Senior Product Security Architect

Cubic Corporation

Hyderabad

On-site

INR 3,500,000 - 7,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cubic Corporation in Hyderabad, India, seeks a Senior Product Security Architect to embed security across the product lifecycle—from design to deployment—enabling secure innovation at scale.

You will partner with engineering, DevOps, cloud, and business leaders to mitigate risks while accelerating delivery, define the product security strategy, and lead threat modeling and security assessments.

Qualifications

  • 12–18+ years of experience in Application Security, Product Security or Security Architecture.
  • Hands-on expertise in secure application design and threat modeling.
  • Proven leadership in a Senior Manager/Architect level role.

Responsibilities

  • Define product security architecture frameworks and standards.
  • Embed Secure SDLC (SSDLC) across design, development, testing and deployment.
  • Lead threat modeling, risk assessments and vulnerability management.
  • Drive DevSecOps adoption, automation and CI/CD security controls.
  • Ensure compliance with ISO 27001, SOC 2 and data privacy regulations.
  • Mentor and guide Product Security Engineers and Architects.

Skills

Threat modeling
Security architecture
DevSecOps
Leadership

Education

Bachelor’s in Computer Science
Master’s in Information Security
Engineering degree

Job description

Business Unit:

Cubic Transportation Systems

Company Details:

When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.

We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Cubic.com.

Job Details:

Summary: We are seeking a highly experienced Senior Product Security Architect who will be responsible for embedding security into the entire product lifecycle—from design to deployment—while enabling secure innovation at scale.

As a senior leader, you will define the product security strategy, influence engineering practices, and ensure security is a core pillar of product development rather than an afterthought. You will partner closely with engineering, DevOps, cloud, and business leaders to mitigate risks while accelerating delivery.

Key Responsibilities

1. Security Architecture & Strategy

  • Define and implement product security architecture frameworks and standards.
  • Integrate Security-by-Design and Privacy-by-Design principles into all products.
  • Establish a long-term product security roadmap aligned with business strategy.
  • Lead threat modeling and risk assessments for critical products and platforms.
  • Provide architectural guidance for:
    • Cloud-native applications
    • Microservices and APIs
    • SaaS and enterprise platforms
  • Drive adoption of security frameworks including:
    • NIST Secure Software Development Framework (SSDF) – NIST SP 800-218
    • OWASP SAMM (Software Assurance Maturity Model)

2. Secure SDLC (Software Development Lifecycle)

  • Design and implement a Secure SDLC (SSDLC) framework across teams.
  • Embed security controls across:
    • Design
    • Development
    • Testing
    • Deployment
  • Define and enforce:
    • Secure coding standards
    • Secure coding practices
    • DevSecOps integration
  • Ensure adoption of:
    • SAST (Static Application Security Testing)
    • DAST (Dynamic Application Security Testing)
    • SCA (Software Composition Analysis)
    • Penetration Testing frameworks
  • Establish security maturity metrics and SSDLC governance aligned with NIST SSDF and OWASP SAMM.

3. Engineering & DevSecOps Enablement

  • Partner with engineering teams to shift security left.
  • Drive adoption of DevSecOps practices and automation.
  • Enable teams through:
    • Security training and awareness
    • Secure coding guidelines
    • Architecture reviews
  • Implement and govern CI/CD security controls and secure pipeline configurations.
  • Act as a trusted advisor to engineering leadership.

4. Vulnerability & Risk Management

  • Oversee application and product vulnerability management lifecycle.
  • Define prioritization frameworks based on:
    • Risk severity
    • Business impact
  • Drive remediation programs and SLAs.
  • Conduct:
    • Penetration testing reviews
    • Security assessments
  • Interpret and prioritize findings from SAST, DAST, SCA, and penetration testing activities.

5. Cloud & Infrastructure Security

  • Provide security architecture for:
    • AWS / Azure / GCP environments
    • Container security (Docker, Kubernetes)
  • Define controls for:
    • Identity & Access Management (IAM)
    • Data protection (encryption, key management)
    • Network security

6. Regulatory Compliance & Governance

  • Ensure compliance with industry standards:
    • ISO 27001
    • SOC 2
    • GDPR and Data Privacy regulations
  • Implement audit-ready processes and controls.
  • Partner with risk teams for:
    • Security audits
    • Compliance assessments

7. Leadership & Stakeholder Management

  • Lead and mentor a team of Product Security Engineers and Architects.
  • Collaborate with:
    • Engineering leadership
    • Product management
    • Cybersecurity teams
    • External vendors and partners
  • Influence senior stakeholders on:
    • Security investments
    • Risk posture
    • Strategic priorities

8. Incident Readiness & Response

  • Support security incident handling related to product vulnerabilities.
  • Define incident response playbooks for product security risks.
  • Conduct post-incident reviews and improve controls.

Required Qualifications

Education

  • Bachelor’s or Master’s degree in:
    • Computer Science
    • Information Security
    • Engineering
    • Related field

Experience

  • 12–18+ years of experience in:
    • Application Security
    • Product Security
    • Security Architecture
    • DevSecOps
  • Proven experience in a leadership role (Senior Manager / Architect level).
  • Hands-on expertise in:
    • Secure application design
    • Threat modeling
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Architect
Senior Product Security Architect

Cubic Corporation • Telangana

On-site
INR 2,000,000 - 3,000,000
Product Security Architect (Threat Modeling)
Product Security Architect (Threat Modeling)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 3,000,000 - 5,000,000
Security Architecture and ENGINEERING
Security Architecture and ENGINEERING

TOCUMULUS • Bengaluru

On-site
INR 1,600,000 - 2,400,000
Product Security Engineer
Product Security Engineer

Hugohub • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Lead- Product Security
Lead- Product Security

42 Gears Mobility Systems • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Cybersecurity Subject Matter Expert
Cybersecurity Subject Matter Expert

Sunovaa Tech • Pune District, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Cyber Security Architect
Cyber Security Architect

Good co India • India

On-site
INR 2,400,000 - 4,800,000
CyberSecurity Architect
CyberSecurity Architect

Siemens Mobility • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

GAVS Technologies • Chennai District

On-site
INR 2,000,000 - 3,000,000