Job Title: Information Security Architect
Location: Bangalore, India
Department: Information Security / IT Risk
Job Type: Full-time/Hybrid
Experience Level: 10+ years in Information Security (including 3–5 years in architecture roles)
About the Role:
We are seeking an experienced and highly skilled Information Security Architect to lead the design, implementation, and governance of enterprise-wide security solutions. Based in Bangalore, the ideal candidate will work closely with global IT, DevOps, compliance, and business teams to ensure the organization’s systems and data are secure, scalable, and compliant with industry standards and regulations.
Key Responsibilities:
- Develop and maintain enterprise security architecture strategy and standards aligned with business goals.
- Evaluate, recommend, and architect security solutions across cloud (AWS/Azure/GCP), on-premise, and hybrid environments.
- Provide expert guidance on secure design and threat modeling across applications, infrastructure, networks, and data.
- Define and enforce security policies, reference architectures, and secure coding practices.
- Conduct architecture risk assessments and security design reviews for new projects and technologies.
- Collaborate with Engineering, DevOps, and IT teams to implement secure SDLC and CI/CD pipelines.
- Stay up to date on emerging threats, vulnerabilities, and regulatory changes, and guide proactive defense strategies.
- Contribute to incident response and forensics investigations as a senior escalation point.
- Lead or support internal and external audits, including ISO 27001, SOC 2, and regulatory compliance (e.g., GDPR, HIPAA).
Key Requirements:
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
- 10+ years of experience in information security with at least 3–5 years in a security architecture role.
- Strong understanding of security architecture frameworks such as SABSA, TOGAF, or NIST.
- Expertise in identity and access management (IAM), encryption, network security, and data loss prevention (DLP).
- Hands-on experience with cloud security (AWS, Azure, or GCP), containers (Docker/Kubernetes), and infrastructure-as-code (Terraform, CloudFormation).
- Knowledge of security tools like SIEM, WAF, CASB, SAST/DAST, and vulnerability management.
- Professional certifications preferred: CISSP, CCSP, CISM, SABSA, AWS/Azure Security Specialty.
- Excellent communication and stakeholder management skills.
Preferred Qualifications:
- Experience in regulated industries (Finance, Healthcare, Telecom, etc.).
- Familiarity with Zero Trust Architecture and Secure Access Service Edge (SASE).
- Experience in mentoring junior security engineers and architects.