Gautam Buddha Nagar, Uttar Pradesh
Job Summary
Role Summary
The Security by Design Engineer will be responsible for embedding security into the application design and architecture lifecycle. The role will lead secure design reviews, threat modeling, architecture risk assessments, and security consulting to help teams identify and address security risks early in the SDLC.
Key Responsibilities
Perform architecture and design security reviews for new applications, major changes, and technology implementations.
Review architecture diagrams, data flows, trust boundaries, integration points, deployment models, and privileged components.
Conduct threat modeling exercises using structured approaches such as STRIDE and document applicable threats and mitigations.
Evaluate security controls for authentication, authorization, input validation, data protection, encryption, session management, logging, and error handling.
Provide security recommendations for web applications, APIs, cloud-native workloads, SaaS/COTS integrations, and third-party connectivity.
Work with architects, application owners, developers, product teams, and AppSec stakeholders to close design-level security risks.
Track security observations, mitigation plans, residual risks, and sign-off decisions in alignment with Secure SDLC governance.
Create reusable secure design patterns, checklists, and guidance for application teams.
Support management reporting, audit evidence, and governance reviews related to Security by Design activities.
Conduct awareness sessions for architects and development teams on secure design expectations.
Required Technical Skills
Strong understanding of Secure SDLC and Security by Design principles.
Hands-on experience in threat modeling, architecture risk assessment, and secure design review.
Knowledge of application architecture, API security, identity and access management, cloud security, encryption, and integration security.
Understanding of OWASP Top 10, OWASP ASVS, secure coding practices, and common application vulnerability categories.
Ability to analyze design artifacts, identify attack paths, recommend practical controls, and articulate risk clearly to stakeholders.
Good documentation, facilitation, and stakeholder communication skills.
Preferred Skills
Experience with Azure, AWS, or GCP security architecture reviews.
Exposure to API gateways, IAM patterns, secrets management, encryption/key management, and logging/monitoring requirements.
Knowledge of security frameworks, control mapping, risk acceptance, and audit evidence preparation.
Certifications such as CISSP, CSSLP, CCSP, SABSA, or equivalent are added advantage.
Experience
6 to 10 years of experience in Application Security, Security Architecture, Secure Design Review, or Secure SDLC governance.
Prior experience working directly with architects, engineering teams, product teams, and business stakeholders.
Expected Deliverables
Secure design review reports and control recommendations.
Threat modeling outputs with risks, mitigations, and residual risk decisions.
Security sign-off inputs for new applications and major changes.
Reusable secure architecture patterns, checklists, and awareness material.
Status reporting for design review coverage, open observations, and closure progress.
Key Responsibilities
Key Responsibilities
Perform architecture and design security reviews for new applications, major changes, and technology implementations.
Review architecture diagrams, data flows, trust boundaries, integration points, deployment models, and privileged components.
Conduct threat modeling exercises using structured approaches such as STRIDE and document applicable threats and mitigations.
Evaluate security controls for authentication, authorization, input validation, data protection, encryption, session management, logging, and error handling.
Provide security recommendations for web applications, APIs, cloud-native workloads, SaaS/COTS integrations, and third-party connectivity.
Work with architects, application owners, developers, product teams, and AppSec stakeholders to close design-level security risks.
Track security observations, mitigation plans, residual risks, and sign-off decisions in alignment with Secure SDLC governance.
Create reusable secure design patterns, checklists, and guidance for application teams.
Support management reporting, audit evidence, and governance reviews related to Security by Design activities.
Conduct awareness sessions for architects and development teams on secure design expectations.
Skill Requirements
Other Requirements
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-