Talent.com
This job offer is not available in your country.
Principal Security Architect

Principal Security Architect

Kshema General Insurance LimitedDelhi, India
5 days ago
Job description

POSITION OVERVIEW

Kshema General Insurance is seeking a Principal Security Architect to join our security organization. This role reports to the Chief Technology Officer and will play a critical role in shaping and executing Kshema’s cloud security strategy across a diverse and evolving technology landscape.

The role will work closely with development teams, product teams, and others across the organization to integrate security into the delivery lifecycle from design through deployment. This person will play a key role in defining security requirements, performing application security assessments, and providing developers with remediation advice.

DUTIES & RESPONSIBILITIES

Work independently with developers, system / network engineers, product owners, and other colleagues to ensure secure design, development, and implementation of applications, infrastructure, and networks.

Participate in engineering projects to identify threats and vulnerabilities in our cloud infrastructure and system architectures.

Define cybersecurity requirements and security concepts and work with engineering teams to successfully deliver business solutions.

Perform security design reviews of cloud systems, and networks.

Provide remediation guidance and recommendations to systems administrators.

Develop enterprise standards based on security best practices.

Demonstrate deep expertise in Azure and either AWS or Google Cloud Platform (GCP), including native security services.

Design secure cloud-native and hybrid architectures, including zero trust, micro-segmentation, and secure access patterns.

Design secure VPCs, firewalls, VPNs, and secure connectivity between on-prem and cloud.

Protect data utilizing Encryption (at rest, in transit, and in use), key management (KMS, HSM), tokenization, and data classification.

Integrate security into CI / CD pipelines, infrastructure as code (IaC) scanning, and container security (e.g., Kubernetes, Docker).

Conduct threat modeling, risk assessments, and security reviews for cloud workloads.

Define and drive cloud security strategy aligned with business and IT goals.

Create architecture diagrams, security design documents, and architecture decision records.

Closely work with CISO in evaluating technology initiatives and projects to determine advanced cybersecurity requirements and controls necessary to comply with company policies, standards, and industry best practices.

Demonstrate best practices, create proofs-of-concept and propose solutions to Customer’s Software and Infrastructure Architects and provide strategic technical direction across the development and infrastructure teams.

Build and sustain good working relationships with development and infrastructure teams and involve them in the overall application and cloud Security Technology strategy.

Develop security related user stories and product specific threat models for products, as well as CI / CD pipelines and infrastructure-as-code.

Develop technical security requirements for the business and see them through the development lifecycle.

Collaborate with business contacts to ensure third-party cloud applications comply with our standards, controls, policies, and principles.

MINIMUM REQUIREMENTS

Bachelor’s degree in computer science or business with emphasis in IT or the equivalent combination of education, training and work experience.

Requires 10+ years of experience in cybersecurity, with at least 4 years focused on cloud security architecture.

Proven experience designing and securing solutions in Azure (preferred), and / or AWS

Deep understanding of cloud-native services, container security (e.g., Kubernetes), and serverless architectures.

Strong knowledge of DevSecOps practices and secure software development lifecycle (SSDLC).

Familiarity with compliance frameworks such as NIST, ISO 27001, SOC 2, HIPAA, and PCI-DSS.

Advanced knowledge of IAM principles, federation, SSO, RBAC / ABAC, and privileged access management.

Relevant certifications such as AWS Certified Security – Specialty, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, or CCSP.

Hands-on practical experience high quality threat models and knowledge of MITRE framework, STRIDE framework and kill chains.

Deep understanding of network protocols, operating systems, databases, applied cryptography, least privilege, zero trust principles, identity & access management, and other core information security concepts.

Hands-on experience in performing threat modeling for applications, identifying threats, and suggesting optimal mitigation strategies.

Strong understanding of threat modeling methodologies (e.g., STRIDE, DREAD, PASTA).

Proficiency in using threat modeling tools (e.g., Microsoft Threat Modeling Tool, Threat Modeler, OWASP Threat Dragon).

In-depth knowledge of common security vulnerabilities (e.g., OWASP Top Ten, CVEs) and attack vectors.

PREFERRED EXPERIENCE

Experience in regulated industries (e.g., financial services, insurance, healthcare).

Strong communication and leadership skills, with the ability to influence technical and non-technical stakeholders.

Experience leading security architecture programs or initiatives at the enterprise level.

Experience with Container security platforms.

Experience incorporating security policy into Infrastructure as Code.

Create a job alert for this search

Principal Architect • Delhi, India

Related jobs
  • Promoted
Threat Intelligence Lead

Threat Intelligence Lead

ResecurityNew Delhi, Delhi, India
Resecurity is an American cybersecurity company based in Los Angeles, California.They specialize in providing next-generation endpoint protection and intelligence-driven cybersecurity solutions to ...Show moreLast updated: 30+ days ago
  • Promoted
Lead DFT Engineer

Lead DFT Engineer

ACL DigitalMeerut, IN
Semiconductors / ASIC / SoC Design.DFT architecture, planning, and implementation across complex SoC / ASIC designs.As a technical leader, you will mentor junior engineers, collaborate with cross-fun...Show moreLast updated: 30+ days ago
  • Promoted
Senior Security Consultant

Senior Security Consultant

Claranet IndiaDelhi, IN
Founded at the beginning of the dot.CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP)...Show moreLast updated: 30+ days ago
  • Promoted
Cyber Security Specialist

Cyber Security Specialist

Tiger AdvisoryMeerut, IN
Tiger Advisory provides premier cybersecurity consulting services, helping clients manage risks, strengthen resilience, and achieve compliance in an ever-evolving digital landscape.Our mission is t...Show moreLast updated: 10 days ago
  • Promoted
Information Technology Governance Consultant

Information Technology Governance Consultant

INSPYR SolutionsMeerut, IN
Job Opening : Governance, Risk & Compliance (GRC) Analyst – Level 2 / 3.Governance, Risk, and Compliance (GRC) Analyst.SaaS applications while helping define governance frameworks and risk processes.S...Show moreLast updated: 15 days ago
  • Promoted
Cyber Security Consultant

Cyber Security Consultant

Paramount Computer SystemsMeerut, IN
As a IAM Consultant in Access Management, your role will involve : .Designing, implementing, optimizing and supporting.IAM) solutions for enterprise clients. Single Sign-On (SSO), Multi-Factor Authent...Show moreLast updated: 10 days ago
  • Promoted
IT / Computer security Analyst as Admin Executive

IT / Computer security Analyst as Admin Executive

KMM Infotech Solutions Private LimitedMeerut, IN
Job Title : IT / Computer Security Analyst as Admin Executive.We are seeking a proactive, detail-oriented .Security Consultant in driving key security initiatives across the organization.This role i...Show moreLast updated: 20 days ago
  • Promoted
Senior Engineer - OT Security

Senior Engineer - OT Security

Network IntelligenceDelhi, India
Experience with ICS systems and ICS security industry practices with exposure to Operational technologies.Minimum 3 years with supporting PLC, DCS, SIS, HMI or SCADA systems.Experience supporting a...Show moreLast updated: 5 days ago
  • Promoted
Senior Security Architect

Senior Security Architect

ValueLabsDelhi, India
Dear Candidate, we are hiring Application Security +Dev Sec Ops Architect for Chennai location.Please find below JD and if you are interested , do share resume to below email id.Kubernetes / Open Shi...Show moreLast updated: 5 days ago
  • Promoted
Security Researcher

Security Researcher

Altered SecurityMeerut, IN
Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information secu...Show moreLast updated: 30+ days ago
  • Promoted
L3 Server Engineer – Major Incident Management

L3 Server Engineer – Major Incident Management

Nextbridge IT SolutionsMeerut, IN
Nextbridge IT Solutions is a US-based IT solution firm specializing in connecting exceptional talent with organizations driving transformation in infrastructure, cloud, and emerging technologies.We...Show moreLast updated: 22 days ago
  • Promoted
Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA)

Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA)

SentinelMeerut, IN
Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA).The security function of a world renowned manufacturing organisation for power tools is seeking a Saviynt IGA Engineer ...Show moreLast updated: 14 days ago
  • Promoted
Security Engineer (Red Team)

Security Engineer (Red Team)

Crossing HurdlesMeerut, IN
Your focus will be to uncover vulnerabilities, prompt-injection pathways, and data-exfiltration risks before adversaries do. Design and automate multi-turn attacks involving browser, terminal, and A...Show moreLast updated: 10 days ago
  • Promoted
Security Consultant

Security Consultant

World Wide TechnologyDelhi, IN
Be the primary lead in cybersecurity delivery engagements for a wide variety of clients in different industry verticals.Evaluate and recommend security strategies for networks, systems, operations,...Show moreLast updated: 10 days ago
  • Promoted
Senior Penetration Tester

Senior Penetration Tester

Vista Applied Solutions Group IncMeerut, IN
Client is looking for Senior PenTester and this is remote position from India.Security and Penetration Testing.OSCP Certification - Industry-standard credential demonstrating practical penetration ...Show moreLast updated: 10 days ago
  • Promoted
Cyber Security Engineer

Cyber Security Engineer

Paramount Computer SystemsMeerut, IN
Identity Governance and Administration (IGA).The role involves designing, implementing, and supporting enterprise-grade IGA solutions to ensure secure, efficient, and compliant identity lifecycle m...Show moreLast updated: 10 days ago
  • Promoted
Program / Project Manager – Cybersecurity

Program / Project Manager – Cybersecurity

AiiR ResponseMeerut, IN
AiiR Response specializes in AI-driven breach response and extortion management, automating negotiations, investigations, and recovery to significantly reduce incident costs and response times.With...Show moreLast updated: 22 days ago
  • Promoted
JD Edwards Security Consultant

JD Edwards Security Consultant

IT ConsultingDelhi, IN
JD Edwards Security Consultant.Collaborate with global business stakeholders to understand business processes and security requirements within JD Edwards. Design and document standardized user roles...Show moreLast updated: 22 days ago