Principal Product Architect
NewBe an early applicantPrincipal
Product Architect – Cybersecurity
Location: Hyderabad, India (On-site) Department: Product & Engineering
Experience: 12+ years, including significant
time in cybersecurity product companies
About
NopalCyber
NopalCyber
is an AI-native cybersecurity company that combines offensive and defensive
security through its proprietary Exposure Reduction Platform and AI-powered
Cyber Intelligence Quotient (CIQ) risk-scoring engine, enabling organizations
to continuously discover, validate, prioritize, detect, respond to, and
remediate cyber risk across complex enterprise environments.
Role
Summary
We're
looking for a Principal Product Architect to own the technical architecture
behind NopalCyber's integrated product portfolio — from our External Attack
Surface Management to Internal Attack Surface Management to detection and
response platform. This is a hands-on, high-influence role for someone who has
spent their career inside cybersecurity product companies, understands how
attackers and defenders actually operate, and knows how to translate that
understanding into scalable, secure, and elegant product architecture. You'll
set technical direction across multiple product lines, partner closely with
Product Management and Engineering leadership, and mentor architects and senior
engineers across the org.
Key
Responsibilities
- Own end-to-end architecture for
Nopal360 (e.g., MXDR/SOC platform, EASM, IASM GRC tooling), from concept
through scale, ensuring designs are secure, resilient, and built for
multi-tenant, high-volume telemetry environments.
- Translate a deep, current
understanding of the threat landscape — adversary tactics, techniques, and
procedures (TTPs), emerging attack vectors, and the evolving regulatory
environment — into product and platform decisions that keep NopalCyber
ahead of the threats it defends against.
- Define architectural standards,
patterns, and guardrails (data ingestion pipelines, detection engines, API
design, identity and access controls, cloud infrastructure) that scale
across the Nopal 360° platform.
- Partner with Product Management
to shape roadmap decisions, evaluating technical feasibility, security
implications, and build-vs-buy tradeoffs for new capabilities.
- Lead architecture reviews and
design decisions in collaboration with engineering teams, ensuring
consistency across services while leaving room for team-level autonomy.
- Evaluate and integrate
third-party threat intelligence feeds, detection frameworks (e.g., MITRE
ATT&CK), and security tooling into the product architecture.
- Act as a technical authority in
conversations with customers, prospects, and partners on product
architecture, security posture, and platform capabilities.
- Mentor senior engineers and
product architects, raising the technical bar across the organization.
- Stay current on the threat
landscape and competitive product landscape, and proactively bring in
ideas that keep NopalCyber's products differentiated and effective.
What
You'll Bring
- 12+ years of experience in
software/security engineering, with a substantial portion spent at
cybersecurity product companies (e.g., EDR/XDR, SIEM/SOAR, vulnerability
management, CTEM, cloud security platforms).
- A track record of architecting
cybersecurity products end-to-end — not just consuming security tools, but
having built them.
- Strong, current understanding
of the threat landscape: attacker TTPs, the MITRE ATT&CK framework,
common attack vectors across network, cloud, identity, and application
layers, and how detection and response systems are designed to counter
them.
- Proven experience designing
distributed, cloud-native architectures that handle high-volume,
high-velocity security telemetry (logs, alerts, events) with an emphasis
on reliability and low-latency detection.
- Deep knowledge of security
architecture principles: zero trust, defense in depth, secure-by-design
development, identity and access management, and data protection.
- Hands-on fluency with cloud
platforms (AWS, Azure, or GCP), modern data pipelines, and API-first
design.
- Experience partnering directly
with Product Management and executive stakeholders to shape roadmap and
make architectural tradeoffs under real business constraints.
- Excellent communication skills
— able to explain complex technical and threat concepts clearly to
engineers, product managers, customers, and leadership alike.
Nice to
Have
- Experience architecting SOC
platforms, MXDR/managed detection services, or attack surface management
tooling specifically.
- Prior experience in an
offensive security context (red team, penetration testing, or adversary
simulation) that informs how you think about defensive product design.
- Relevant industry
certifications (OSCP, CISSP, GCIA, GCTI, or similar).
- Experience building or scaling
products at a high-growth cybersecurity startup.
What We
Offer
- The chance to shape the core
architecture of a cybersecurity platform used to protect real
organizations, from the ground up.
- A close-knit, high-trust team
where architectural decisions have direct, visible impact.
- Competitive compensation,
benefits, and growth path commensurate with a principal-level technical
role.
- A culture built around
NopalCyber's mission: making elite, affordable security accessible to
every organization, regardless of size.