Location: Remote | Hyderabad, India
The Lead Software Security Architect plays a critical role in safeguarding Hyland's products and services by ensuring secure design, rigorous testing, and proactive vulnerability management. Acting as the bridge between security and engineering teams, this role requires strong communication and advisory skills, with an equal focus on application security, infrastructure/cloud security, and software architecture.
This position works closely with engineering teams to promote secure coding practices, identify potential risks, and serve as the organization's primary trusted advisor on all matters related to software security. This is a high-impact leadership role for a seasoned security professional who thrives in a fast-paced environment and is passionate about building a strong, company-wide security culture.
-
Review software designs, test plans, and security controls to ensure alignment with established standards.
-
Maintain and evolve threat models; define and review controls to address current and emerging risks.
-
Assess, prioritize, and drive remediation of internal and external vulnerabilities, including third-party components.
-
Design and deliver secure development training; promote a strong security culture across engineering teams.
-
Act as the primary point of contact and trusted advisor for security matters across the organization.
-
Mentor and coach team members; provide timely feedback to leadership on team capabilities and growth areas.
Languages
Java, .NET, Python, JavaScript, TypeScript
Authentication & Protocols
SAML, OAuth2.0, OpenID Connect, REST API, GraphQL, WebSocket, Message Queue
Cloud – AWS
EKS, WAF, API Gateway, Lambda, S3, SQS, RDS
Security Testing
SAST, SCA, DAST, GitHub Advanced Security (preferred), Veracode, Checkmarx, Snyk
Security Practices
OWASP Top 10, Vulnerability Management, Threat Modeling, Secret Management
AI & Emerging Tech
LLM / Agentic AI
DevOps & CI/CD
DevSecOps Tooling
Compliance Frameworks
SOC2, NIST 800-53, ISO 27001, FedRAMP
-
Bachelor's degree in Computer Science or related field, with a minimum of 8 years of relevant security architecture and application security experience, preferably within a professional services company or similar environment working with startups and large security-mature companies.
-
3+ years of experience working with stakeholders across many functions, with strong leadership, sound judgment, and business acumen.
-
Strong understanding of secure coding practices in Java, .NET, JavaScript/TypeScript, and Python; familiarity with DevSecOps principles is beneficial.
-
Demonstrated ability to influence, motivate, and mobilize team members and business partners; ability to coach and mentor team members in a timely manner.
-
Excellent collaboration, interpersonal, and communication skills; able to effectively convey technical concepts to non-technical audiences and maintain professionalism across all teams.
-
Understanding of security vulnerabilities, attacker exploit techniques, and methods for remediation.
-
Prior working experience in or with an Architecture, Engineering, or Software Development Team.
-
Understanding of best practices in one or more security engineering specialties: secure development, DevOps, cryptography, network security, security operations, cloud/systems security, policy, and incident response.
-
LLM/Agentic AI understanding and related threats and risks associated.
-
Capacity and tolerance for extreme context switching and interruptions while remaining productive and able to provide effective, safe guidance.
-
Experience with secret management and authentication/authorization protocols (SAML, OAuth2.0, OpenID Connect, REST API, GraphQL, WebSocket, Message Queue).
-
Hands-on experience with AWS cloud security services (EKS, WAF, API Gateway, Lambda, S3, SQS, RDS) and Docker.
-
Experience with SAST, SCA, and DAST tools; GitHub Advanced Security preferred — Veracode, Checkmarx, Snyk, and open-source tools also welcomed.
-
Familiarity with SOC2, NIST 800-53, ISO 27001, and FedRAMP compliance frameworks.
-
Experience assisting with gap assessments, automation of evidence gathering, and collaboration with architects, developers, and GRC teams.
-
CISSP or CSSLP certification preferred but not mandatory.
Hyland is the pioneer of the Content Innovation Cloud™, delivering ubiquitous enterprise intelligence to organizations with solutions that unlock actionable insights and drive automation. © Hyland. All rights reserved.
Trusted by thousands of organizations worldwide, including many of the Fortune 100, Hyland's solutions create the foundation for a connected, agentic enterprise, where teams harness the power of AI to redefine how they operate and engage with those they serve. For additional information on Hyland's platform and services, please visit Hyland.com.
Since 1991, it has been Hyland's mission to help our employees, customers and partners exceed their potential with our industry-leading content services platform. Our employees exude a contagious energy and are passionate about what they do – whether it's helping customers succeed, raising up their fellow Hylanders, or engaging in the communities where they live and work.
The #HylandLife hashtag encompasses our employee-centric culture. Our employees live our culture day in and day out by bringing their best self to work. Hyland supports them to do just that through career development resources, wellbeing programs and innovation practices. We thrive on diverse viewpoints and new ideas and believe that a positive, inclusive workplace is imperative to sustainable success.
As we've grown to a company of nearly 4,000 strong, we have the opportunity to make a significant impact on our communities. We strongly support employee initiatives and align our giving campaigns and programs to organizations that are important to them.
Hyland is an equal opportunity employer. We value diversity and are committed to providing an inclusive workplace for all employees and applicants. Employment decisions are made without regard to any characteristic protected by applicable laws and regulations. Information collected during the hiring process is used solely to assess qualifications, verify identity, and comply with legal requirements.