Lead Cloud & Application Security Architect

JRD Systems

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

12 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

JRD Systems is seeking a Lead Cloud & Application Security Architect with 8+ years of experience to secure enterprise-grade applications across AWS, GCP, and Azure. This senior role combines hands-on architecture with strategic leadership to establish secure coding standards, threat modeling frameworks, and DevSecOps guardrails.

You will mentor engineers, collaborate with executive leadership, and drive security across multi-cloud environments, ensuring robust risk management and secure software

Qualifications

  • 8+ years of deep technical experience in application security or DevSecOps.
  • Hands-on architecture across AWS, GCP, and Azure.
  • Strong knowledge of IAM, KMS, VPC security, and threat modeling.

Responsibilities

  • Define and enforce multi-cloud guardrails and IaC security standards.
  • Lead secure DevSecOps pipelines with SAST, DAST, SCA, and container scanning.
  • Direct threat modeling sessions (STRIDE/PASTA) for flagship products.
  • Create secure-by-default reference architectures and remediations.
  • Mentor engineering leads and security staff.

Skills

Multi-Cloud
DevSecOps
Threat Modeling
Security Leadership
Secure Coding

Tools

AWS IAM
GCP IAM
Azure Key Vault

Job description

Job Description: Lead Cloud & Application Security Architect
Role Overview

We are seeking a Lead Cloud & Application Security Architect with a distinguished track record of securing enterprise-grade applications across highly complex, multi-cloud environments. With a minimum of 8 years of dedicated experience, you will serve as the premier technical authority bridging software engineering, cloud architecture, and modern threat defense.

This is a high-impact, hands-on leadership role. You will be responsible for defining the secure coding standards, threat modeling frameworks, and DevSecOps compliance guardrails that protect our software across AWS, GCP, and Azure. You are someone who commands the technical respect of elite developers, possesses deep multi-cloud infrastructure fluency, and can elegantly translate sophisticated technical risks into pragmatic business outcomes.

What You'll Do
  • Define Multi-Cloud Guardrails: Architect, implement, and maintain consistent infrastructure-as-code (IaC) security standards and zero-trust Identity & Access Management (IAM) governance across our AWS, GCP, and Azure footprints.
  • Establish Strategic DevSecOps Pipelines: Standardize and scale automated application security testing (SAST, DAST, SCA, and container scanning) globally within multi-cloud CI/CD ecosystems. Ensure these pipelines protect velocity while minimizing false positives.
  • Lead Advanced Threat Modeling: Direct complex architectural reviews and threat modeling sessions (using STRIDE/PASTA) for flagship enterprise products, mapping trust boundaries across heterogeneous cloud infrastructures and distributed microservices.
  • Engineered Remediations & Reference Architectures: Author high-quality, reusable software libraries and "secure-by-default" reference architectures (e.g., standardized encryption, multi-tenant data isolation, secret management) to eliminate entire vulnerability classes at the root.
  • Champion Culture & Strategy: Drive the long-term AppSec roadmap, establish an enterprise-wide Security Champions program, and provide technical mentorship to senior engineering leads and security staff.
What You'll Bring
  • Experience Blueprint: A minimum of 8+ years of deep technical experience in application security, product security, or DevSecOps engineering, preferably backed by an early career foundation in core software development.
  • Multi-Cloud Mastery: Proven hands-on architecture experience across all three major public cloud providers:
  • AWS: Deep knowledge of IAM, KMS, VPC security, GuardDuty, and AWS Organizations.
  • GCP: Proficiency with Cloud IAM, Workload Identity, Cloud Key Management, and Google Kubernetes Engine (GKE) security.
  • Azure: Experience with Microsoft Entra ID (formerly Azure AD), Azure Key Vault, Managed Identities, and Azure Kubernetes Service (AKS).
  • Advanced Threat Mechanics: Comprehensive mastery of web application vulnerabilities (OWASP Top 10), API security, container security/isolation, and modern distributed system attacks.
  • Pragmatic Executive Presence: Exceptional communication skills with a proven ability to collaborate with engineering squads to resolve issues while effectively presenting risk metrics to C-level executives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Architect
Cloud Security Architect

Liminal Custody • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Cloud Security Architect
Cloud Security Architect

ZainTECH • Ernakulam

On-site
INR 1,500,000 - 2,000,000
Cloud Security Architect
Cloud Security Architect

Zain Group • Ernakulam

On-site
INR 1,500,000 - 2,500,000
Cloud Security Architect
Cloud Security Architect

Adfolks LLC • Ernakulam

On-site
INR 2,000,000 - 3,000,000
Senior Cloud Security Architect
Senior Cloud Security Architect

Claranet India • Jaipur

On-site
INR 800,000 - 1,200,000
Senior Cloud Security
Senior Cloud Security

Sourcebae • Mumbai

On-site
INR 4,000,000 - 6,500,000
Platform Security Engineer
Platform Security Engineer

CDK Global • Hyderabad

On-site
INR 300,000 - 520,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

Weekday AI (YC W21) • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Senior Cloud Security Engineer - DevSecOps
Senior Cloud Security Engineer - DevSecOps

NetConnectGlobal • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Cloud Security Engineer
Cloud Security Engineer

PwC India • India

On-site
INR 2,400,000 - 4,200,000