Product Security Architect IRC286354

GlobalLogic

Gurgaon

On-site

INR 3,500,000 - 6,000,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible work schedules
Work from home options
Paid time off
Professional development

Job summary

GlobalLogic in India is seeking a Product Security Architect to lead offensive and defensive security strategies within engineering teams. This hands-on role involves writing security-centric code, conducting deep-dive penetration tests, and automating threat detection in pipelines.

You will drive secure design, perform architecture reviews, and develop reusable security libraries while guiding remediation with engineers and stakeholders.

Qualifications

  • 10+ years in Cybersecurity or Software Engineering, with 4+ years in Product Security or AppSec.
  • Breaker mindset balanced with builder empathy to explain vulnerabilities to product owners.
  • OSCP certification is required or strongly preferred.

Responsibilities

  • Secure Architecture & Threat Modeling: lead structured threat modeling sessions using STRIDE/PASTA during design.
  • Architecture Reviews: conduct deep-dive security reviews of designs focusing on authentication (OIDC/SAML), authorization (RBAC/ABAC), data isolation.
  • Security Scaffolding: build/maintain shared security libraries and encryption wrappers for engineers.
  • In-House Pentesting: perform manual tests on web apps, APIs, and cloud infra to find logic flaws.
  • Exploitation Research: develop PoC exploits to demonstrate impact and remediation.
  • Bug Bounty Management: oversee bug bounty program and triage reports with developers on high-severity fixes.
  • Secure Code Review: assess high-risk PRs for OWASP Top 10/ASVS.
  • Automation (DevSecOps): integrate SAST/DAST/SCA into CI/CD to reduce false positives.
  • Vulnerability Remediation: write code fixes and pair-program with engineers.

Skills

Security frameworks
Offensive tools
Secure coding
Cloud security
Identity & auth

Education

OSCP Certification

Tools

Burp Suite
Metasploit
Kali Linux
Nmap
Postman

Job description

Job Description

Looking for a Product Security Architect to lead our offensive and defensive security strategies. You will be embedded with engineering teams to ensure our products are resilient against sophisticated attacks. This is a “hands‑on” role: you will write security-centric code, conduct deep-dive penetration tests, and automate threat detection within our pipelines. You are not just an auditor; you are a builder who solves security challenges with engineering solutions.

Requirements
Technical Mastery Required
  • Security Frameworks: OWASP ASVS, SAMM, NIST 800-53, and Cloud Security Alliance (CSA).
  • Offensive Tools: Burp Suite Professional, Metasploit, Kali Linux, Nmap, and Postman (for API hacking).
  • Secure Coding: Deep knowledge of vulnerabilities in Java/.NET and how to prevent them (e.g., SQLi, XSS, CSRF, SSRF).
  • Cloud Security: Securing Kubernetes (K8s) secrets, IAM Least Privilege, and Cloud Workload Protection (CWPP).
  • Identity/Auth: Expert-level understanding of JWT, OAuth2, OpenID Connect, and WebAuthn/FIDO2.
Qualifications

Experience: 10+ years in Cybersecurity or Software Engineering, with 4+ years specifically in Product Security or Application Security (AppSec).

Mindset: A “Breaker” mentality balanced with a “Builder’s” empathy; the ability to explain why a vulnerability matters to a product owner.

Certifications: OSCP (Offensive Security Certified Professional)

Communication: Ability to translate complex exploitation paths into clear risk assessments for non-technical leadership.

Job responsibilities
Key Responsibilities
  • Secure Architecture & Threat Modeling

Threat Modeling: Lead structured threat modeling sessions (using STRIDE or PASTA) during the design phase to identify architectural flaws before a single line of code is written.

Architecture Reviews: Conduct deep-dive security reviews of system designs, focusing on authentication (OIDC/SAML), authorization (RBAC/ABAC), and data isolation.

Security Scaffolding: Build and maintain shared security libraries (e.g., standardized encryption wrappers, input validation modules) for use by all engineering teams.

Offensive Security & Exploitation

In-House Pentesting: Perform regular manual penetration tests on web applications, APIs, and cloud infrastructure to identify logic flaws that automated tools miss.

Exploitation Research: Develop PoC (Proof of Concept) exploits for discovered vulnerabilities to demonstrate impact to stakeholders and validate remediation.

Bug Bounty Management: Oversee the bug bounty program, triaging reports and working directly with developers on high‑severity fixes.

Secure Coding & SDLC Integration

Secure Code Review: Review high-risk pull requests (e.g., changes to auth, payments, or crypto) to ensure compliance with OWASP Top 10 and ASVS.

Automation (DevSecOps): Integrate and fine-tune SAST, DAST, and SCA tools into the CI/CD pipeline to reduce “false positive” fatigue for developers.

Vulnerability Remediation: Don’t just find bugs—write the code to fix them. Pair-program with engineers to implement secure patterns.

What we offer
Exciting Projects

We focus on industries like High-Tech, communication, media, healthcare, retail and telecom. Our customer list is full of fantastic global brands and leaders who love what we build for them.

Collaborative Environment

You Can expand your skills by collaborating with a diverse team of highly talented people in an open, laidback environment — or even abroad in one of our global centers or client facilities!

Work-Life Balance

GlobalLogic prioritizes work-life balance, which is why we offer flexible work schedules, opportunities to work from home, and paid time off and holidays.

Professional Development

Our dedicated Learning & Development team regularly organizes Communication skills training("GL Vantage, Toast Master"),Stress Management program, professional certifications, and technical and soft skill trainings.

Excellent Benefits
  • We provide our employees with competitive salaries, family medical insurance, Group Term Life Insurance, Group Personal Accident Insurance , NPS(National Pension Scheme ), Periodic health awareness program, extended maternity leave, annual performance bonuses, and referral bonuses.
Fun Perks
  • We want you to love where you work, which is why we host sports events, cultural activities, offer food on subsidies rates, Corporate parties. Our vibrant offices also include dedicated GL Zones, rooftop decks and GL Club where you can drink coffee or tea with your colleagues over a game of table and offer discounts for popular stores and restaurants!
About GlobalLogic

GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the world’s largest and most forward-thinking companies. Since 2000, we’ve been at the forefront of the digital revolution – helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in transforming businesses and redefining industries through intelligent products, platforms, and services.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Architect IRC286354
Product Security Architect IRC286354

GlobalLogic • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Flexible work schedules
Work from home opportunities
Learning & Development programs
Senior Backend Engineer – Python IRC302277
Senior Backend Engineer – Python IRC302277

GlobalLogic • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Exciting Projects
Collaborative Environment
Work-Life Balance
+3
Senior Architect IRC302165
Senior Architect IRC302165

GlobalLogic • Chennai District

On-site
INR 3,500,000 - 6,000,000
Flexible work schedules
Work from home options
Paid time off
DevOps Engineer (3 Years Experience) IRC302539
DevOps Engineer (3 Years Experience) IRC302539

GlobalLogic • Gurgaon

On-site
INR 1,400,000 - 2,300,000
Exciting Projects
Collaborative Environment
Work-Life Balance
+3
Senior Java Developer IRC301136
Senior Java Developer IRC301136

GlobalLogic • Bengaluru

On-site
INR 1,800,000 - 4,000,000
Flexible work schedule
Work from home
Paid time off & holidays
+11
DevOps Engineer | Chennai IRC300885
DevOps Engineer | Chennai IRC300885

GlobalLogic • Chennai District

On-site
INR 1,200,000 - 2,400,000
Platform Lead IRC300489
Platform Lead IRC300489

GlobalLogic • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Sr. Java Dev IRC300495
Sr. Java Dev IRC300495

GlobalLogic • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Flexible work schedules
Work from home options
Learning & development programs
+1
Sr. Java Dev IRC300498
Sr. Java Dev IRC300498

GlobalLogic • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Exciting Projects
Collaborative Environment
Work-Life Balance
+3
OKTA Admin IRC301685
OKTA Admin IRC301685

GlobalLogic • India

On-site
INR 1,200,000 - 1,800,000
Flexible work schedules
Work from home opportunities
Professional development programs
+1