Senior Security Architect · Bengaluru (Bangalore), Mumbai, Delhi, Gurugram, Noida, Pune, Hyderabad, Chennai · 12 - 20 years · Posted 17 Jun 2024

Senior Security Architect
Senior Security Architect
The Security Architect leads the design and development of innovative security architectures for protecting data deployed into different types of cloud and cloud/hybrid systems. This position will directly contribute to the overall global enterprise cloud architecture and lead the security vision and strategy around cloud-based applications, across all types (including Infrastructure, Platform, and Software as a Service (IaaS/PaaS/SaaS).
Job Description
The Security Architect will serve as the central point of contact for other Technology teams within the Organization for all matters related to cloud security.
The successful candidate possesses the excellent interpersonal and communication skills required to partner with other leaders across the business to identify opportunities and risks and develop and deliver solutions that support business strategies and protect the intellectual property globally.
Expertise – Collaborate with Application Owners, Technical Owners, Platform Leads, and Information Security teams, to architect and design cloud security solutions.
Knowledge of cloud security services such as Azure and AWS is essential
Delivery – Complete architecture assessments across projects, prove use of security solutions to support new distributed computing solutions that span private cloud and public cloud services.
Security Technology Strategy – Work with engineering, service and business teams to create technology roadmaps.
Responsibilities Include
• Design and develop security architectures for cloud and cloud/hybrid based systems. Possess a firm understanding of the offerings within both Amazon Web Services (AWS) and the Microsoft Azure platforms. Based on business requirements, design and implement cloud-native architecture and design that will allow those requirements to be met with a minimal degree of risk and with appropriate security controls present.
• Represent the Corporate Information Security Office in development and implementation of the overall global enterprise cloud architecture.
• Act as the ambassador and senior technical representative for Information Security while engaging with other senior technical leaders throughout the Organization in design and implementation of cloud and cloud/hybrid based implementations and solutions.
• Work with Engineering, Infrastructure Services, and Application Development organizations to choose appropriate technology solutions and facilitates complete integration. Develops standards in partnership with Engineering, Infrastructure Services, and Application Development.
• Lead training and technical forums, serve as both a formal and informal mentor, and execute other initiatives designed to share knowledge across Security and Technology groups.
• Identify, recommend, coordinate, and/or conduct informal/formal training sessions to deliver timely knowledge to support teams regarding technologies, processes or tools.
• Develop and execute strategies to increase Cloud Security knowledge throughout the enterprise, as well as developing and mentoring more-junior security analysts and engineers.
• 5-8 years of experience with Security Architect and/or Engineering.
• 3-5 years of experience with Cloud platforms such as Microsoft Azure and Amazon Web Services (AWS).
• Experience architecting solutions within Microsoft Azure, Amazon Web Services (AWS) and, preferably, other cloud providers.
• Experience with assessment, development, implementation, optimization, and documentation of a comprehensive and broad set of security technologies and processes (secure software development (Application Security), data protection, cryptography, key management, identity and access management (IAM), network security) within SaaS, IaaS, PaaS, and other cloud environments.
• Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (OAuth, OpenID, etc).
• Experience with deployment orchestration, automation, and security configuration management preferred.
• Experience with service-oriented architecture for cloud-based services.
• Experience working with cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies.
• Experience with enterprise applications (architecture, development, support, and troubleshooting).
• Experience performing threat modeling and design reviews to assess security implications and requirements for introduction of new technologies.
• Experience representing technical viewpoints to diverse audiences and in making timely and prudent technical risk decisions.
• Experience with enterprise architecture and working as part of a cross-functional team to implement solutions.
• Strong interpersonal and communication skills; ability to work in a team environment
• Ability to work independently with minimal direction; self-starter/self-motivated
• Detailed understanding of SSL/TLS protocols and certificate-based solutions
• Technical writing experience
Preferred Qualifications
• Minimum of 15 years of formal education - Graduate / Postgraduate in Computer Science / Information Technology Professional work experience between 10-15 and at least 6-8 years as a Security Architect / Junior Security Architect
• Working Experience with distributed team preferred.
• Relevant industry certifications such as CISSP, CISM, or CCSP

Similar jobs (10)
Greetings from zealous sevices!
GoLang (Soln Architect) -(9 AM to 6PM)
Experience: 10-12 Yrs
Need a senior Solution Architect - No BGV - ok with consultants
Own end-to-end solution architecture for a cloud-based cybersecurity platform operating at massive scale (millions of assets), spanning multiple product modules and a broad third-party integration ecosystem.
What They'll Do
Define and own the overall solution architecture across multiple product modules (e.g., detection, response, asset inventory, reporting), ensuring they work as a coherent, scalable system rather than disconnected parts
Design for scale: architecture that reliably handles millions of assets/endpoints with predictable performance, cost, and reliability as volume grows
Lead cloud infrastructure architecture decisions, compute, storage, networking, multi-region/multi-tenant strategy, disaster recovery
Architect and govern third-party integrations (SIEM/SOAR, ticketing, identity providers, cloud provider APIs, threat intel feeds, etc.), define integration patterns, data contracts, and reusable frameworks rather than one-off connections
Create and maintain architecture roadmaps, capacity plans, and technical strategy aligned with product/business roadmap
Set architectural standards and guardrails (scalability, security, data flow, API design) across engineering teams
Act as the technical bridge between engineering, product, security, and infrastructure/DevOps teams
Conduct architecture reviews, threat-model system designs, and identify scaling bottlenecks or single points of failure before they hurt production
Own key non-functional requirements: performance, availability, security, cost-efficiency, compliance
Support presales/enterprise customer conversations on architecture, especially for large or complex deployments
Evaluate and select core technologies (data stores, messaging systems, orchestration, IaC tooling)
What They Should Have
8–12+ years in software/infra engineering, with 4+ years specifically in a solution/enterprise architect role
Proven experience architecting systems at scale (millions of records/assets/events), not just designing on paper, but having operated such systems in production
Deep cloud architecture expertise (AWS/GCP/Azure), multi-account/multi-tenant design, cost optimization, networking, IAM
Strong grasp of distributed systems patterns: data partitioning, eventual consistency, event-driven architecture, caching strategies
Experience designing integration architectures (APIs, webhooks, message queues) across many heterogeneous third-party systems
Security architecture fluency,this is a security product, so the architect must think adversarially about their own system
Ability to produce architecture documentation (C4 diagrams, ADRs, data flow diagrams) that both engineers and executives can use
Track record of cross-functional influence, able to align multiple engineering teams around a shared architecture without direct authority
Cybersecurity domain knowledge (SIEM/EDR/CNAPP/CSPM concepts, threat detection pipelines), or equivalent adjacent domain with fast ramp-up ability
Nice to Have
Experience with specific integration ecosystems relevant to your product (e.g., Splunk, ServiceNow, Okta, AWS Security Hub)
Familiarity with IaC (Terraform), service mesh, and Kubernetes at scale Enterprise/regulated-industry experience (SOC 2, FedRAMP, ISO 27001) shaping architecture decisions
Prior experience scaling a product from ""hundreds of thousands"" to ""tens of millions"" of managed assets
Company Description
Appiness Interactive Pvt. Ltd. is a Bangalore-based product development and UX firm that specializes in digital services for startups to fortune-500s. We work closely with our clients to create a comprehensive soul for their brand in the online world, engaged through multiple platforms of digital media. Our team is young, passionate, and aggressive, not afraid to think out of the box or tread the un-trodden path in order to deliver the best results for our clients. We pride ourselves on Practical Creativity where the idea is only as good as the returns it fetches for our clients.
Role Overview
We are looking for an experienced Senior Cloud Security Engineer with 7+ years of experience, including strong hands-on expertise in AWS Cloud Security. The candidate will be responsible for designing, implementing, assessing, and continuously improving security across AWS cloud environments. The role requires strong knowledge of cloud security architecture, IAM, network security, threat detection, vulnerability management, incident response, security monitoring, encryption, and DevSecOps.
This is a highly technical position. Hands-on technical expertise will be given significantly more importance than communication skills. Good written and verbal communication is sufficient.
Key Responsibilities
- Design and implement secure AWS cloud architectures.
- Establish and maintain AWS security best practices and security controls.
- Implement IAM, RBAC, least-privilege access, MFA, federation and privileged access controls.
- Secure AWS networking including VPCs, Security Groups, NACLs, routing, private/public subnets and VPC endpoints.
- Implement and manage AWS security services including:
- AWS IAM
- AWS KMS
- AWS CloudTrail
- Amazon GuardDuty
- AWS Security Hub
- AWS Config
- AWS WAF
- AWS Secrets Manager
- Monitor and investigate security events, threats and suspicious activities.
- Lead or participate in cloud security incident response and root-cause analysis.
- Conduct vulnerability assessments and coordinate remediation.
- Perform AWS security posture reviews and identify misconfigurations.
- Review cloud architectures and provide security recommendations.
- Implement encryption and data protection controls.
- Secure CI/CD pipelines and support DevSecOps practices.
- Review Infrastructure as Code for security risks.
- Implement security automation wherever possible.
- Work with engineering, DevOps and infrastructure teams to embed security into the development lifecycle.
- Establish security standards, policies and controls for AWS environments.
- Support compliance requirements and security audits.
- Mentor junior engineers and provide technical guidance.
Mandatory Technical Skills
Must Have
- 7+ years of overall IT/Security/Cloud experience
- Strong AWS Cloud Security experience
- Hands-on AWS security architecture
- AWS IAM
- IAM policies, roles, permissions and least privilege
- AWS networking security
- VPC, Security Groups and NACLs
- CloudTrail and security logging
- GuardDuty
- Security Hub
- KMS and encryption
- Vulnerability management
- Cloud security monitoring
- Incident response
- Security hardening
- Security architecture/design
Good to Have
- AWS Organizations / SCP
- Terraform / CloudFormation
- DevSecOps
- CI/CD security
- Docker/Kubernetes security
- SAST/DAST/SCA
- SIEM tools
- Python/Bash/PowerShell scripting
- CIS Benchmarks
- NIST
- ISO 27001
- SOC 2
- AWS security certifications
About the Role
We are looking for an experienced Solution Architect / Technical Lead to lead solution architecture, system integrations, and Azure platform design for a Visitor Management System project in Abu Dhabi.
The ideal candidate will have 10+ years of experience in software projects, strong expertise in Microsoft Azure, solution architecture, integrations, and enterprise application design, along with the ability to lead technical teams and stakeholders.
Key Responsibilities
- Lead the overall solution architecture and technical design of the Visitor Management System.
- Design and implement scalable, secure, and high-performing solutions on Microsoft Azure.
- Define Azure cloud architecture, infrastructure components, networking, security, and deployment strategies.
- Lead integration architecture between the Visitor Management System and external/enterprise applications.
- Design and oversee APIs, web services, and system integrations.
- Provide technical leadership throughout the software development lifecycle.
- Review existing systems and recommend improvements in architecture, scalability, performance, and security.
- Prepare technical architecture documents, solution designs, integration specifications, and technical documentation.
- Work closely with development, infrastructure, security, and project management teams.
- Troubleshoot complex technical and architectural issues and provide effective solutions.
- Ensure solutions follow enterprise architecture, security, and coding best practices.
- Participate in technical discussions with clients and stakeholders and translate business requirements into technical solutions.
- Mentor and guide technical teams on architecture and implementation.
Required Technical Skills
- Strong experience in Solution Architecture / Technical Architecture
- Strong hands-on experience with Microsoft Azure
- Azure platform and cloud architecture
- Azure services, infrastructure, networking, and security
- API and system integration
- REST APIs / Web Services
- Microservices and distributed application architecture
- Enterprise application architecture
- Database architecture and SQL
- Azure DevOps / CI-CD
- Identity & Access Management / Microsoft Entra ID
- Cloud security, scalability, performance, and high availability
- Software development lifecycle and Agile methodologies
Required Experience
- 10+ years of experience in software projects
- Proven experience as a Solution Architect, Azure Architect, Technical Architect, or Technical Lead
- Strong experience designing and implementing enterprise-level software solutions
- Experience leading technical teams and working with multiple stakeholders
- Experience with Azure-based architecture and integrations
- Experience in visitor management, access control, security systems, or similar enterprise systems will be an advantage
Position
Solution Architect/Technical Architect
Experience
· 12 - 16+ years of overall IT experience
· Significant hands-on experience working as a Solution/Technical Architect
Education
· B.Tech / M.Tech / MCA / MBA or equivalent
Certifications
· TOGAF® certification (Level 1/2) preferred to ensure alignment with enterprise architecture standards
· Microsoft Certified: Azure Solutions Architect Expert (AZ-305) and other supporting certifications such as AZ-104, AZ-400, or AZ-500 preferred.
Key Responsibilities
· Define and evolve the target architecture for .NET-based distributed platform.
· Architect highly configurable solutions on Azure with strong focus on scalability, tenant isolation, resilience, maintainability, and speed of delivery.
· Lead solution design across ASP.NET Core services, REST APIs, event-driven workflows, background processing, integration patterns, and shared platform capabilities.
· Drive adoption of modern .NET and cloud-native patterns including microservices, domain-driven design, event-driven architecture, API-first design, and secure service-to-service communication.
· Partner with engineering teams on real implementation decisions, review critical designs and code paths, and provide hands-on guidance for performance, operability, and production readiness.
· Architect Azure-native deployment patterns using AKS, containers, API Management, Service Bus/Event Grid or equivalent messaging, Key Vault, managed observability, and CI/CD automation.
· Work with data and platform teams on PostgreSQL-backed service design, data access patterns, caching strategies, and database performance for high-volume transactional workloads.
· Define non-functional requirements and architecture guardrails around performance, scalability, availability, recoverability, security, compliance, and cost efficiency.
· Embed DevSecOps and observability into platform design through telemetry, tracing, alerting, diagnostics, secrets management, and release governance.
· Evaluate emerging technologies, AI-assisted engineering enablers, and modernization options pragmatically, with clear build-vs-buy and risk-reward trade-offs.
· Mentor senior engineers and technical leads, contribute to architectural governance, and create reusable patterns, reference implementations, and standards across teams.
· Bachelor’s or master’s degree in computer science, Engineering, or a related field.
· 12–16 years of experience in software engineering, solution architecture, or platform engineering, with significant experience in Microsoft technology stacks.
Essential Qualification and Skills
· Strong hands-on expertise in C#, .NET / .NET Core / .NET 8, ASP.NET Core, Web APIs, background services, and enterprise application design.
· Deep experience in architecting distributed systems using microservices, asynchronous messaging, event-driven design, and API-led integration patterns.
· Strong Azure architecture experience, preferably across AKS, App Services, Functions, API Management, Key Vault, Service Bus, Event Grid, Storage, monitoring, and identity integration patterns.
· Experience designing and supporting platforms, configurable product architectures, and integration-heavy enterprise solutions.
· Strong understanding of relational databases and performance engineering, especially SQL Server and/or PostgreSQL, including schema design, indexing, query tuning, and transaction handling.
· Solid grasp of non-functional architecture including performance, scalability, availability, fault isolation, observability, and disaster recovery.
· Strong understanding of application and platform security including authentication, authorization, secrets management, encryption, secure coding, and compliance-oriented design.
· Experience with containers, Kubernetes, CI/CD, infrastructure automation, and modern DevSecOps practices.
· Ability to make sound architecture decisions with a balance of pragmatism, delivery speed, engineering quality, and long-term maintainability.
· Strong communication and stakeholder management skills across product, engineering, architecture, operations, security, and client-facing teams.
Skills & Competencies
· Experience in insurance, Insurtech, BFSI, or other regulated, transaction-heavy domains.
· Exposure to policy administration, billing, accounting, claims, workflow orchestration, or reporting platforms within the insurance value chain.
· Experience with architecture frameworks and modelling approaches such as TOGAF, domain-driven design, UML, C4, or equivalent practical architecture methods.
· Familiarity with mixed technology landscapes involving .NET, Java/Spring Boot, enterprise workflow tools, and integration ecosystems.
· Experience with observability and reliability tooling such as Datadog, Dynatrace, Application Insights, Open Telemetry, Grafana, or similar.
· Working knowledge of Angular, React, or modern web application architecture patterns.
· Exposure to AI-enabled engineering, intelligent automation, or embedding AI capabilities into enterprise platforms.
· Leadership experience across globally distributed or virtual teams.
A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.
Key Responsibilities
- Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
- Conduct vulnerability assessments, penetration testing, and risk analysis.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
- Collaborate with IT and business teams to integrate security into system architecture and processes.
- Lead incident response drills and disaster recovery planning.
- Provide guidance and mentorship to junior cybersecurity staff.
- Stay updated on emerging threats, tools, and technologies.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5–10 years of proven experience in cybersecurity engineering or related roles.
- Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
- Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
- Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.
Skills
- Advanced problem-solving and analytical skills.
- Strong communication and leadership abilities.
- Ability to manage complex projects and handle escalations effectively.
- Proactive mindset with adaptability to evolving cyber threats.
WowPe is a leading fintech company revolutionizing the way businesses handle financial transactions. Our suite of innovative products includes a secure Payment Gateway for seamless online transactions, robust Payouts solutions to streamline bulk payments, and a versatile Point of Sale (POS) system for efficient in-store transactions. At WowPe, we’re dedicated to providing user-friendly, scalable, and reliable solutions that empower businesses to grow and succeed in today’s fast-paced digital economy.
We are looking for a highly skilled Cloud Infrastructure & Cloud Network Engineer to design, build, and manage secure, scalable hybrid cloud environments at WowPe. This role will focus on cloud networking, hybrid connectivity, infrastructure automation, security, reliability, and performance across on-prem and cloud platforms (AWS/Azure). You will play a critical role in ensuring high availability, security, and performance of our fintech platforms.
A Day in the Life
- Design and review cloud network architectures (VPC/VNet, routing, segmentation)
- Troubleshoot latency, connectivity, VPN, and performance issues
- Work with DevOps and application teams to support deployments and scalability
- Automate infrastructure provisioning and security guardrails
- Monitor network health, traffic flow, and system performance
- Ensure security, compliance, and disaster recovery readiness
- Support hybrid connectivity between on-prem data centers and cloud environments.
Key Responsibilities
Cloud Networking & Hybrid Architecture
- Design and implement VPC/VNet architectures, subnetting, routing tables, NAT, gateways, and secure segmentation
- Build and manage hybrid connectivity between on-prem data centers and cloud using Site-to-Site VPN, ExpressRoute, Direct Connect
- Configure and manage Layer 4 & Layer 7 load balancers for high availability and traffic distribution
- Architect DNS, CDN, and edge networking strategies for low-latency global access
Security & Zero-Trust
- Implement Zero-Trust networking using security groups, NACLs, identity-aware proxies, mTLS
- Design secure access controls and network isolation
- Work closely with security teams to ensure PCI, ISO, SOC compliance readiness
Automation, Platform & Reliability
- Automate infrastructure provisioning using Infrastructure as Code (Terraform/ARM/CloudFormation)
- Build self-healing, auto-scaling architectures with health checks and fault tolerance
- Support and manage Kubernetes clusters (EKS/AKS) including networking and service communication
- Integrate infra with CI/CD pipelines for safe and frequent deployments
Operations & Observability
- Perform advanced troubleshooting for latency, packet loss, MTU, routing loops
- Implement and manage monitoring, logging, and observability (Prometheus, Grafana, ELK, Azure Monitor, CloudWatch)
- Design and maintain disaster recovery architectures, multi-region networking, and replication strategies
- Ensure high availability, performance optimization, and cost efficiency
Basic Qualifications & Skills
- 4+ years of experience in Cloud Infrastructure & Cloud Networking
- Strong hands-on experience with AWS and/or Azure
- Deep understanding of VPC/VNet, routing, NAT, gateways, load balancers, DNS
- Experience with Hybrid connectivity (VPN, ExpressRoute, Direct Connect)
- Solid knowledge of network security, firewalls, access control, segmentation
- Hands-on experience with Infrastructure as Code (Terraform preferred)
- Experience in monitoring, troubleshooting, and incident handling
- Strong understanding of high availability, DR, and performance optimization
Preferred Qualifications
- Experience in fintech, BFSI, or high-compliance environments
- Exposure to Zero-Trust architecture and security best practices
- Experience with Kubernetes (EKS/AKS), service mesh, microservices networking
- Familiarity with CI/CD pipelines and DevOps practices
- Knowledge of CDN, edge networking, and global traffic management
- Experience with compliance frameworks (PCI-DSS, ISO 27001, SOC2)
- Ability to design large-scale, resilient, production-grade architectures
Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles
2
Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,
3
Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.
4
Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.
5
Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.
6
Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.
7
Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.
8
Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.
Job Description:
Job title : Cloud Architect
Experience: 10+ years
Location: Chennai / Pune / Hyderabad / Bangalore
Shift: UK Shift
Work Mode: Onsite(WFO)
Notice Period: Immediate Joiner/ serving notice period only
Project Scope:
This engagement automates end-to-end infrastructure build provisioning across on-prem and Azure. The team will build a shared ServiceNow-led intake, approval, orchestration, and closed-loop status model, using Jenkins/Ansible for on-prem builds and Azure DevOps/Terraform for cloud builds. Automation includes standards, security/compliance controls, scan gates, CMDB/change updates, and handover.
Roles and Responsibilities:
Define Azure automation architecture, governance, and reusable cloud build patterns.
Own Azure architecture for automated build provisioning using the ServiceNow-led control plane.
Define approved build patterns, SKUs, landing-zone integration, Terraform standards, Azure DevOps architecture, and guardrails.
Translate security, compliance, resiliency, tagging, cost, and data-residency requirements into automated controls.
Design ServiceNow, rules engine, Azure DevOps, Terraform, Azure Policy, CMDB, and callback integrations.
Review solution designs and assure quality with cloud, security, finance, and platform teams.
Required Skills:
Azure landing zones, networking, RBAC, Key Vault, Azure Policy, Terraform, Azure DevOps, FinOps, ServiceNow APIs.
10+ years in infrastructure/cloud engineering; 5+ years designing Azure solutions.
Bachelor’s degree or equivalent experience; Azure Solutions Architect certification preferred.
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com







