Application Security Architect

Mettler-Toledo, Inc.

Bengaluru

Hybrid

INR 2,000,000 - 3,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
Quarterly awards for outstanding individuals

Job summary

Mettler-Toledo, Inc. is looking for a Principal Application Security Architect in Bengaluru, India. The role involves leading application security initiatives, ensuring secure application delivery, and mentoring teams on security best practices. Candidates should have over 12 years of experience in application security and be well-versed in cloud security and CI/CD integrations. The position offers a hybrid working model and extensive training opportunities.

Qualifications

  • 12–15+ years in software engineering, application security, or architecture experience.
  • Proven history of executing and delivering AppSec improvements at scale.
  • Active in the security community, regularly attends meetups or conferences.

Responsibilities

  • Own delivery of AppSec outcomes for critical applications and platforms.
  • Lead hands-on threat modelling and remediation execution.
  • Create and guide a team of local application security subject matter experts.

Skills

Secure SDLC and application architecture
OWASP Top 10
API Security Top 10
Cloud Security
Deep experience integrating security into CI/CD pipelines

Education

B.E / B.Tech / M.E / M.Tech in Computer Science or related fields

Tools

Blackduck
Trivy
Prisma cloud
Tenable

Job description

Our Opening and Your Responsibilities
Role Summary

The Principal Application Security Architect is a hands‑on execution leader accountable for delivering application security outcomes across modern cloud‑native and legacy enterprise systems. This role owns security delivery end‑to‑end – from design through production, ensuring high‑risk applications ship securely, on time, and at scale. This is a doer role with architectural authority.

Primary Responsibility
  • Own delivery of AppSec outcomes for critical applications and platforms
  • Lead hands‑on threat modelling, architecture reviews, and remediation execution
  • Set and enforce security release gates and acceptance criteria
  • Actively reduce critical and high‑risk vulnerabilities through deep code reviews, root‑cause analysis, direct remediation guidance
  • Ensure development teams understand the importance of application security principles
  • Continuously liaise with various product teams to analyse application vulnerabilities
  • Create and guide a team of local application security subject matter experts
  • Serve as final technical authority for AppSec decisions on high‑stakes initiatives
  • Unblock engineering teams and resolve security‑delivery conflicts
  • Report clear, actionable risk status to senior leadership
  • Develop organisational processes and methods for security, privacy and related assets
  • Continuously evaluate vulnerabilities and risks in software platforms, interfaces and applications
  • Perform SW threat modelling, security risk assessment across various technology stacks
  • Create product security requirements and concepts; promote ‘secure by design’ approach
  • Triage and remediation planning for discovered vulnerabilities aligned to program deadlines
  • Engage with internal and external partners to ensure alignment to commitments
  • Mentor SW teams on secure coding, best practices, industry standards, tools, and processes
  • Seek to build‑in security during development of software systems and applications
  • Ensure that organisational processes stay current; contribute to the Quality Management System
What You Need to Succeed
  • Qualification: B.E / B.Tech / M.E / M.Tech (Computer Science or related fields)
  • 12–15+ years in software engineering, application security, or architecture experience
  • Proven history of executing and delivering AppSec improvements at scale
  • Deep hands‑on expertise in: Secure SDLC and application architecture, OWASP Top 10, API Security Top 10, threat modelling (STRIDE or equivalent)
  • Strong experience securing modern architectures (cloud, APIs, microservices, containers, Kubernetes) & legacy enterprise systems (monoliths, SOA, on‑prem)
  • Strong understanding of authentication & authorization (OAuth2, OIDC, SAML), cryptography, secrets management, secure configuration
  • Deep experience integrating security into CI/CD pipelines
  • Experience with ISO 27001/27002 and NIST Cybersecurity Framework
  • Experience in identifying potential attacks and threat vectors and offering mitigation
  • Experience with vulnerability management tools like Blackduck, Trivy, Prisma cloud, Tenable etc.
  • Proficient in security assessments, authentication and access control
  • Understanding of penetration testing, applied cryptography and security protocols preferable
  • Experience with AppSec practices for infrastructure, connected devices etc.
  • Good understanding of cryptographic primitives and their underlying principles preferable
  • Good understanding of networking protocols, such as TCP/IP and UDP.
  • Good understanding of content delivery networks and their integration into applications
  • Active in the security community. Regularly attends meetups or conferences
  • Working understanding of agile development processes
  • Lead without authority in a matrix organization
  • Excellent communication skills – verbal and written
  • Ability to translate complex ideas into simple solutions to implement
Our Offer to You
  • Hybrid working model.
  • Family mediclaim benefits including parents & term life insurance cover.
  • Wide portfolio of training opportunities including but not limited to conferences, workshops, education reimbursement & online learning.
  • A wide range of career paths to explore based on individual strengths and aspirations.
  • Quarterly and annual awards for outstanding individuals and quality of life improvement program.
Equal Opportunity Employment

We promote equal opportunity worldwide and value diversity in our teams in terms of business background, area of expertise, gender and ethnicity. For more information on our commitment to sustainability, diversity and equal opportunity please visit us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000