Sr. Lead Cybersecurity Architect - Product Security Lead
Job responsibilities
- Partnering with the Engineering & Architecture teams to integrate security controls into platforms (e.g. AWS, GCP, etc. based public cloud platforms) and frameworks
- Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
- Assisting and guiding engineering teams in the secure development of infrastructure services and products
- Ensure security considerations are delivered in compliance with firmwide technology controls from the start and throughout the Software Development Lifecycle.
- Developing extensible security solutions aligned to the product strategy in future developments.
- Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
- Work with architects and developers to design and implement secure code practices, conduct code reviews, and ensure security is embedded in the design.
- Knowledge of emerging security threats, vulnerabilities, and trends relevant to our products.
- Drive security education and awareness across the organization, ensuring all employees understand their role in maintaining product security.
- Provide regular security updates to senior management and stakeholders, translating technical security issues into business impact.
- Improve security policies, standards, and guidelines related to product security.
- Stay up-to-date with the latest security technologies, trends, and best practices.
Required qualifications, capabilities, and skills
- Formal Training or certification with 5 + years of experience in a product security role with a track record of driving security initiatives.
- Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
- Experience with threat modeling, risk assessment, and vulnerability management.
- Proficiency in programming languages (e.g., Java, Python, C/C++).
- Familiarity with security frameworks (e.g., NIST Cybersecurity Framework) and industry regulations (e.g., GDPR, HIPAA).
- Excellent leadership, communication, and interpersonal skills.
- Security certifications such as CISSP, CISM, or relevant certifications are a plus.
- Cloud Certifications such as AWS Solutions Architecture Associate/Professional, AWS Security Specialty
- Experience with DevSecOps practices and tools is desirable.
- Ability to lead and work effectively in a cross-functional team environment.
Strong problem-solving skills and the ability to think critically
Preferred qualifications , capabilities and skills
- Security certifications (e.g., CISSP, CISM, CCSP) and/or cloud certifications (e.g., AWS Security Specialty, Solutions Architect).
- Experience with DevSecOps and continuous compliance controls (policy-as-code, guardrails, automated evidence).
#CTC