Product Security Lead

Insight Global

Bengaluru

On-site

INR 4,500,000 - 7,500,000

Full time

31 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Insight Global is seeking a Product Security Architect to lead secure by design architecture across digital products, cloud services, APIs, mobile apps, IoT/OT solutions, and AI/LLM enabled platforms. The role focuses on translating business and technical requirements into scalable security patterns, guardrails, and risk-based decisions throughout the SDLC.

The ideal candidate will guide engineering teams, perform threat modeling, and drive secure coding practices across multi-cloud and hybrid

Qualifications

  • Bachelor's degree in computer science, IT, cybersecurity, engineering or related field.

Responsibilities

  • Define and maintain Product Security reference architectures, design principles, security patterns, standards, and reusable guardrails for Web, Mobile, API, Cloud, IoT, and AI enabled products.
  • Lead Product Security Risk Assessments and security architecture reviews from concept and design through deployment, operations, major change, and end of life.
  • Facilitate threat modeling and attack path analysis to identify trust boundaries, abuse cases, security requirements, compensating controls, and residual risks.
  • Translate business, regulatory, privacy, and technical requirements into practical security controls and architecture decisions.
  • Provide security guidance for multi cloud, hybrid, containerized, serverless, microservices, event driven, and legacy application architectures.
  • Architect controls for identity and access, authentication and authorization, API security, secrets and key management, encryption, logging and monitoring, data protection, network segmentation, and secure configuration.
  • Guide product and engineering teams on secure design patterns, secure coding practices, vulnerability remediation, and prevention of recurring security defects.
  • Partner with DevSecOps teams to embed scalable security controls and risk based quality gates into CI/CD pipelines, developer workflows, Infrastructure as Code, and software supply chain processes.
  • Define security testing strategies combining SAST, SCA, DAST, IaC, Container, API, Mobile, Cloud, penetration testing, and manual design validation based on product risk.
  • Review high risk vulnerabilities and architecture exceptions, recommend remediation or compensating controls, and document risk ownership and decision rationale.
  • Develop security requirements for third party components, open source software, SaaS integrations, vendor hosted platforms, and externally exposed services.
  • Establish secure architecture approaches for AI/LLM applications, including model and data access, prompt and output handling, agent and tool permissions, Retrieval Augmented Generation, AI APIs, and ML pipelines.
  • Support incident response, root cause analysis, and post incident architecture improvements for Product Security events when required.
  • Create architecture decision records, diagrams, assessment reports, security requirements, and executive ready risk summaries.
  • Present technical findings and strategic recommendations to engineering leaders, product owners, architecture forums, risk stakeholders, and senior management.
  • Mentor security engineers, deliver secure design enablement, and act as a trusted advisor to product and engineering teams.
  • Stay updated on emerging threats, vulnerabilities, regulatory expectations, and technology changes, and incorporate them into Product Security architecture and standards.

Skills

Threat modeling
Security architecture
DevSecOps
Cloud security
Application security
Security testing
Leadership

Education

Bachelor's degree in computer science, information technology, cybersecurity, engineering, or related discipline

Tools

SAST tools
SCA tools
DAST tools
IaC tooling
CI/CD pipelines

Job description

Insight Global is hiring for a Product Security Architect with strong expertise in Product Security to lead secure by design architecture across digital products, cloud services, APIs, mobile applications, IoT/OT connected solutions, and AI/LLM enabled platforms. This role focuses on translating business and technical requirements into scalable security patterns, architecture guardrails, and actionable risk decisions throughout the Software Development Lifecycle (SDLC). The ideal candidate will have deep experience in application and cloud security architecture, threat modeling, DevSecOps, security testing, and influencing engineering and product teams.

  • Bachelor's degree in computer science, information technology, cybersecurity, engineering, or related discipline.
  • 10 - 12 years of experience in cybersecurity, with strong experience in Product Security, Application Security, Cloud Security, and Security Architecture.
  • Demonstrated experience leading security architecture reviews for complex, business critical products across the software development lifecycle.
  • Experience working with engineering, architecture, product management, and business teams in a global, matrixed environment.
Roles and Responsibilities
  • Define and maintain Product Security reference architectures, design principles, security patterns, standards, and reusable guardrails for Web, Mobile, API, Cloud, IoT, and AI enabled products.
  • Lead Product Security Risk Assessments and security architecture reviews from concept and design through deployment, operations, major change, and end of life.
  • Facilitate threat modeling and attack path analysis to identify trust boundaries, abuse cases, security requirements, compensating controls, and residual risks.
  • Translate business, regulatory, privacy, and technical requirements into practical security controls and architecture decisions.
  • Provide security guidance for multi cloud, hybrid, containerized, serverless, microservices, event driven, and legacy application architectures.
  • Architect controls for identity and access, authentication and authorization, API security, secrets and key management, encryption, logging and monitoring, data protection, network segmentation, and secure configuration.
  • Guide product and engineering teams on secure design patterns, secure coding practices, vulnerability remediation, and prevention of recurring security defects.
  • Partner with DevSecOps teams to embed scalable security controls and risk based quality gates into CI/CD pipelines, developer workflows, Infrastructure as Code, and software supply chain processes.
  • Define security testing strategies combining SAST, SCA, DAST, IaC, Container, API, Mobile, Cloud, penetration testing, and manual design validation based on product risk.
  • Review high risk vulnerabilities and architecture exceptions, recommend remediation or compensating controls, and document risk ownership and decision rationale.
  • Develop security requirements for third party components, open source software, SaaS integrations, vendor hosted platforms, and externally exposed services.
  • Establish secure architecture approaches for AI/LLM applications, including model and data access, prompt and output handling, agent and tool permissions, Retrieval Augmented Generation, AI APIs, and ML pipelines.
  • Support incident response, root cause analysis, and post incident architecture improvements for Product Security events when required.
  • Create architecture decision records, diagrams, assessment reports, security requirements, and executive ready risk summaries.
  • Present technical findings and strategic recommendations to engineering leaders, product owners, architecture forums, risk stakeholders, and senior management.
  • Mentor security engineers, deliver secure design enablement, and act as a trusted advisor to product and engineering teams.
  • Stay updated on emerging threats, vulnerabilities, regulatory expectations, and technology changes, and incorporate them into Product Security architecture and standards.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Architect
Senior Product Security Architect

Cubic Corporation • Telangana

On-site
INR 2,000,000 - 3,000,000
Senior Product Security Architect
Senior Product Security Architect

Cubic Corporation • Hyderabad

On-site
INR 3,500,000 - 7,500,000
Product Security Architect (Threat Modeling)
Product Security Architect (Threat Modeling)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 3,000,000 - 5,000,000
Principal, Product Security Architect
Principal, Product Security Architect

Zinnov Management Consulting • Bengaluru

Hybrid
INR 4,500,000 - 7,500,000
Product Security Engineer
Product Security Engineer

Hugohub • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Senior Product Security Engineer
Senior Product Security Engineer

Ecolab Food Safety & Hygiene Solutions Private Limited • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Senior Product Security Engineer
Senior Product Security Engineer

enableIT • Bengaluru

Hybrid
INR 3,500,000 - 5,500,000