Security Engineer at Upswing Financial Technologies Private Limited · Bengaluru (Bangalore) · 3 - 6 years · Raised funding · Posted 4 Jun 2023

At Upswing, we are committed to building a robust, scalable & secure API platform to power the world of Open Finance.
We are a passionate and self-driven team of thinkers who aspire to build the rails to connect the legacy financial sector with financial innovators through a simple and powerful banking-as-a-service (BaaS) platform.
We are looking for motivated engineers who will be working in a highly creative and cutting-edge technology environment to build a world-class financial services suite.
About the role
As part of the DevSecOps team at Upswing, you will get to work on building state-of-the-art infrastructure for the future. You will also be –
- Managing security aspects of the Cloud Infrastructure
- Designing and Implementing Security measures, Incident Response guidelines
- Conducting Security Awareness Training
- Developing SIEM tooling and pipelines end to end for vulnerability/security/incident reporting
- Developing automation and performing routine VAPT for Network and Applications
- Integrating with 3rd party vendors for the services required to improve security posture
- Mentoring people across the teams to enable best practices
What will you do if you join us?
- Engage in a lot of cross-team collaboration to independently drive forward DevSecOps practices across the org
- Take Ownership of existing, ongoing, and future DevSecOps initiatives
- Plan and Engage in Architecture discussions to bring in different angles (especially security angles) to the table
- Build Automation stack and tools for security pipeline
- Integrate different security measures and pipelines with the SIEM tool
- Conducting routine VAPT using manual and automated workflows, generating and maintaining the report for the same
- Introduce and Implement best practices across teams for a great security posture in the org
You should have
- Curiosity for on-the-job learning and experimenting with new technologies and ideas
- A strong background in Linux environment
- Proven experience in Architecting networks with security first implementation
- Experience with VAPT tooling for Networks and Applications is required
- Strong experience in Cloud technologies, multi-cloud environments, and best practices in Cloud
- Experience with at least one scripting language (Ruby/Python/Groovy)
- Experience in Terraform is highly desirable but not mandatory
- Some experience with Kubernetes, and Docker is required
- Understanding Java web applications and monitoring them for security vulnerabilities would be a plus
- Any other DevSecOps-related experience will be considered

About Upswing Financial Technologies Private Limited
About
Here’s a quick read to know more about Upswing (upswing.one)
Company page on LinkedIn: linkedin.com/company/upswing-financial-technologies
We are a seed funded company, have recently raised USD 4Mn
• In the news: inc42.com/buzz/open-finance-startup-upswing-raises-4-mn-from-qed-investors
• Lead investor: http://qedinvestors.com/companies/upswing
• Angel investors: Founders and Senior executives of Jupiter, Cred, Slice, Epifi, Snapdeal, One Assist and many more.
Company vision:
At Upswing, our mission is to enable consumer companies to offer differentiated financial products and empower the financial institutions with greater reach through our Secure, Scalable and easy to integrate API platform.
We are enabling Consumer Tech/Non-Tech companies to become full stack banking players. The transformation will reduce the cost and complexity for any company to become a financial services company and re-define the future of banking
Our simple and powerful banking-as-a-service stack will help companies launch new banking products in weeks, not years.
Founding team has more than 40 years of experience in Building Banking, Lending, Payments and Disruptive Technology Stack.
Anupam Bagchi: Built Jupiter, India’s First Transit and multi bank EMI, Foundation to RuPay, Lending, Payments, Digital Banking. (linkedin.com/in/anupam-bagchi-b770572)
Nihar Gupta: Built Jupiter, Strategy and Execution of 811, Issuing, Acquiring, Toll Payments, Forex and Digital Banking (https://www.linkedin.com/in/nihargupta/)
Gazal Garg: Built disruptive tech at Zilingo from an idea to a unicorn, IIT Kharagpur alumnus - (linkedin.com/in/gazalgarg)
Tech stack
Candid answers by the company
We are enabling Consumer Tech/Non-Tech companies to become full stack banking players. The transformation will reduce the cost and complexity for any company to become a financial services company and re-define the future of banking
Connect with the team
Similar jobs (10)
A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.
Key Responsibilities
- Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
- Conduct vulnerability assessments, penetration testing, and risk analysis.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
- Collaborate with IT and business teams to integrate security into system architecture and processes.
- Lead incident response drills and disaster recovery planning.
- Provide guidance and mentorship to junior cybersecurity staff.
- Stay updated on emerging threats, tools, and technologies.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5–10 years of proven experience in cybersecurity engineering or related roles.
- Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
- Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
- Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.
Skills
- Advanced problem-solving and analytical skills.
- Strong communication and leadership abilities.
- Ability to manage complex projects and handle escalations effectively.
- Proactive mindset with adaptability to evolving cyber threats.
Company Description
Appiness Interactive Pvt. Ltd. is a Bangalore-based product development and UX firm that specializes in digital services for startups to fortune-500s. We work closely with our clients to create a comprehensive soul for their brand in the online world, engaged through multiple platforms of digital media. Our team is young, passionate, and aggressive, not afraid to think out of the box or tread the un-trodden path in order to deliver the best results for our clients. We pride ourselves on Practical Creativity where the idea is only as good as the returns it fetches for our clients.
Role Overview
We are looking for an experienced Senior Cloud Security Engineer with 7+ years of experience, including strong hands-on expertise in AWS Cloud Security. The candidate will be responsible for designing, implementing, assessing, and continuously improving security across AWS cloud environments. The role requires strong knowledge of cloud security architecture, IAM, network security, threat detection, vulnerability management, incident response, security monitoring, encryption, and DevSecOps.
This is a highly technical position. Hands-on technical expertise will be given significantly more importance than communication skills. Good written and verbal communication is sufficient.
Key Responsibilities
- Design and implement secure AWS cloud architectures.
- Establish and maintain AWS security best practices and security controls.
- Implement IAM, RBAC, least-privilege access, MFA, federation and privileged access controls.
- Secure AWS networking including VPCs, Security Groups, NACLs, routing, private/public subnets and VPC endpoints.
- Implement and manage AWS security services including:
- AWS IAM
- AWS KMS
- AWS CloudTrail
- Amazon GuardDuty
- AWS Security Hub
- AWS Config
- AWS WAF
- AWS Secrets Manager
- Monitor and investigate security events, threats and suspicious activities.
- Lead or participate in cloud security incident response and root-cause analysis.
- Conduct vulnerability assessments and coordinate remediation.
- Perform AWS security posture reviews and identify misconfigurations.
- Review cloud architectures and provide security recommendations.
- Implement encryption and data protection controls.
- Secure CI/CD pipelines and support DevSecOps practices.
- Review Infrastructure as Code for security risks.
- Implement security automation wherever possible.
- Work with engineering, DevOps and infrastructure teams to embed security into the development lifecycle.
- Establish security standards, policies and controls for AWS environments.
- Support compliance requirements and security audits.
- Mentor junior engineers and provide technical guidance.
Mandatory Technical Skills
Must Have
- 7+ years of overall IT/Security/Cloud experience
- Strong AWS Cloud Security experience
- Hands-on AWS security architecture
- AWS IAM
- IAM policies, roles, permissions and least privilege
- AWS networking security
- VPC, Security Groups and NACLs
- CloudTrail and security logging
- GuardDuty
- Security Hub
- KMS and encryption
- Vulnerability management
- Cloud security monitoring
- Incident response
- Security hardening
- Security architecture/design
Good to Have
- AWS Organizations / SCP
- Terraform / CloudFormation
- DevSecOps
- CI/CD security
- Docker/Kubernetes security
- SAST/DAST/SCA
- SIEM tools
- Python/Bash/PowerShell scripting
- CIS Benchmarks
- NIST
- ISO 27001
- SOC 2
- AWS security certifications
Location : Mumbai
Big Picture (The Opportunity) :
Are you looking for an opportunity to advance your Career? & If you are able to maintain a positive attitude even when everything goes wrong, if you are detail oriented and self motivated with a passion to learn and improve your skills and knowledge, we have a perfect job for you !
What do we want from you ? (Our Expectations) :
- Zero to 2 years experience in Linux Operating System.
- Flexible working hours - able to support occasional nights, weekends, and call-ins, able to quickly adapt to a constantly changing faced paced environment. Open to travel to sites.
- An ideal person who is excited and motivated about running and supporting a production - grade critical infrastructure and looks for opportunities to improve processes with automation.
What are you required to do ? (Your Responsibilities) :
- Proactively maintain and develop all linux infrastructure technology to maintain a 24*7*365 uptime service.
- Engineering of systems administration-related various solutions for our various SAAS products and projects as well as operational needs.
- Proactively monitoring system performance and capacity planning.
- Providing technical support to customers for Applications, Operating systems, and networking.
- Will also be the first point of contact for our clients, where installations are placed on a permanent basis, for basic troubleshooting and problem solving.
- Fault finding, analysis and logging information for reporting of performance exceptions.
- Maintain best practices on managing systems and services across all environments.
Skills & Qualification Required (Add Value) :
- Graduate - Preferred to have Bachelor‘s Degree in Engineering, Computer Science or related field.
- He / She should be familiar with the installation and configuration of Linux operating systems and setup and operation of TCP/IP networking on Linux systems also familiar with Internet concepts including SMTP, IMAP, POP, HTTP, DNS, LDAP and related protocols.
- You should possess excellent communication skills .
- Knowledge of Email concepts, Helpdesk Concept , VoIP Concept , Cloud computing will be an added advantage.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
WowPe is a leading fintech company revolutionizing the way businesses handle financial transactions. Our suite of innovative products includes a secure Payment Gateway for seamless online transactions, robust Payouts solutions to streamline bulk payments, and a versatile Point of Sale (POS) system for efficient in-store transactions. At WowPe, we’re dedicated to providing user-friendly, scalable, and reliable solutions that empower businesses to grow and succeed in today’s fast-paced digital economy.
We are looking for a highly skilled Cloud Infrastructure & Cloud Network Engineer to design, build, and manage secure, scalable hybrid cloud environments at WowPe. This role will focus on cloud networking, hybrid connectivity, infrastructure automation, security, reliability, and performance across on-prem and cloud platforms (AWS/Azure). You will play a critical role in ensuring high availability, security, and performance of our fintech platforms.
A Day in the Life
- Design and review cloud network architectures (VPC/VNet, routing, segmentation)
- Troubleshoot latency, connectivity, VPN, and performance issues
- Work with DevOps and application teams to support deployments and scalability
- Automate infrastructure provisioning and security guardrails
- Monitor network health, traffic flow, and system performance
- Ensure security, compliance, and disaster recovery readiness
- Support hybrid connectivity between on-prem data centers and cloud environments.
Key Responsibilities
Cloud Networking & Hybrid Architecture
- Design and implement VPC/VNet architectures, subnetting, routing tables, NAT, gateways, and secure segmentation
- Build and manage hybrid connectivity between on-prem data centers and cloud using Site-to-Site VPN, ExpressRoute, Direct Connect
- Configure and manage Layer 4 & Layer 7 load balancers for high availability and traffic distribution
- Architect DNS, CDN, and edge networking strategies for low-latency global access
Security & Zero-Trust
- Implement Zero-Trust networking using security groups, NACLs, identity-aware proxies, mTLS
- Design secure access controls and network isolation
- Work closely with security teams to ensure PCI, ISO, SOC compliance readiness
Automation, Platform & Reliability
- Automate infrastructure provisioning using Infrastructure as Code (Terraform/ARM/CloudFormation)
- Build self-healing, auto-scaling architectures with health checks and fault tolerance
- Support and manage Kubernetes clusters (EKS/AKS) including networking and service communication
- Integrate infra with CI/CD pipelines for safe and frequent deployments
Operations & Observability
- Perform advanced troubleshooting for latency, packet loss, MTU, routing loops
- Implement and manage monitoring, logging, and observability (Prometheus, Grafana, ELK, Azure Monitor, CloudWatch)
- Design and maintain disaster recovery architectures, multi-region networking, and replication strategies
- Ensure high availability, performance optimization, and cost efficiency
Basic Qualifications & Skills
- 4+ years of experience in Cloud Infrastructure & Cloud Networking
- Strong hands-on experience with AWS and/or Azure
- Deep understanding of VPC/VNet, routing, NAT, gateways, load balancers, DNS
- Experience with Hybrid connectivity (VPN, ExpressRoute, Direct Connect)
- Solid knowledge of network security, firewalls, access control, segmentation
- Hands-on experience with Infrastructure as Code (Terraform preferred)
- Experience in monitoring, troubleshooting, and incident handling
- Strong understanding of high availability, DR, and performance optimization
Preferred Qualifications
- Experience in fintech, BFSI, or high-compliance environments
- Exposure to Zero-Trust architecture and security best practices
- Experience with Kubernetes (EKS/AKS), service mesh, microservices networking
- Familiarity with CI/CD pipelines and DevOps practices
- Knowledge of CDN, edge networking, and global traffic management
- Experience with compliance frameworks (PCI-DSS, ISO 27001, SOC2)
- Ability to design large-scale, resilient, production-grade architectures
Greetings from zealous sevices!
GoLang (Soln Architect) -(9 AM to 6PM)
Experience: 10-12 Yrs
Need a senior Solution Architect - No BGV - ok with consultants
Own end-to-end solution architecture for a cloud-based cybersecurity platform operating at massive scale (millions of assets), spanning multiple product modules and a broad third-party integration ecosystem.
What They'll Do
Define and own the overall solution architecture across multiple product modules (e.g., detection, response, asset inventory, reporting), ensuring they work as a coherent, scalable system rather than disconnected parts
Design for scale: architecture that reliably handles millions of assets/endpoints with predictable performance, cost, and reliability as volume grows
Lead cloud infrastructure architecture decisions, compute, storage, networking, multi-region/multi-tenant strategy, disaster recovery
Architect and govern third-party integrations (SIEM/SOAR, ticketing, identity providers, cloud provider APIs, threat intel feeds, etc.), define integration patterns, data contracts, and reusable frameworks rather than one-off connections
Create and maintain architecture roadmaps, capacity plans, and technical strategy aligned with product/business roadmap
Set architectural standards and guardrails (scalability, security, data flow, API design) across engineering teams
Act as the technical bridge between engineering, product, security, and infrastructure/DevOps teams
Conduct architecture reviews, threat-model system designs, and identify scaling bottlenecks or single points of failure before they hurt production
Own key non-functional requirements: performance, availability, security, cost-efficiency, compliance
Support presales/enterprise customer conversations on architecture, especially for large or complex deployments
Evaluate and select core technologies (data stores, messaging systems, orchestration, IaC tooling)
What They Should Have
8–12+ years in software/infra engineering, with 4+ years specifically in a solution/enterprise architect role
Proven experience architecting systems at scale (millions of records/assets/events), not just designing on paper, but having operated such systems in production
Deep cloud architecture expertise (AWS/GCP/Azure), multi-account/multi-tenant design, cost optimization, networking, IAM
Strong grasp of distributed systems patterns: data partitioning, eventual consistency, event-driven architecture, caching strategies
Experience designing integration architectures (APIs, webhooks, message queues) across many heterogeneous third-party systems
Security architecture fluency,this is a security product, so the architect must think adversarially about their own system
Ability to produce architecture documentation (C4 diagrams, ADRs, data flow diagrams) that both engineers and executives can use
Track record of cross-functional influence, able to align multiple engineering teams around a shared architecture without direct authority
Cybersecurity domain knowledge (SIEM/EDR/CNAPP/CSPM concepts, threat detection pipelines), or equivalent adjacent domain with fast ramp-up ability
Nice to Have
Experience with specific integration ecosystems relevant to your product (e.g., Splunk, ServiceNow, Okta, AWS Security Hub)
Familiarity with IaC (Terraform), service mesh, and Kubernetes at scale Enterprise/regulated-industry experience (SOC 2, FedRAMP, ISO 27001) shaping architecture decisions
Prior experience scaling a product from ""hundreds of thousands"" to ""tens of millions"" of managed assets
Job Description:
- Infrastructure Management: Design, implement, and manage scalable, reliable, and secure cloud infrastructure using AWS, GCP, and/or Azure.
- CI/CD Pipelines: Develop and maintain continuous integration and continuous deployment (CI/CD) pipelines to streamline the development lifecycle.
- Automation: Automate infrastructure provisioning, configuration management, and application deployment processes.
- Monitoring and Performance: Implement monitoring, logging, and alerting solutions to ensure system health, performance, and reliability.
- Security: Ensure the security of cloud infrastructure and applications, including identity management and compliance with industry standards.
- Collaboration: Work closely with client and development teams to integrate DevOps practices and deliver high-quality software.
- Documentation: Maintain comprehensive documentation of infrastructure, configurations, and processes.
- Innovation: Stay current with emerging technologies and industry trends, integrating them into the DevOps strategy as appropriate.
Qualifications:
- Education: Bachelor's degree in Computer Science, Information Technology, or a related field.
- Experience: 7 - 10 years of overall experience with relevant experience of at least 7 years in DevOps and served as a lead or senior engineer.
Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles
2
Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,
3
Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.
4
Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.
5
Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.
6
Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.
7
Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.
8
Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.
Job Description - Security Solutions Architect
Job Title
Security Solutions Architect / Senior Security Solutions Architect
Practice: Cloud Security & Reliability Engineering (CSR)
Location: India
Regional Coverage: EU/UK, Middle East & Africa (MEA), India, and APAC
Experience:
- Security Solutions Architect: 8–10 years
- Senior Security Solutions Architect: 10–12+ years
Role Overview
We are looking for an experienced Security Solutions Architect / Senior Security Solutions Architect to drive security solutioning across complex cloud, hybrid, and multi-cloud customer environments.
This is a customer-facing solution architecture role operating at the intersection of cloud security, cybersecurity transformation, compliance, pre-sales solutioning, and delivery readiness. The architect will work closely with customers, sales, practice leaders, OEM partners, and delivery teams to understand business and security challenges and translate them into technically robust, commercially viable, and executable security solutions.
The role requires someone who can go beyond product-led solutioning. The successful candidate should be able to understand a customer's existing security landscape, identify risks and capability gaps, define the target-state architecture, and build a clear transformation roadmap.
Given our coverage across EU/UK, MEA, India, and APAC, the architect must also be comfortable adapting security architectures to different regulatory, data sovereignty, industry, and operational requirements.
A strong foundation in Google Cloud Security is mandatory, complemented by hands-on knowledge of modern security platforms, particularly CNAPP/CSPM technologies such as Wiz. Experience across Microsoft security and other cybersecurity platforms will be an advantage.
Key Responsibilities
Security Solution Architecture & Consulting
- Own end-to-end security solution architecture for cloud, hybrid, and multi-cloud customer environments.
- Lead technical discovery and security assessment workshops to understand the customer's current environment, security posture, business objectives, risks, regulatory obligations, and operational challenges.
- Translate customer requirements into scalable, secure, resilient, and commercially viable solution architectures.
- Develop current-state and target-state security architectures, transformation roadmaps, and solution blueprints.
- Design security solutions across areas such as:
- Cloud Security and Cloud-Native Security
- CNAPP, CSPM, CWPP, and Cloud Security Posture Management
- Security Operations and SIEM/SOAR modernization
- Threat Detection and Response
- Identity and Access Management
- Data Security and Data Protection
- Network and Zero Trust Security
- Vulnerability and Exposure Management
- Security Automation and AI-driven Security Operations
- Cyber Resilience and Security Monitoring
Google Cloud Security
- Architect and demonstrate Google Cloud security capabilities across cloud-native and enterprise security use cases.
- Design solutions leveraging relevant Google Cloud security services and technologies for security posture management, threat detection, security operations, data protection, identity, and workload security.
- Translate Google Cloud security capabilities into business and security outcomes relevant to the customer's environment.
- Conduct customer demonstrations, technical workshops, architecture discussions, and proof-of-concept engagements.
- Maintain awareness of evolving Google Cloud security capabilities and incorporate them into solution offerings and reusable architectures.
CNAPP / CSPM & Wiz
- Architect and demonstrate CNAPP and CSPM solutions, with strong hands-on experience in Wiz.
- Design cloud security posture, workload protection, vulnerability management, attack-path analysis, and cloud risk management solutions.
- Position CNAPP capabilities as part of a broader cloud security operating model rather than as a standalone technology deployment.
- Integrate CNAPP capabilities into security operations, governance, compliance, and remediation workflows.
Security Operations & Transformation
- Support customers in modernizing traditional security operations toward cloud-native and AI-enabled security operations.
- Design architectures for SIEM/SOAR modernization, security data onboarding, threat detection, incident response, automation, and security analytics.
- Understand existing customer security ecosystems and define integration approaches across cloud platforms, security tools, identity systems, network infrastructure, and enterprise applications.
- Identify opportunities to simplify fragmented security architectures and improve security effectiveness through platform consolidation and automation.
Compliance & Regulatory Architecture
- Translate regulatory and compliance obligations into practical security architecture and technical controls.
- Design solutions considering relevant frameworks and regulatory requirements, including:
- GDPR and data protection requirements across EU/UK
- Data residency, sovereignty, and localization requirements
- Security and regulatory frameworks applicable across UAE and KSA
- India DPDP Act and relevant sector-specific requirements
- RBI and IRDAI requirements for regulated Indian financial services organizations
- Relevant APAC regulatory and cybersecurity frameworks
- Industry standards such as ISO 27001, PCI DSS, and other applicable security frameworks
- Work with customers in regulated industries including BFSI, government/public sector, healthcare, and other compliance-sensitive environments.
The architect is not expected to act as a legal or compliance auditor but must be capable of translating applicable regulatory and security requirements into appropriate architectural controls and solution designs.
Pre-Sales, SOW & Commercial Solutioning
- Own the technical solutioning lifecycle from initial discovery through proposal, technical closure, and handover to delivery.
- Develop end-to-end Statements of Work (SOWs), including:
- Scope
- Technical solution and architecture
- Deliverables
- Implementation approach
- Effort estimation
- Assumptions and dependencies
- Exclusions
- Acceptance criteria
- Build commercial solutions using standard pricing and estimation frameworks while balancing customer competitiveness, delivery feasibility, risk, and target margins.
- Contribute to RFP/RFI responses, proposals, presentations, solution workshops, and executive-level customer discussions.
- Present and defend proposed architectures with customer CISOs, security leaders, cloud teams, enterprise architects, compliance stakeholders, and technical teams.
- Clearly articulate solution value, differentiation, risks, trade-offs, and expected security outcomes.
Delivery Readiness & Governance
- Validate solution feasibility with delivery and engineering teams before customer commitment.
- Ensure that proposed scope, architecture, effort, timelines, and assumptions are aligned with delivery capabilities.
- Lead structured sales-to-delivery handovers and remain engaged during critical transition stages.
- Minimize delivery rework and commercial leakage by ensuring that customer commitments are clearly documented and technically validated.
Practice Development
- Build reusable security solution architectures, reference designs, SOW templates, pricing models, discovery frameworks, and accelerators.
- Develop repeatable solution patterns for common industry and regulatory scenarios.
- Contribute to the evolution of the CSRE security services portfolio and go-to-market offerings.
- Work with technology partners and OEMs to develop joint solutions, demonstrations, and market propositions.
- Support internal sales and technical teams through enablement sessions and solution playbooks.
- Mentor junior architects and security engineers, particularly at the Senior Security Solutions Architect level.
Must-Have Skills & Experience
- 8–12+ years of relevant experience across cybersecurity, cloud security, security architecture, consulting, or security solutioning.
- Strong hands-on experience with Google Cloud Security, with the ability to architect, demonstrate, and position security capabilities in customer environments.
- Strong hands-on experience with CNAPP/CSPM technologies, preferably Wiz.
- Strong understanding of cloud security architecture across IaaS, PaaS, containers, Kubernetes, cloud-native services, and hybrid environments.
- Experience designing security solutions for complex enterprise environments.
- Strong understanding of modern security architecture concepts across Security Operations, SIEM/SOAR, IAM, data security, network security, vulnerability management, and cloud workload protection.
- Experience designing solutions for regulated industries such as BFSI, government/public sector, or healthcare.
- Working knowledge of security, privacy, compliance, and data sovereignty requirements across relevant geographies.
- Demonstrated experience in customer-facing technical discovery, architecture workshops, and solution presentations.
- Experience independently developing SOWs, technical proposals, effort estimates, and commercial solutions.
- Ability to communicate complex security concepts clearly to technical, business, and executive stakeholders.
- Strong stakeholder management and presentation skills.
Good to Have
- Microsoft Azure and Microsoft Security experience, including exposure to technologies such as Defender, Sentinel, and Entra.
- Experience with Google Security Operations or SIEM/SOAR modernization programs.
- Experience with additional cloud and cybersecurity platforms across AWS, Azure, and multi-cloud environments.
- Exposure to AI-driven security operations, security automation, and emerging AI security technologies.
- Experience working with customers across EU/UK, MEA, India, or APAC.
- Experience working with large enterprise and regulated customers.
- Consulting, system integration, professional services, or managed security services background.
- Relevant cloud and cybersecurity certifications from Google Cloud, Wiz, Microsoft, AWS, or recognized security certification bodies.
What Success Looks Like
The successful architect will be able to:
- Independently lead complex customer security solutioning from discovery to technical closure.
- Build architectures that are secure, compliant, commercially competitive, and executable by delivery teams.
- Demonstrate and position Google Cloud Security and Wiz capabilities confidently in real customer scenarios.
- Convert complex customer security and regulatory challenges into clear solution architectures and transformation roadmaps.
- Produce high-quality SOWs with accurate scope, assumptions, effort, and commercial structure.
- Build trust with customer CISOs, security teams, enterprise architects, compliance stakeholders, and internal delivery teams.
- Create reusable security solution patterns that improve solutioning speed, quality, and consistency across regions.
Experience Level
Security Solutions Architect | 8–10 Years
Expected to independently lead discovery, architecture, solution design, demonstrations, SOW development, and technical solutioning for mid-size to large security engagements.
Senior Security Solutions Architect | 10–12+ Years
Expected to lead complex, strategic, multi-technology, multi-country, and compliance-intensive security engagements. Should be capable of engaging senior customer stakeholders, shaping security transformation programs, handling complex commercial and architectural decisions, mentoring other architects, and contributing to the development of the security practice and its go-to-market strategy.
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.










