Senior Software- Security Agent Architect

SISA

Mumbai

On-site

INR 350,000 - 650,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SISA in Mumbai seeks a Senior/Principal Architect to own end-to-end architecture for an agent-based endpoint security platform spanning the Go runtime agents, on-premise management, telemetry relay, and cloud backend.

This hands-on role requires reviewing code and low-level design, guiding kernel-level drivers, securing device communications, and shaping multi-tenant, PCI-DSS‑compliant deployments across customer premises and cloud.

Qualifications

  • 15–20+ years in software engineering with 8+ years in architecture or senior leadership.
  • Deep expertise in distributed systems and agent-based security products (EDR/XDR) is strongly preferred.
  • Strong hands-on Go experience with C/C++ for kernel-level guidance.
  • Experience with kernel internals (Windows/Linux) and OS hooking for real-time monitoring.

Responsibilities

  • Define architecture for kernel-level components and interactions with user-mode runtime.
  • Own architectural decisions across endpoint, on-premise components, and cloud backend.
  • Define control-plane and data-plane transport strategies (gRPC/Protobuf/HTTP/2).
  • Ensure multi-tenant SaaS design with PCI-DSS considerations and secure deployments.
  • Lead architecture reviews, mentor engineers, and engage with enterprise clients.

Skills

Go
C/C++
Kernel drivers
gRPC
mTLS
PCI-DSS
Security architecture
Distributed systems
Leadership
Cloud/AWS

Education

Bachelor's/Master's in CS/ENG

Job description

About The Role
We build a distributed, agent-based endpoint security platform for the payment ecosystem, combining an endpoint agent (a core runtime plus pluggable security modules, built entirely in Go), an on-premise management component deployed at the customer site, a local telemetry relay component, and a cloud backend. Kernel-level components that hook into the OS are written in C/C++, as is standard for driver-level development. We're looking for a Senior/Principal Architect to own end-to-end architecture across this stack — from the control-plane protocol on the endpoint, through on-premise components, to secure egress into the cloud backend. This is a hands-on architecture role: you will be expected to review code and low-level design, not just produce diagrams.
About The Role
We build a distributed, agent-based endpoint security platform for the payment ecosystem, combining an endpoint agent (a core runtime plus pluggable security modules, built entirely in Go), an on-premise management component deployed at the customer site, a local telemetry relay component, and a cloud backend. Kernel-level components that hook into the OS are written in C/C++, as is standard for driver-level development. We're looking for a Senior/Principal Architect to own end-to-end architecture across this stack — from the control-plane protocol on the endpoint, through on-premise components, to secure egress into the cloud backend. This is a hands-on architecture role: you will be expected to review code and low-level design, not just produce diagrams.
Key Responsibilities
  • Define the architecture for kernel-level components on the endpoint (drivers/kernel modules used for real-time monitoring, hooking, or enforcement), including their interaction with and isolation from the user-mode agent runtime and its modules.
  • Own architectural decisions across the full platform: the endpoint agent (core runtime + pluggable security modules), the on-premise management component, the on-premise telemetry relay component, and the cloud backend.
  • Define and evolve the control-plane (gRPC/Protobuf) and data-plane transport strategy between the endpoint agent, the on-premise management component, and the telemetry relay component.
  • Own version compatibility strategy across independently-versioned components (agent, core runtime, modules, management component, cloud backend).
  • Design secure, outbound-only, multi-tenant deployment topology — mTLS and certificate lifecycle management, IPSec/VPN egress design — suitable for PCI-regulated payment industry clients.
  • Own the client‑facing security architecture narrative: per-hop network/port/protocol documentation, PCI-DSS scoping discussions, and direct engagement with client InfoSec/audit teams.
  • Architect the security-module lifecycle: subscription entitlement enforcement, binary distribution, staged/canary rollout and rollback, resource governance across concurrently running modules, and failure isolation so a single module cannot take down the core agent runtime.
  • Define HA/DR strategy for on-premise components deployed inside customer environments that are not directly operated by us.
  • Evaluate and decide on the design of any bi-directional channel between the cloud backend and on-premise components, ensuring it doesn't undermine the outbound-only security posture documented to clients.
  • Run architecture reviews, mentor senior and mid-level engineers, and own technical roadmap and tech-debt prioritization.
  • Represent the company in high-stakes architecture and security review calls with enterprise client stakeholders.
Required Technical Skills
  • 15–20+ years in software engineering, including 8+ years in architecture or senior technical leadership roles.
  • Deep expertise in distributed systems design; direct experience with agent-based security products (EDR/XDR, endpoint protection, DLP, or similar) is strongly preferred.
  • Strong hands‑on background in Go — the agent runtime and its modules are built entirely in Go — plus working proficiency in C/C++ for reviewing and guiding kernel-level driver work. Able to review code and low‑level design in depth, not just at a diagram level.
  • Solid understanding of kernel-level/OS-internals development (e.g., Windows kernel drivers/minifilters, Linux kernel modules/eBPF) sufficient to architect and review how endpoint agents hook into the OS for real-time monitoring or enforcement, and to reason about the security and stability risks that come with it.
  • Expert‑level knowledge of gRPC, Protocol Buffers, and HTTP/2, including streaming and multiplexing trade‑offs at scale.
  • Strong grasp of mTLS/PKI design: certificate issuance, rotation, and revocation for large, distributed fleets.
  • Solid understanding of network security fundamentals: IPSec/VPN tunnel design, NAT/firewall traversal, and outbound‑only architecture patterns for customer‑premise deployments.
  • Experience architecting multi‑tenant SaaS products with components deployed partially on customer premises, not just in a vendor‑controlled cloud.
  • Working knowledge of PCI-DSS (or equivalent frameworks such as ISO 27001/SOC 2) and their direct implications on network and data‑flow architecture.
Preferred / Nice To Have
  • Prior architecture role at a cybersecurity product company (EDR, XDR, SIEM, DLP, or breach‑and‑attack simulation).
  • Direct exposure to active security‑testing or breach‑and‑attack simulation style products.
  • Cloud infrastructure experience (AWS/Azure/GCP) for the backend/cloud side of the platform.
  • Track record presenting architecture directly to enterprise client security/audit teams.
What Success Looks Like In This Role
  • A documented, defensible security architecture narrative that survives client InfoSec audits without surprises.
  • A version compatibility and module‑lifecycle strategy that prevents fleet-wide breakage from a single bad rollout.
  • A mentored engineering team capable of making sound architectural trade‑offs independently.
Education

Bachelor's or Master's degree in Computer Science, Engineering, or a related field. Equivalent hands‑on experience will be given full weight over formal qualifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software- Security Agent Architect
Senior Software- Security Agent Architect

Sisainfosec • Mumbai

On-site
INR 500,000 - 900,000
SISA Information Security - Senior/Principal Architect - Endpoint Detection & Response
SISA Information Security - Senior/Principal Architect - Endpoint Detection & Response

SISA • Mumbai

On-site
INR 3,500,000 - 5,500,000
Principal Software Engineer- Agent Developer
Principal Software Engineer- Agent Developer

SISA • Delhi

On-site
INR 4,000,000 - 6,500,000
Senior Infrastructure Security Architect
Senior Infrastructure Security Architect

Radware • Chennai District

On-site
INR 3,500,000 - 6,000,000
Security Architecture and ENGINEERING
Security Architecture and ENGINEERING

TOCUMULUS • Bengaluru

On-site
INR 1,600,000 - 2,400,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Delhi

On-site
INR 2,500,000 - 4,500,000
Security Architect (Bangalore, India)
Security Architect (Bangalore, India)

AiPrise • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Pune District

On-site
INR 4,000,000 - 7,000,000
Lead Engineer - Security
Lead Engineer - Security

Cloudcover Consultancy • Pune District

On-site
INR 1,800,000 - 3,200,000
Security Solutions Architect (Enterprise, Cloud, OT & AI Security)
Security Solutions Architect (Enterprise, Cloud, OT & AI Security)

PeopleBridge Partners (PBP) • Mumbai

On-site
INR 2,500,000 - 3,500,000
Direct impact on enterprise architecture
Opportunities for professional growth
Blend of strategy and hands-on work