Product Security Architect (Threat Modeling) in India at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security Architect (Threat Modeling) based in India.
This role offers the opportunity to shape secure product development by embedding security principles throughout the software lifecycle.
The position focuses on threat modeling, security architecture reviews, and providing strategic guidance to engineering and product teams.
You will help teams identify risks early, design resilient applications, and implement secure solutions across modern cloud environments.
The role combines deep technical expertise with collaboration, enabling secure-by-design practices across innovative products and platforms.
You will work closely with engineering, DevOps, cloud, and infrastructure teams to improve security maturity and reduce application risks.
This is an ideal opportunity for a security professional passionate about architecture, emerging technologies, and building safer digital experiences.
The role is responsible for leading security architecture initiatives, identifying risks, and enabling secure software development practices across product teams. Key responsibilities include:
- Conduct security architecture reviews and threat modeling exercises for applications, products, services, and platform capabilities.
- Partner with engineering and product teams to identify security risks and recommend practical mitigation strategies throughout the SDLC.
- Act as a security advisor by providing guidance on secure architecture patterns, coding practices, and implementation approaches.
- Review application architectures, APIs, data flows, infrastructure designs, and deployment models to identify vulnerabilities and improve security posture.
- Assess security considerations for AI and machine learning solutions and recommend secure development approaches.
- Develop and maintain security standards, reference architectures, technical guidelines, and best practices.
- Build and enhance security automation, tooling, and workflows to improve architecture reviews and threat modeling efficiency.
- Perform application security assessments and support investigations into security concerns discovered during development.
- Create developer enablement materials, conduct security awareness sessions, and promote secure-by-design practices.
- Support security incident investigations and perform root cause analysis for application security issues.
- Collaborate with Product Security, Engineering, DevOps, Cloud, and Infrastructure teams to integrate security into development processes.
The ideal candidate has strong experience in application security, security architecture, and risk assessment, with the ability to influence engineering teams and communicate complex security concepts. Required qualifications and skills include:
- 5–8 years of experience in Application Security, Product Security, Security Architecture, or a related cybersecurity field.
- Strong understanding of Secure Software Development Lifecycle (SSDLC/SDLC) principles.
- Hands-on experience conducting threat modeling, security architecture reviews, application security assessments, and risk assessments.
- Strong knowledge of security principles including OWASP Top 10, API security, authentication, authorization, cryptography, secrets management, and secure design practices.
- Experience reviewing application architectures, cloud environments, APIs, integrations, and technical designs.
- Ability to identify, prioritize, and communicate security risks with practical remediation recommendations.
- Experience reviewing source code and understanding modern programming languages.
- Experience developing security scripts, automation tools, or workflows to improve security engineering processes.
- Familiarity with cloud platforms, especially AWS, and cloud-native application architectures.
- Knowledge of threat modeling methodologies such as STRIDE, PASTA, Attack Trees, and MITRE ATT&CK is preferred.
- Familiarity with security testing tools including SAST, DAST, SCA, IaC scanning, and vulnerability management platforms.
- Understanding of DevSecOps practices and CI/CD security integration.
- Strong technical documentation, communication, and stakeholder management skills.
- Ability to collaborate effectively with technical and non-technical teams while influencing secure design decisions.
The role offers the opportunity to work in a collaborative security-focused environment with flexibility and professional growth opportunities, including:
- Remote work opportunity based in India.
- Opportunity to work on impactful product security initiatives and modern technology environments.
- Exposure to cloud-native architectures, AI security, and advanced application security practices.
- Collaboration with cross-functional engineering and product teams.
- Opportunities to strengthen expertise in threat modeling, security architecture, and DevSecOps.
- A role focused on continuous learning, innovation, and improving digital security practices.