Principal, Product Security Architect

Zinnov Management Consulting

Bengaluru

Hybrid

INR 4,500,000 - 7,500,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Zinnov Management Consulting in Bengaluru seeks a Principal, Product Security Architect to define secure-by-design architecture across products and cloud services. You will lead threat modeling, security design reviews, and governance for security patterns and controls while guiding engineering teams to reduce architectural risk throughout the lifecycle.

We expect deep knowledge of secure-by-design principles, threat modeling, and modern cloud-native architectures.

Qualifications

  • Must have deep knowledge of secure-by-design principles, threat modeling, security architecture patterns, risk assessment, and control design across applications, cloud, infrastructure, and identity.
  • Experience with secure SDLC / DevSecOps practices and security testing disciplines including SAST, DAST, SCA, SBOM, API security, secrets, and container/IaC security.
  • Strong understanding of modern cloud-native architectures, APIs, Kubernetes, identity protocols, encryption/PKI, logging, and network-security controls.
  • Ability to analyze complex solution constraints and ensure compatibility, interoperability, stability, usability, and security across multiple systems and platforms.

Responsibilities

  • Define and govern secure-by-design architecture across products, platforms, cloud services, and enterprise integrations.
  • Lead threat modeling and security design reviews; establish reusable security patterns and control requirements.
  • Guide engineering teams in reducing architectural risk throughout the product and software development lifecycle.
  • Embed secure architecture reviews into the SDLC and partner with DevSecOps teams on secure tooling and controls.
  • Review cloud and container architectures for security design gaps and control effectiveness.
  • Develop architecture standards, technical memoranda, and governance artifacts for the internal architecture and product-security community.
  • Provide technical leadership and design guidance to senior engineering stakeholders.

Skills

Threat modeling
Security architecture
DevSecOps
Cloud security
Kubernetes
API security
Security testing (SAST/DAST/SCA)
Executive communication
Secure-by-design principles
Security documentation

Education

Bachelor's degree in Computer Science, Engineering, Information Security, or related

Tools

IriusRisk
ThreatModeler
Microsoft Threat Modeling Tool
Checkmarx
Veracode
Snyk
Black Duck

Job description

What you'll do

As Principal, Product Security Architect, you will define and govern secure‑by‑design architecture across products, platforms, cloud services, and enterprise integrations. You will lead threat modeling and security design reviews, establish reusable security patterns and control requirements, and guide engineering teams in reducing architectural risk throughout the product and software development lifecycle.

How you'll make an impact
  • Design secure end‑to‑end architectures across applications, APIs, cloud, infrastructure, data, identity, and connected‑product environments, balancing security, usability, interoperability, resilience, and cost.
  • Lead threat modeling and abuse‑case analysis using methodologies such as STRIDE, attack trees, MITRE ATT&CK, and tools such as IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool, or equivalent.
  • Define security reference architectures and patterns for identity, encryption, key management, secrets, network segmentation, API security, data protection, logging, and secure communications.
  • Embed secure architecture reviews into the SDLC and partner with DevSecOps teams on SAST, DAST, SCA, SBOM, container, IaC, and cloud‑security controls using enterprise tooling such as Checkmarx, Veracode, Snyk, Black Duck, or equivalents.
  • Assess product and platform designs against medical‑device and software‑security expectations including IEC 81001‑5‑1, AAMI TIR57, NIST SSDF, FDA cybersecurity guidance, and applicable enterprise standards.
  • Review cloud and container architectures across AWS/Azure/GCP, Kubernetes, microservices, APIs, and third‑party integrations for security design gaps and control effectiveness.
  • Guide risk treatment and remediation for architectural findings, product vulnerabilities, attack paths, and control deficiencies with engineering and business owners.
  • Develop architecture standards, technical memoranda, decision records, and governance artifacts for the internal architecture and product‑security community.
  • Evaluate emerging security technologies and patterns and provide technical leadership, coaching, and design guidance to senior engineering stakeholders.
What you'll bring
Skills Required
  • 8+ years of experience in security architecture, solution architecture, product security, or related engineering roles designing secure end‑to‑end solutions.
  • Deep knowledge of secure‑by‑design principles, threat modeling, security architecture patterns, risk assessment, and control design across applications, cloud, infrastructure, and identity.
  • Experience with secure SDLC / DevSecOps practices and security testing disciplines including SAST, DAST, SCA, SBOM, API security, secrets, and container/IaC security.
  • Strong understanding of modern cloud‑native architectures, APIs, Kubernetes, identity protocols, encryption/PKI, logging, and network‑security controls.
  • Ability to analyze complex solution constraints and ensure compatibility, interoperability, stability, usability, and security across multiple systems and platforms.
  • Strong technical writing, architecture documentation, risk communication, and executive level stakeholder skills.
  • Bachelor's degree in Computer Science, Engineering, Information Security, or a related technical discipline.
Preferred
  • Experience in medical-device, healthcare, or life‑sciences product security and familiarity with FDA cybersecurity guidance, IEC 81001‑5‑1, AAMI TIR57, and NIST SSDF.
  • Experience with threat‑modeling platforms and security architecture governance at enterprise scale.
  • CISSP, CSSLP, SABSA, CCSP, cloud‑security, or comparable product/security architecture certification.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberSecurity Architect
CyberSecurity Architect

ITH Icoserve • Bengaluru

On-site
INR 4,500,000 - 7,500,000
CyberSecurity Architect
CyberSecurity Architect

Siemens Mobility • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Product Security Lead
Product Security Lead

Insight Global • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Principal Architect (Security)
Principal Architect (Security)

Weekday • Hyderabad

On-site
INR 5,000,000 - 10,000,000
Senior Product Security Architect
Senior Product Security Architect

Cubic Corporation • Hyderabad

On-site
INR 3,500,000 - 7,500,000
Senior Product Security Architect
Senior Product Security Architect

Cubic Corporation • Telangana

On-site
INR 2,000,000 - 3,000,000
Product Security Architect (Threat Modeling)
Product Security Architect (Threat Modeling)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 3,000,000 - 5,000,000
Principal Architect (Security)
Principal Architect (Security)

Weekday AI (YC W21) • Hyderabad

On-site
INR 5,000,000 - 10,000,000
CyberSecurity Architect
CyberSecurity Architect

Siemens Healthineers • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Principal Architect (Security)
Principal Architect (Security)

Engg • Hyderabad

On-site
INR 5,000,000 - 10,000,000