - Methodologies: Familiarity with threat modeling, risk frameworks,

One address, no account. We’ll tell you when matching roles go live.

More at Qualys

Related open roles

View all roles