Cyber Security SME

Summary

Cybersecurity SME providing architecture guidance, threat modeling, and vulnerability management across products and cloud services, partnering with engineering and DevOps to embed security-by-design throughout the SDLC.

The Cybersecurity Subject Matter Expert (SME) provides deep technical expertise, guidance, and governance for cybersecurity across products, platforms, cloud services, and software engineering initiatives. The SME partners with architects, engineering teams, DevOps, QA, product management, and cybersecurity stakeholders to ensure security-by-design principles are embedded throughout the product lifecycle.

Key Responsibilities

  • Act as the primary cybersecurity expert for assigned products, platforms, and services.
  • Provide cybersecurity architecture guidance, design reviews, and implementation recommendations.
  • Lead Threat Modeling, Threat & Risk Analysis (TRA), and cybersecurity risk assessments.
  • Drive vulnerability management, remediation tracking, and security incident support activities.
  • Coordinate penetration testing and security assessments.
  • Support secure software development lifecycle (SSDLC) implementation.
  • Guide teams on SAST, DAST, Software Composition Analysis (SCA), and SBOM governance.
  • Develop and maintain cybersecurity standards, procedures, guidelines, and secure baselines.
  • Support compliance with NIST, ISO 27001/27002, FDA Cybersecurity Guidance, and IEC 81001-5-1.
  • Provide cybersecurity training, mentoring, and technical leadership.
  • Work with geographically distributed development teams in USA, Canada, Finland, Switzerland, and India
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, or related field.
  • 8+ years of experience in software engineering, cloud engineering, platform engineering, or cybersecurity.
  • 5+ years of direct experience in product cybersecurity, application security, or security architecture.
  • Experience in regulated healthcare or medical device environments preferred.

Technical Skills

  • Application Security, Product Security, Secure SDLC
  • Threat Modeling and Risk Assessment
  • Azure/AWS Cloud Security
  • Container and Kubernetes Security
  • Identity & Access Management
  • Vulnerability Management and Incident Response
  • SAST, DAST, SCA and SBOM tools
  • OWASP Top 10, NIST, ISO 27001/27002

Preferred Certifications

  • CISSP
  • CSSLP
  • CCSP
  • CEH
  • Azure Security Engineer Associate
  • CKS

Please note the requirements for the candidates:

  • Should be open to travel to Pune for the in-person interview round
  • Willing to work in a hybrid model from the Pune office

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available