10,000+ Active Jobs
|
500+ Hiring Companies
|
100% Verified Jobs
India
HiringGo Logo
Companies
Exclusive Jobs
Jobs Login
Homeโ€บCompaniesโ€บGlobalLogicโ€บProduct Security Architect IRC286354
G

Product Security Architect IRC286354

GLOBALLOGIC ACTIVELY HIRING
๐Ÿ“LOCATIONNoida
๐Ÿ“ˆEXPERIENCE10 to 14 Yrs
๐Ÿ•˜TYPEFull time
๐ŸฅIndustryIT Services & Consulting
๐Ÿ—“POSTED20 Aug 2026

01Overview

Description Looking for a Product Security Architect to lead our offensive and defensive security strategies. You will be embedded with engineering teams to ensure our products are resilient against sophisticated attacks. This is a hands-on role: you will write security-centric code, conduct deep-dive penetration tests, and automate threat detection within our pipelines. You are not just an auditor; you are a builder who solves security challenges with engineering solutions. Requirements Technical Mastery Required Security Frameworks: OWASP ASVS, SAMM, NIST 800-53, and Cloud Security Alliance (CSA). Offensive Tools: Burp Suite Professional, Metasploit, Kali Linux, Nmap, and Postman (for API hacking). Secure Coding: Deep knowledge of vulnerabilities in Java/.NET and how to prevent them (e.g., SQLi, XSS, CSRF, SSRF). Cloud Security: Securing Kubernetes (K8s) secrets, IAM Least Privilege, and Cloud Workload Protection (CWPP). Identity/Auth: Expert-level understanding of JWT, OAuth2, OpenID Connect, and WebAuthn/FIDO2. Qualifications Experience: 10+ years in Cybersecurity or Software Engineering, with 4+ years specifically in Product Security or Application Security (AppSec). Mindset: A Breaker mentality balanced with a Builders empathy; the ability to explain why a vulnerability matters to a product owner. Certifications: OSCP (Offensive Security Certified Professional) Communication: Ability to translate complex exploitation paths into clear risk assessments for non-technical leadership. Job responsibilities Key Responsibilities Secure Architecture & Threat Modeling Threat Modeling: Lead structured threat modeling sessions (using STRIDE or PASTA) during the design phase to identify architectural flaws before a single line of code is written. Architecture Reviews: Conduct deep-dive security reviews of system designs, focusing on authentication (OIDC/SAML), authorization (RBAC/ABAC), and data isolation. Security Scaffolding: Build and maintain shared security libraries (e.g., standardized encryption wrappers, input validation modules) for use by all engineering teams. Offensive Security & Exploitation In-House Pentesting: Perform regular manual penetration tests on web applications, APIs, and cloud infrastructure to identify logic flaws that automated tools miss. Exploitation Research: Develop PoC (Proof of Concept) exploits for discovered vulnerabilities to demonstrate impact to stakeholders and validate remediation. Bug Bounty Management: Oversee the bug bounty program, triaging reports and working directly with developers on high-severity fixes. Secure Coding & SDLC Integration Secure Code Review: Review high-risk pull requests (e.g., changes to auth, payments, or crypto) to ensure compliance with OWASP Top 10 and ASVS. Automation (DevSecOps): Integrate and fine-tune SAST, DAST, and SCA tools into the CI/CD pipeline to reduce false positive fatigue for developers. Vulnerability Remediation: Dont just find bugswrite the code to fix them. Pair-program with engineers to implement secure patterns. What we offer Exciting Projects: We focus on industries like High-Tech, communication, media, healthcare, retail and telecom. Our customer list is full of fantastic global brands and leaders who love what we build for them. Collaborative Environment: You Can expand your skills by collaborating with a diverse team of highly talented people in an open, laidback environment or even abroad in one of our global centers or client facilities! Work-Life Balance: GlobalLogic prioritizes work-life balance, which is why we offer flexible work schedules, opportunities to work from home, and paid time off and holidays. Professional Development: Our dedicated Learning & Development team regularly organizes Communication skills training(GL Vantage, Toast Master),Stress Management program, professional certifications, and technical and soft skill trainings. Excellent Benefits: We provide our employees with competitive salaries, family medical insurance, Group Term Life Insurance, Group Personal Accident Insurance , NPS(National Pension Scheme ), Periodic health awareness program, extended maternity leave, annual performance bonuses, and referral bonuses. Fun Perks: We want you to love where you work, which is why we host sports events, cultural activities, offer food on subsidies rates, Corporate parties. Our vibrant offices also include dedicated GL Zones, rooftop decks and GL Club where you can drink coffee or tea with your colleagues over a game of table and offer discounts for popular stores and restaurants! About GlobalLogic GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the worlds largest and most forward-thinking companies. Since 2000, weve been at the forefront of the digital revolution helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in .

02What you'll need

Experience
10 to 14 Yrs
Employment Type
Full time
Programming languages
Secure CodingCloud SecurityThreat ModelingArchitecture ReviewsSecurity FrameworksOffensive ToolsIdentityAuthOffensive SecurityExploitation ResearchBug Bounty Management

03About GLOBALLOGIC

IT Services & ConsultingIndustry
Full timeEmployment Type
NoidaLocation
Not Disclosed ยท salary hidden by employer
10 to 14 Yrs ยท Noida
Applications are reviewed directly by the hiring team.
Role Snapshot
Work ModeNot specified
Visa SponsorshipNot specified
RelocationNot specified
Job TypeFull time
Hiring StatusACTIVELY HIRING
G
GLOBALLOGIC
IT Services & Consulting
View all GLOBALLOGIC jobs โ†’
Share