
Principal Cyber Security Architect
- Bangalore, Karnataka
- Permanent
- Full-time
- Design, implement, and maintain security controls and best practices across multi-cloud environments (AWS, Azure, GCP).
- Ensure alignment with the AWS Well-Architected Framework and security standards across cloud vendors.
- Drive and support compliance initiatives including HITRUST, FedRAMP, HIPAA, and GDPR, ensuring all systems and processes meet regulatory requirements.
- Lead the development and maintenance of security and privacy policies, procedures, and documentation.
- Partner with product development, program management, regulatory, privacy, and legal teams to define and enforce security requirements for healthcare solutions, including applications, on-premises systems, and SaaS analytics platforms.
- Collaborate with cross-functional teams including IT, compliance, and engineering to integrate security into business and technical processes.
- Lead and manage security incident response, including assessment of risk and impact of breaches to protected systems.
- Review engineering changes, new services, and feature requests for security implications and required controls.
- Verify implementation and effectiveness of security and privacy measures as defined in organizational policies and plans.
- Research and evaluate emerging technologies, industry trends, and market developments to inform security strategy and support operational initiatives.
- Provide strategic guidance on cybersecurity best practices and threat mitigation.
- Drive certification processes for HITRUST and FedRAMP, including audit preparation and documentation.
- Mentor junior security architects and engineers, fostering a culture of continuous improvement and knowledge sharing.
- Master’ s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
- 8+ years of progressive experience in cybersecurity, with at least 4 years in a senior or architectural role.
- Strong understanding of HIPAA, and GDPR compliance frameworks.
- Hands-on experience with multi-cloud environments (AWS, Azure, GCP), including security architecture and cloud governance.
- One or more recognized cybersecurity certifications such as CISSP, CISM, CCSP, HCISPP, or equivalent.
- Strong analytical and problem-solving skills with the ability to assess complex systems and recommend effective security solutions.
- Excellent communication and collaboration skills across technical and non-technical teams.
- Demonstrated leadership in managing security incidents and mentoring teams.
- Experience with secure software development practices, DevSecOps, and product security lifecycle.
- Proven experience in the healthcare or medical domain, including familiarity with clinical systems and healthcare data flows.
- Knowledge of additional security frameworks such as NIST, ISO 27001, or SOC 2.
- Experience supporting audit and certification processes for HITRUST and FedRAMP.
- Deep knowledge of the AWS Well-Architected Framework and cloud-native security controls.
- Exposure to emerging technologies and trends in cybersecurity, privacy, and healthcare IT.