Company Overview:
Bose Professional is a leader in the professional audio industry, specializing in the design and manufacturing of cutting-edge audio solutions including loudspeakers, amplifiers, signal processing devices, controls, software, and accessories. As we continue to expand our team, we are seeking a Information Security Architect to join us on our journey.
We have organized ourselves culturally around a set of shared values. We are a
team first, which means we are collaborative and support each other toward our common goals. We start everything from the outside in, starting with the
customer and solving from there
. We value
trust, so we are a company of people who are open and direct, avoid politics, and who do what it takes to deliver on our commitments. And as we work together, we are empathetic, courteous, and fair, because we
respect each other. Finally, we believe that creativity and innovation belong in all parts of the company in order to drive
excellence in everything we do.
Position Overview:
The Information Security Architect will lead Bose Professional’s day-to-day security function across internal IT security, secure product development, customer-facing digital services, and compliance needs. This hands-on leadership role in a lean environment requires someone who can assess risk, guide technical teams, coordinate internal and external resources, work with business stakeholders, and build practical security programs that support business growth.
Key Responsibilities:-
Lead and mature the company’s security and privacy program across internal and customer facing systems.
-
Establish and continually improve an application security program covering secure development practices, vulnerability management, code scanning, remediation planning, and product security needs.
-
Coordinate security operations and oversee service performance with external partners, including managed SOC services.
-
Build and maintain the foundation for SOC 2 readiness and broader compliance objectives.
-
Assess and communicate security risk in a clear, business-oriented way that enables informed decisions and balanced prioritization.
-
Use modern tools, automation, and AI-enabled capabilities to improve security operations, testing, analysis, and reporting.
-
Support privacy and data protection efforts by aligning security controls with global privacy expectations and customer trust requirements.
-
Provide security guidance, communication, and leadership to employees, technical teams, service providers, and stakeholders across global locations.
-
Support Company objectives by completing additional tasks as needed
Qualifications:-
7+ years of technical experience in IT, engineering, security, infrastructure, cloud, software, or a related discipline, including at least 4 years focused on information security.
-
Ability to operate hands-on with technical teams and core enterprise technologies while also guiding others through implementation and remediation work.
-
Working knowledge of security practices across identity, endpoint protection, vulnerability management, logging and monitoring, incident response, network security, cloud platforms, and software development environments.
-
Experience with secure software development, application security testing, vulnerability remediation, or product security programs.
-
Strong communication skills, with the ability to explain technical and risk concepts to engineering teams, business stakeholders, executives, and global colleagues.
-
Comfort using AI tools, automation, or emerging technologies to improve security workflows, analysis, documentation, and decision support.
-
Practical understanding of risk management, security controls, and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, or similar standards.
-
Awareness of global privacy and data protection expectations and how security controls support responsible data handling.
-
Experience in a lean or growing technology organization where security responsibilities require both strategic ownership and hands-on execution.
-
Experience working with managed security providers, SOC partners, penetration testing providers, or external auditors.
-
Exposure to enterprise security, IT, and development platforms such as Microsoft 365, Entra ID, Defender, Intune, AWS, GitHub, Jira, SIEM, vulnerability management, and code scanning tools.
-
Security certifications such as CISSP, CISM, CCSP, Security+, AWS Security, Microsoft Security, or similar credentials are helpful but not required.
-
Experience supporting customer-facing SaaS, connected products, digital services, or software-enabled hardware products.
We are looking for someone who is pragmatic, collaborative, curious, and comfortable balancing security, business needs, customer trust, and operational reality. The right candidate will bring strong judgment, technical credibility, and the ability to build security maturity in a way that helps the business move forward responsibly.
Bose Professional is an equal opportunity employer and values diversity in the workplace. We encourage all qualified individuals to apply.
Position/Title: Information Security Architect
Time Type: Full-time
Job Exempt: Yes
Pay Rate Type: Salary
Location: Mangalore, India (Hybrid)
Reports to: VP of IT & Security
Department: IT
BYZPHmwTze