Description :
Job Role : Information Security Architect.
Experience Required : 7 to 9 years.
Location : Bangalore (Hybrid).
Key Responsibilities :
- Design and review secure system and application architectures.
- Conduct and support threat modeling and risk assessment activities.
- Identify and document attack surfaces and potential vulnerabilities during design reviews.
- Act as a security advisor to project and architecture teams throughout the development lifecycle.
- Capture and manage technical security observations in SD Elements, ensuring traceability and remediation tracking.
- Engage with stakeholders across development, architecture, and infrastructure teams to embed security into solution design.
- Align solutions with enterprise architecture frameworks (e.g., TOGAF, SABSA) and internal security policies.
- Participate in architecture review boards and security governance forums.
- Support secure design validation for cloud, on-prem, and hybrid environments.
Required Skills and Experience :
79 years of experience in information security or architecture-related roles.Strong background in application security, secure development lifecycle, and architecture design.Hands-on experience in threat modelling and understanding of attack surfaces.Past experience in VAPT execution and remediation handling (even though not part of the current responsibilities).Experience using SD Elements for security requirements and issue tracking is mandatory.Proficient in architecture frameworks such as TOGAF, SABSA, or NIST.Good knowledge of cloud security (preferably Azure) and secure DevOps practices.Excellent communication skills to collaborate with global stakeholders and technical teams.Tools and Frameworks Knowledge (Preferred) :
Tools :
SD Elements, Threat Modeller, Microsoft Defender, architectural modelling tools.Frameworks :
TOGAF, SABSA, NIST CSF, OWASP Top 10, MITRE ATT & CK.Certifications : Mandatory :
CISSP (Certified Information Systems Security Advantage :AZ-500 (Microsoft Azure Security Technologies), CCSP (Certified Cloud Security Professional).(ref : hirist.tech)