Senior Manager - Information Security

Etenico Technologies

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

11 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Etenico Technologies seeks a Security Architect to own enterprise security across application, infrastructure and the integration seam in a hybrid, multi-cloud data environment. You will design secure reference architectures, set baselines, and lead architecture reviews across on-premise and cloud estates.

You will mentor a team of security architects, advise CIO/CISO on architecture decisions, and ensure observable telemetry for defensible security controls in healthcare data environments.

Qualifications

  • 15+ years in information security, with leadership in security architecture.
  • Experience across application, infrastructure, and integration layers.
  • Healthcare data/regulatory context preferred; global/multi-geography exposure.

Responsibilities

  • Own enterprise security architecture across application, infrastructure, and integration.
  • Define target-state security architectures for on-premise, hybrid, and multi-cloud estates.
  • Chair architecture reviews and set OS baselines; defend against engineering pushback.
  • Define API security end-to-end and identity/service-to-service trust models.
  • Lead and grow a team of security architects; advise CIO/CISO on architecture decisions.

Skills

Security architecture
Cloud security
API security
Zero trust
Kubernetes security

Tools

SAST
DAST
SCA
Secrets scanning
CI/CD security

Job description

Exp- 8+
Team

Security architects and domain specialists (application, infrastructure, cloud)

Role Purpose

Modern enterprises do not get breached in the application or in the infrastructure — they get breached in the space between them. APIs, data pipelines, service handoffs, and integration layers form a seam that traditionally has no single owner: application security regimes stop at the code boundary, infrastructure security regimes stop at the host and network boundary, and the integration fabric between them is under-governed by both.

The Security Architect owns end-to-end security architecture across the enterprise — application security, infrastructure security, and, explicitly, the integration seam between them. The mandate is to design, standardise, and defend the security architecture of a hybrid, multi-cloud, high-volume data environment operating across four geographies and a 30,000+ workforce handling regulated healthcare data.

What This Role Is — and Is Not

This is a security architecture role, not a GRC role. The incumbent is a practising technologist who designs and reviews systems at the whiteboard and in the design document — not an audit, compliance, or risk-register manager. Candidates whose background is predominantly GRC, audit coordination, or compliance programme management will not be considered for this position, regardless of seniority. Familiarity with regulatory context (HIPAA, HITRUST, SOC 2) is expected as environmental literacy — it is not the job.

Key Responsibilities
1. Enterprise Security Architecture Ownership
  • Define and maintain the target-state security architecture, reference architectures, and reusable secure design patterns across on-premise, hybrid, and multi-cloud estates.
  • Chair the security design review board; every significant platform, product, and integration passes through architecture review with documented control decisions.
  • Set hardening and configuration baselines at the operating system level (Windows and Linux), and defend them against engineering pushback with technical argument, not policy citation.
2. Application Security Architecture
  • Own secure-by-design standards across the SDLC: threat modelling, secure design review, cryptographic standards, secrets management, and AppSec tooling architecture (SAST, DAST, SCA, secrets scanning).
  • Define API security architecture end to end: authentication and authorisation models (OAuth 2.0, OIDC, mTLS, service-to-service trust), gateway patterns, schema and payload validation, rate limiting, and abuse detection.
3. Infrastructure Security Architecture
  • Architect network segmentation, zero-trust access, identity and privileged-access architecture, and endpoint security integration across data centres and cloud.
  • Own workload security architecture in a multi-cloud environment: landing zones, container and Kubernetes security, infrastructure-as-code review, and cloud-native control selection (CSPM, DSPM, CNAPP alignment).
4. The Integration Seam — Explicit Mandate
  • Own security architecture for the layer where application and infrastructure regimes meet: API gateways and service meshes, middleware and message queues, data ingestion and ETL/ELT pipelines, file-transfer and B2B handoffs, and third-party integrations.
  • For every material data flow, establish explicit control ownership at each hop — ingestion, staging, transformation, serving, consumption — so that no handoff is unowned and no control assumption is implicit.
  • Design trust boundaries and data-in-motion protections across environment transitions (on-prem to cloud, cloud to cloud, enterprise to partner).
5. Leadership and Advisory
  • Lead and grow a team of security architects; raise the architectural bar across engineering and platform teams through patterns, enablement, and review — not gatekeeping.
  • Serve as principal technical advisor to the CIO and CISO on architecture-driven risk decisions, vendor and platform architecture evaluations, and security investment trade-offs.
  • Partner with SOC and detection engineering so that architecture decisions produce observable, defensible telemetry — architecture that cannot be monitored is architecture that cannot be defended.
Required Technical Depth

The successful candidate can do all of the following unaided, at a whiteboard:

  • Operating systems. Explain process, memory, privilege, and credential models on Windows and Linux, and derive hardening decisions from them rather than from checklists.
  • Data flow architecture. Draw a typical enterprise data path — ingestion, landing/staging, ETL/ELT transformation, warehouse/lake serving, API and reporting consumption — and place the correct control (and control owner) at every hop and handoff.
  • API mechanics. Articulate how APIs actually work: token issuance and validation, gateway versus service-level enforcement, east-west versus north-south traffic, schema validation, and common failure modes (BOLA/IDOR, token replay, over-permissive scopes).
  • Hybrid and multi-cloud. Deep working fluency in at least two of AWS, Azure, and GCP, including identity federation, network architecture, encryption and key management, and the security consequences of managed-service choices.
  • Identity and network. Zero-trust architecture, segmentation strategy, IAM/PAM design, and directory/federation architecture across a heterogeneous estate.
  • Modern platforms. Containers and Kubernetes, service mesh, CI/CD pipeline security, and infrastructure-as-code review.
Certifications and Experience
Certifications — Required
  • At least one current, technically-oriented security architecture or engineering certification: CISSP (ISSAP concentration strongly preferred), SABSA (SCF/SCP), CCSP, or GIAC GDSA/GCSA.
  • Offensive or hands-on credentials (OSCP, GPEN, GWAPT) are a strong plus — they evidence the attacker-informed mindset this role demands.
  • GRC-track certifications (CISA, CRISC, ISO 27001 Lead Auditor/Implementer) do not qualify on their own and will not be weighted as substitutes for the above.
Experience
  • 15+ years in information security, with 5+ years in a security architecture leadership role covering both application and infrastructure domains — not one or the other.
  • Demonstrable ownership of security architecture in a hybrid, multi-cloud environment at enterprise scale.
  • Experience in regulated-data environments (healthcare, financial services, or equivalent) preferred; global or multi-geography operating experience preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architecture and ENGINEERING
Security Architecture and ENGINEERING

TOCUMULUS • Bengaluru

On-site
INR 1,600,000 - 2,400,000
Staff Security Architect
Staff Security Architect

KFC Corporation • Gurgaon

Hybrid
INR 1,800,000 - 2,500,000
Information Technology Security Manager
Information Technology Security Manager

Advantmed India LLP • Pune District

Hybrid
INR 2,000,000 - 4,000,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Hyderabad

On-site
INR 3,500,000 - 6,000,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Maharashtra

On-site
INR 900,000 - 1,260,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Bengaluru

On-site
INR 4,000,000 - 7,500,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Mumbai

On-site
INR 4,200,000 - 7,000,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Chennai District

On-site
INR 3,500,000 - 7,000,000
Security Architect
Security Architect

JUARA IT SOLUTIONS • Chennai District

On-site
INR 3,500,000 - 5,500,000
Security Solutions Architect (Enterprise, Cloud, OT & AI Security)
Security Solutions Architect (Enterprise, Cloud, OT & AI Security)

PeopleBridge Partners (PBP) • Mumbai

On-site
INR 2,500,000 - 3,500,000
Direct impact on enterprise architecture
Opportunities for professional growth
Blend of strategy and hands-on work