Home
Jobs

Director - Application Security Architect

18 - 23 years

50 - 55 Lacs

Posted:Just now| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Job Purpose
This is a critical role within the Cyber Security Office, reporting directly to the Security Architecture Lead. With a focus on ensuring the security of GSK s applications, both commercial off-the-shelf (COTS) and home-grown developments, throughout their lifecycle. The ideal candidate will have extensive experience in life sciences and operational technology (OT) environments, with a strong background in application security, DevSecOps, and secure software development lifecycle (SDLC) practices. This role requires a strategic thinker, a problem solver, and an innovator who can collaborate effectively with cross-functional teams to enhance GSK s security posture.
Key responsibilities
  • This is an individual contributor role with a focus on strategic design and innovation
  • Develop and maintain a comprehensive application security architecture strategy that aligns with GSK s business goals and regulatory requirements
  • Lead the design and implementation of secure application architectures for both COTS and custom[1]developed applications
  • Integrate security best practices into the SDLC, ensuring that security is embedded in every phase of application development
  • Collaborate with development, DevOps, and IT teams to implement and enforce security controls and policies
  • Conduct threat modeling, risk assessments, and security code reviews to identify and mitigate vulnerabilities
  • Drive the adoption of DevSecOps practices, automating security testing and monitoring within CI/CD pipelines
  • Stay current with emerging threats, technologies, and trends in application security to inform strategic decisions
  • Provide technical guidance and mentorship to security engineers and development teams
  • Ensure compliance with industry standards and regulatory requirements (e.g., GDPR, HIPAA, PCI)
  • Communicate complex security concepts and strategies to non-technical stakeholders, ensuring understanding and buy-in
  • Lead the evaluation and selection of security tools and technologies to enhance application security
  • Conduct security assessments and gap analyses to identify and mitigate security risks
  • Support the development and implementation of security architectures across various domains, including AI/ML, cloud, and network security
  • Continuously evaluate and refine application security solutions to enhance their effectiveness and efficiency
  • Establish metrics to measure the effectiveness and performance of application security solutions
Required skills
  • Proven experience in developing and implementing application security strategies and architectures
  • Extensive knowledge of secure coding practices, threat modeling, and risk assessment methodologies
  • Strong expertise in DevSecOps, CI/CD pipelines, and automation of security testing
  • Hands-on experience with security tools and technologies (SAST, DAST, RASP, WAF) Experience in life sciences and OT environments, with a deep understanding of regulatory requirements
  • Strong communication and collaboration skills, with the ability to engage with technical and non-technical stakeholders
  • Proficiency in writing, developing, and maintaining technical documentation, including security standards, strategies, and implementation plans
  • Ability to prioritize and filter actions to focus on those with significant impact on the program
  • Excellent problem-solving and analytical skills, with the ability to work under pressure
  • Knowledge of AI and machine learning security considerations
  • Ability to think creatively and drive innovation in application security
  • Strategic thinker with a business-focused mindset
  • Strong collaborator and innovator
  • Ability to communicate complex security concepts to non-technical stakeholders
  • Problem solver with a proactive approach to identifying and mitigating security risks
  • Experience with cloud security (AWS, Azure, GCP)
Required Qualifications
  • Advanced degree in Computer Science
  • Total 18+ years of experience out of which 7+ years of cyber security engineering experience
  • Certifications such as CISSP, CISM, CEH, along with TOGAF, SABSA, or Purdue
  • Experience in security automation and orchestration
  • Understanding of AI and machine learning security considerations
Skills
Cyber Security Architecture, Secure Coding Practices, Security Controls, Security Policies, Security System, Security System Design, Test Planning, Vulnerability Management, Vulnerability Scanning
If you come across unsolicited email from email addresses not ending in gsk.com or job advertisements which state that you should contact an email address that does not end in gsk.com , you should disregard the same and inform us by emailing askus@gsk.com, so that we can confirm to you if the job is genuine.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
GSK India
GSK India

Pharmaceuticals & Biotechnology

Mumbai

Approximately 2,000 Employees

38 Jobs

    Key People

  • Vas Narasimhan

    CEO of GSK
  • Diana W. Bianchi

    Chief Scientific Officer

RecommendedJobs for You

Mumbai, Mumbai Suburban, Mumbai (All Areas)