
Associate Security Architect
- Bangalore, Karnataka
- Permanent
- Full-time
- Bachelor's degree in computer science or related field
- 10+ years of experience in Information security and related domain
- 3+ years of experience in security architecture and security solution engineering
- Strong understanding of cryptographic algorithms and protocols used in blockchain, such as hashing functions, public-key cryptography, and zero-knowledge proofs.
- Experience designing and implementing security architectures for applications and microservices.
- Experience in architecting and solving security problems
- Experience in designing and analyzing security solutions with a deep understanding of Blockchain Security, Identity and access management, cloud & infrastructure security, application security, data & network security, security governance, etc.
- Experience with driving Secure SDLC activities, DevSecOps (CI/CD), and agile software development practices
- Knowledge of Security Integration into CI/CD and experience in driving CI/CD adaptation for Security controls
- Sound understanding of security by design principles and architecture-level security concepts
- Strong leadership skills and the ability to coach and mentor other members of the Product Security teams
- Experience with penetration testing methodologies and tools including security analysis, audits, and reviews
- Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities
- Sound knowledge of OWASP Top 10 and SANS 25
- Must have Knowledge and experience with security standards such as CCSS (CryptoCurrency Security Standard), NIST, ISO 27001/2, CSA, SOC 1&2, and CIS
- CISSP, TOGAF/SABSA, or Cloud security certifications are preferred
- Prior application development or software engineering experience is desirable
- Ability to convey security concepts to both technical and non-technical audiences
- Flexible, adaptable, and able to manage multiple tasks in a dynamic, fast-paced environment
- Excellent written and verbal communication skills, interpersonal and presentation skills, and the proven ability to influence and communicate effectively
- Excellent business acumen and a commercial outlook
- Plans, researches, and designs security architecture for Web3 infrastructure, including smart contracts, decentralized wallets and applications, blockchain networks and Web2 applications & systems
- Performs security design and architecture reviews for the existing, and future implementations and new features, and provides recommendations to reduce the risks in Web 3.0 & Web 2.0 layers
- Proactively drive the security requirements phase along with the product and engineering teams, and develop security requirements focused on blockchain and Web3 ecosystems
- Stay informed about emerging threats and vulnerabilities specific to blockchain and Web3 technologies
- Develop and execute incident response plans tailored to the unique security challenges of decentralised environments.
- Implement and manage cryptographic protocols to ensure the security of data and transactions within blockchain systems.
- Develop strategies for secure key management, including private key protection, multi-signature and multi-party computation solutions.
- Ensure that blockchain and Web3 implementations comply with relevant regulations and industry standards
- Bridge the gap between traditional Web2 security practices and Web3 technologies to ensure a cohesive security strategy.
- Develop and implement security policies that address both centralized and decentralized components of the company's infrastructure
- Develop and review threat models and security risk assessments to identify risks and drive mitigations
- Continuously review and align the secure development lifecycle to industry standards, including Microsoft SDL, OWASP development guides, and privacy-related guides
- Work collaboratively with the development and scrum teams to strengthen the existing software development lifecycle and standardize the secure development process across the company
- Review of cloud and physical infrastructure and their threat landscape to ensure ongoing and continued implementation of adequate security controls.
- Design Your Own Benefit: Tailor your perk package to fit your unique needs. Whether you're eyeing a new gadget or welcoming a furry friend into your life, our flexible benefits ensure that you can prioritize what matters most to you.
- Unlimited Wellness Leaves: We believe in the power of well-being. Take the time you need to recharge, knowing that your health is our priority. With unlimited wellness leaves, you can return refreshed, ready to build and grow.
- Mental Wellness Support: Your mental health is as important as your professional growth. Benefit from access to health experts, free counseling sessions, monthly wellness workshops, and regular team outings, all designed to help you stay balanced and connected.
- Bi-Weekly Learning Sessions: These sessions are more than just updates-they're opportunities to fuel your growth. Stay ahead with the latest industry knowledge, sharpen your skills, and accelerate your career in an ever-evolving landscape.