Security Architect
Experience
- 8+ years of experience in information/cybersecurity (including 3+ years in a dedicated Security Architect role)
About the Role
We are seeking a seasoned Security Architect to design, establish, and own the end-to-end security posture of our enterprise Virtual Desktop Infrastructure (VDI) platform. This platform runs across a complex hybrid ecosystem spanning public/private clouds and on-premises data centers.
In this role, you will be responsible for defining the overarching security architecture, conducting rigorous threat modeling, designing robust identity and access controls, establishing IaC security governance, and ensuring comprehensive compliance across the OS, network, and application layers.
Key ResponsibilitiesSecurity Architecture & Design
- Define and own the comprehensive security architecture for the enterprise VDI platform across hybrid environments (AWS, Azure, GCP, and on-premises).
- Design robust hybrid security models that enforce consistent controls, policy implementation, and governance across cloud-hosted and on-prem VDI workloads.
- Architect and scale zero-trust network infrastructure, micro-segmentation, and strict least-privilege access models.
- Develop, maintain, and publish security reference architectures, design standards, and compliance guardrails for platform engineering teams.
Infrastructure as Code (IaC) Security
- Audit and review Terraform configurations to detect security misconfigurations, over-permissioned IAM roles, and insecure defaults.
- Establish secure IaC standards, including standardized Terraform coding guidelines, secure module baselines, and pre-approved resource configurations.
- Integrate automated IaC security scanning tools (such as tfsec, Checkov, Terrascan, or Snyk IaC) seamlessly into active CI/CD pipelines.
- Implement policy-as-code frameworks (Open Policy Agent / HashiCorp Sentinel) to enforce strict, automated infrastructure guardrails.
- Partner directly with DevOps teams to remediate IaC vulnerabilities and drive secure infrastructure-as-code provisioning patterns.
Threat Modeling & Risk Management
- Lead threat modeling initiatives, vulnerability assessments, and security risk analyses across all hybrid VDI environments.
- Formulate strategic mitigation plans and oversee their technical implementation across the cloud and on-prem stacks.
- Manage and maintain the infrastructure security risk register, ensuring the timely remediation of critical security findings.
Cloud & Network Security
- Engineer cloud native security controls for multi-cloud VDI workloads (IAM policies, network security groups, secure VPC/VNet design).
- Define enterprise strategies for cloud workload protection, secure secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault), and key management (KMS/HSM).
- Architect highly secure hybrid connectivity solutions, utilizing VPN, SD-WAN, AWS Direct Connect, and Azure ExpressRoute.
- Optimize on-prem network defenses by designing robust firewall policies, DMZ configurations, VLAN segmentation, and automated intrusion detection/prevention systems (IDS/IPS).
Identity & Access Management (IAM)
- Architect robust SSO, MFA, certificate-based authentication, and Privileged Access Management (PAM) policies across the hybrid architecture.
- Design and manage secure integrations with corporate identity providers (Active Directory, LDAP, and SAML/OIDC-based IdPs).
- Enforce granular PAM policies customized for VDI administrators as well as general end-users.
Compliance, Certification & Governance
- Drive and lead enterprise-wide compliance and certification initiatives for the following standards:
- ISO/IEC 27001: Information Security Management System (ISMS)
- ISO/IEC 27017: Security controls for cloud services
- ISO/IEC 27018: Protection of PII in public clouds
- ISO/IEC 27701 & GDPR: Privacy Information Management & alignment
- ISO/IEC 20000-1: IT Service Management
- ISO 22301: Business Continuity Management
- Map internal platform controls accurately against CIS Benchmarks, NIST SP 800-53, and SOC 2 Type II frameworks.
- Orchestrate internal security audits, facilitate third-party risk assessments, and manage annual certification renewal processes.
Required Skills & Qualifications
- Experience: Minimum 8 years of dedicated experience in cyber/information security, with at least 3 years operating successfully in a Security Architect capacity.
- Hybrid Infrastructure: Demonstrated track record of securing complex environments across public clouds (AWS, Azure, or GCP) and traditional on-premises data centers.
- IaC & Automation: Strong hands-on experience with Terraform, including security code reviews, custom module assessments, and secure automated provisioning.
- Security Tooling: High proficiency with IaC security scanners (Checkov, tfsec, Terrascan, or Snyk IaC) and implementing policy-as-code frameworks (OPA or HashiCorp Sentinel).
- VDI Security: Deep technical expertise in virtualized infrastructure or VDI platforms (such as VMware Horizon, Citrix, or RDP-based ecosystems).
- Network & IAM: Comprehensive grasp of zero-trust frameworks, micro-segmentation, and core IAM principles (LDAP, Active Directory, SAML, OIDC, MFA, and PAM).
- Compliance Leadership: Robust hands-on experience implementing, auditing, and leading certification pipelines for ISO standards (27001, 27017, 27018, 27701) from gap assessment to official audit.
- Education: B.Tech, M.Tech, or equivalent degree in Computer Science, Information Security, or a closely related technical field.
Preferred Certifications
Possession of one or more of the following credentials is highly advantageous:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- ISO 27001 Lead Implementer or Lead Auditor
- SC-100 (Microsoft Cybersecurity Architect) or AZ-305 (Microsoft Azure Solutions Architect Expert)
- AZ-500 (Microsoft Azure Security Engineer)
- CEH (Certified Ethical Hacker)
Preferred Skills
- Practical deployment experience with secure hybrid networking (SD-WAN, Direct Connect, or ExpressRoute).
- Working familiarity with enterprise SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Qualys).
- Solid exposure to modern DevSecOps practices and embedding automated security testing directly into CI/CD workflows.
- General knowledge of container security and Kubernetes orchestration within hybrid VDI deployments.
Pay: ₹366,807.03 - ₹1,500,000.00 per year
Benefits:
- Health insurance
- Provident Fund
Work Location: In person