Job
Description
As a Product Security Architect at Capgemini, your role will involve assessing the security of software/Product architecture and guiding product architects to ensure security is integrated at the design level itself. **Key Responsibilities:** - Assess the security for software/Product architecture and guide the product architects to ensure security is built into at the design level. - Own the development of cyber security artifacts including threat models and lead discussions on identifying mitigations. - Assist Engineering teams in triaging and identifying fixes for detected product vulnerabilities. - Coordinate security and privacy assessments with internal and external teams, including VAPT, to determine compliance and security posture. - Aid business units in developing and implementing product security and privacy practices, including policies, standards, guidelines, and procedures. - Verify that security and privacy requirements defined in security plans, policies, and procedures are followed, and protection measures are functioning as intended. - Guide the business unit in managing the resolution of security audit or review findings. - Provide security risk management and advice on strategic direction for product and information security. - Assist with security incidents and review risks and impacts of breaches to protected systems. - Review proposed services, engineering changes, and feature requests for security implications and necessary security controls. **Qualifications:** - Bachelor's degree in engineering. - 7+ years of development and security experience, including application security, mobile security, network security, OS security, and Cloud Security. - Experience in Rest API, Kubernetes, and container security assessments. - Product/Information security experience throughout service/product development and deployment phases. - Good understanding of AWS services, specifically related to security. - Experience in designing security solutions. - Hands-on experience in execution and review of Static & Dynamic Code Analysis reports and ability to discuss with development teams for true positives. - Knowledge of penetration testing methodologies and tools. - Experience in automation of pen test scenarios using Python or any other languages. - Strong interpersonal skills and ability to facilitate diverse groups, help negotiate priorities, and resolve conflicts among project stakeholders. - Sound security engineering knowledge to collaborate with Tech Leads and software/products architects to ensure secure products. - Knowledge of information system architecture and security controls such as firewalls and specialized appliances. - Understanding of Cryptography, Encryption Algorithms, PKI, CA, OAuth authentication, and 2FA. **Additional Company Details:** The ideal candidate for this role would have experience in software development and security assessments, with exposure to privacy requirements and understanding of HI-TRUST and SOC2. Preferred skills include excellent cyber security capabilities, knowledge of secure software development lifecycle practices, and up-to-date knowledge of current and emerging security threats and techniques. Security certifications like OSCP, CCSP, or CISSP are considered advantageous.,