Cyber Security Lead / Architect

Department Icon IT / Software Development & Related
102+ Applicants
Posted: 1 day ago
12-16 years
Bengaluru / Bangalore, Karnataka
work from office

Posted: 1 day ago
|
Applicants: 102+
Job Description
Similar Jobs
Please verify your account first! Send OTP

Job Description

Job Title

Cyber Security Lead / Architect

The Cyber Security Architect is responsible for defining, implementing, and governing cybersecurity architectures for Industrial Automation and Control Systems (IACS) and embedded product platforms operating in regulated and safety‑critical environments. The role ensures that products and systems are designed and delivered with strong cybersecurity foundations, aligned with IEC 62443, applicable regulatory requirements (including EU Cyber Resilience Act), and relevant industry best practices.

The position requires a hands‑on security architect capable of working across multiple engineering teams, product lines, and customer programs, ensuring consistent application of security principles while supporting diverse domain needs such as industrial automation, connected products, and vehicle‑adjacent systems.

Roles & Responsibilities

1. Security Architecture & Design Leadership

  • Define and maintain cybersecurity architectures for industrial and embedded systems, ensuring secure‑by‑design principles.
  • Guide security design decisions across multiple products and platforms.
  • Translate security standards and regulatory requirements into practical system and product architectures.
  • Provide architectural input on security trade‑offs involving risk, performance, cost, and lifecycle considerations.

2. Threat Modeling & Risk Analysis

  • Lead threat modeling and Threat Analysis and Risk Assessment (TARA) for products and systems.
  • Identify and assess security risks across system, component, and interface levels.
  • Define and track mitigation strategies aligned with product and operational risk profiles.

3. Secure Product Lifecycle Management

  • Ensure cybersecurity is addressed throughout the entire product lifecycle, including:
  • Concept and requirements definition
  • Architecture and design
  • Development and verification
  • Release, deployment, and post‑deployment monitoring
  • Oversee penetration testing, vulnerability assessment, and remediation activities.
  • Ensure security evidence and documentation are suitable for customer and regulatory review.

4. Security Controls & Secure Development Practices

  • Define and standardize security controls across products and systems.
  • Promote adoption of secure coding practices and security‑focused design reviews.
  • Align development practices with NIST Secure Software Development Framework (SSDF) and industry security guidance.

5. Compliance, Standards & Regulatory Alignment

  • Ensure alignment of products and systems with:
  • IEC 62443 series for industrial and control systems
  • Applicable regional and sector‑specific cybersecurity regulations (e.g., EU CRA)
  • Support customer, internal, and third‑party security assessments and audits.
  • Interpret standards and regulations into actionable engineering and documentation requirements.

6. Cross‑Team Guidance & Capability Enablement

  • Provide guidance and technical direction to engineering teams on cybersecurity topics.
  • Review security designs, threat models, and test strategies across projects.
  • Enable consistent application of security practices across domains and product variations.

7. Stakeholder & Customer Interaction

  • Collaborate with development teams, quality teams, and system architects to address security requirements.
  • Engage with customers, assessors, and regulatory stakeholders to explain security concepts, design decisions, and compliance posture.
  • Communicate security risks and recommendations clearly at both technical and leadership levels.

8. Incident Response, Monitoring & Threat Awareness

  • Define approaches for cybersecurity monitoring and incident response for deployed systems.
  • Monitor emerging threats, vulnerabilities, and advisories relevant to industrial, embedded, and connected systems.
  • Proactively recommend improvements to architectures and controls based on threat intelligence.

Mandatory Skills

  • Strong expertise in IEC 62443 and industrial cybersecurity concepts.
  • Proven experience in security architecture for industrial automation, embedded systems, or connected products.
  • Looking to get Placed? Try our Placement Guarantee Plan

    Hands‑on experience with:
  • Threat modeling and TARA
  • Secure product development lifecycles
  • Vulnerability management and penetration testing
  • Knowledge of NIST CSF and NIST SSDF.
  • Experience with product security, including:
  • Embedded systems and firmware
  • Thick‑client and edge applications
  • Mobile or companion applications (where applicable)
  • Ability to operate across multiple projects, domains, and customer programs in a services environment.

Desirable / Good‑to‑Have Skills

  • Exposure to automotive or vehicle‑adjacent cybersecurity practices, standards, or customer expectations.
  • Familiarity with cybersecurity regulations such as:
  • EU Cyber Resilience Act (CRA)
  • NIS2
  • Data protection and privacy regulations (awareness level)
  • Experience supporting customer or third‑party security audits.
  • Ability to mentor engineers and architects on secure design and implementation practices.

(Certifications are valued but do not replace hands‑on architectural expertise.)

Mandatory Skills

IEC 62443, Industrial cybersecurity, Cybersecurity architecture, Security architecture (industrial / embedded), Industrial automation security (IACS), Embedded systems security, Connected products security, Threat modeling, TARA (Threat Analysis and Risk Assessment), Secure Product Development Lifecycle (SPDLC) / secure SDLC, Vulnerability management, Penetration testing, NIST CSF, NIST SSDF, Product security, Embedded firmware security, Thick client applications security, Edge applications security, Mobile

Desirable Skills

Automotive cybersecurity exposure, Vehicle-adjacent cybersecurity practices, Cybersecurity regulations familiarity, EU Cyber Resilience Act (EU CRA), NIS2, Data protection regulations (awareness), Privacy regulations (awareness), Customer security audits support, Third-party security audits support, Mentoring engineers / architects, Secure design mentoring, Secure implementation mentoring, Security certifications (valued)

Skills to be evaluated on

IEC-62443-Industrial-cybersecurity-Cybersecurity-architecture-Security-architecture-(industrial-/-embedded)-Industrial-automation-security-(IACS)-Embedded-systems-security-Connected-products-security-Threat-modeling-TARA-(Threat-Analysis-and-Risk-Assessment)-Secure-Product-Development-Lifecycle-(SPDLC)-/-secure-SDLC-Vulnerability-management-Penetration-testing-NIST-CSF-NIST-SSDF-Product-security-Embedded-firmware-security-Thick-client-applications-security-Edge-applications-security-Mobile

Years Of Experience

12 to 16 Years

Skills

CybersecuritySoftware DevelopmentTesting

If an employer asks you to pay any kind of fee, please notify us immediately. Jobaaj does not charge any fee from the applicants and we do not allow other companies also to do so.

Important dates & deadlines?

Application Deadline

17 Jul 26, 06:02 PM IST

Similar Jobs

View All
Loading...
Bag Logo
Jobaaj
Don't Miss out any Updates

Subscribe now for the latest job alerts
and never miss an update

Job Alert
Google hiring for Specific Roles Apply Now!
1 min ago
New Opportunity
Amazon is hiring freshers Apply Now!
5 min ago
Featured Jobs
Microsoft opening 50+ positions Apply Now!
10 min ago

Cyber Security Lead / Architect

Share with