Now hiring

Product Security and Privacy Architect (Chennai, IN, 600 032) @ ASSA ABLOY AB

Chennai, IN, 600 032OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><img src="https://dmscdn.successfactors.com/27c0a91770d9ecac9ed08a9f63f401a6121aa728d77960676d754d492bcae147/static_content/77526a33984e424982f2/HIDBanner.png" alt="" width="780" height="130"> </p> <p> </p><h1><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>An Amazing Career Opportunity for Product Security and Privacy Architect<br></strong><strong>Location: Chennai, India (Hybrid)<br></strong><strong>Job ID: 47565</strong></span></h1> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong> </strong></span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Profile Summary:</strong></span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><em>As part of the Product Security and Privacy team, reporting to the Chief Product Security &amp; Privacy Architect, you will support product teams in adopting and implementing HID’s security and privacy program.<br></em><em>Accountable for the</em> <em>quality, consistency, and defensibility of all security &amp; privacy related artifacts you guarantee that outputs are “audit-ready,” and not just “done.<br></em><em>You will have opportunities to work on a very wide portfolio of applications based on different technologies (Web, Embedded, Mobile, Desktop) within a very diverse and international context covering all five HID Business Areas.</em></span><br><br></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>About HID Global</strong></span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">HID Global powers the trusted identities of the world’s people, places and things. We make it possible for people to transact safely, work productively and travel freely. Our trusted identity solutions give people secure and convenient access to physical and digital places and connect things that can be accurately identified, verified and tracked digitally. Millions of people around the world use HID products and services to navigate their everyday lives, and over 2 billion things are connected through HID. We work with governments, educational institutions, hospitals, financial institutions, industrial businesses, and some of the most innovative companies on the planet. Headquartered in Austin, Texas, HID Global has over 4500 employees worldwide and operates international offices that support more than 100 countries. HID Global® is an ASSA ABLOY Group brand. HID Global has is the trusted source for secure identity solutions for millions of customers and users around the world. In India, we have two Engineering Centre (Bangalore and Chennai). Global Engineering Team is based in Chennai and one of the Business Unit Engineering team is based in Bangalore. Check us out: <a href="http://www.hidglobal.com">www.hidglobal.com</a> and <a href="https://youtu.be/23km5H4K9Eo" target="_blank" rel="noopener">https://youtu.be/23km5H4K9Eo</a></span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">LinkedIn: <u> </u><a href="http://www.linkedin.com/company/hidglobal/mycompany/">www.linkedin.com/company/hidglobal/mycompany/</a></span></p> <p><br><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Are You Ready to Join the Team?</strong></span><br><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Our company is committed to finding the best and the brightest talent to help us reach the top. If you are a dynamic, highly skilled, experienced Cloud engineer and technology enthusiast, and you enjoy working in a rapid pace within a rapidly growing business environment, then you will want to consider this position. If you excel at communication, collaboration, and unrelenting innovation, we want to talk to you. And if you bring dedication, positive energy and integrity to the table, you just might be the right fit for our team.</span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong> </strong></span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Qualifications <br></strong>To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.</span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong> </strong></span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Roles &amp; Responsibilities </strong><strong>(Other duties may be assigned)<br></strong></span></p> <ul type="disc"> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Leads day-to-day security/privacy architecture governance, escalates and obtains approval from the Chief Product Security &amp; Privacy Architect as required.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Define corporate wide security and privacy requirements, controls, and standards.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Define corporate wide Secure Coding, third-party, deployment policies &amp; other architecture-related standards.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Define required training content.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Define paved roads/security and privacy-by-design patterns and libraries.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Lead development of AI-enabled PSP Architecture capabilities: define use cases, requirements, and success criteria.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Own the threat modeling framework and quality bars.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Run/approve security &amp; privacy architecture reviews.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Lead audit/assessment planning, evidence of expectations, and defensibility.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Responsible for tooling selection and integration related to security &amp; privacy architecture domain.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Architect for compliance, analyze new regulations and standards to identify gaps in the platform&apos;s capabilities, standards, and controls.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Assess New Acquisitions Architecture and contribute to due diligence on a needed basis.</span></li> </ul> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong><br><br>Primary Duties:<br><br></strong>These define the broader responsibilities and areas of ownership within the role</span></p> <ul type="disc"> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Provide recommendations for risk acceptance and exception requests.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Provide input on tooling strategy and integration guidance for non-architecture related domains.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Provide guidance on security requirements for supply chain tooling, pipeline architecture, and associated standards.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Validate that platform architecture enables enforcement of PSP security controls.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Provide expert input on exploitability, attack paths, and mitigation options during Incident handling process</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Provide guidance on true risk vs noise for security tool outputs and penetration tests.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Provide subject-matter depth during training delivery: advanced Q&amp;A, edge cases, Offer office hours or follow-ups for complex topics</span></li> </ul> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong> </strong></span></p> <div align="center"> </div> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Technical Skills:</strong></span></p> <ul> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Experience contributing to at least one Secure Software Development Lifecycle (SSDL) program, either as a security architect, security champion, or similar role.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Working knowledge of general principles of application security</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Working knowledge of threat modeling principles.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Working Knowledge of security standards (OWASP, ISO, NIST, ...).</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Knowledge of security regulations, such as the Radio Equipment Directive (RED), Cyber Resilience Act (CRA), Federal Information Processing Standards (FIPS), and Common Criteria (CC) or equivalent.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Good understanding of cryptographic principles, including algorithms, key management, and protocols.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Experience using security tools (SAST, DAST, SCA, Vulnerability Scanners, Secret Scanners).</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Hands-on experience in at least one, preferably more, of these application domains:</span> <ul style="list-style-type:circle"> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Embedded device Security</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Mobile security</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Web &amp; API security</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Desktop security.</span></li> </ul> </li> </ul> <p><br><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Preferred Qualifications</strong></span></p> <ul type="disc"> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Cloud infrastructure, Supply Chain, and deployment Security</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Experience with Agile/SAFe Methodology</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Experience with usage of AI tools in the context of a security program.</span></li> </ul> <p> </p> <div align="center"> </div> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Education and/or Experience</strong></span></p> <ul> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Master&apos;s Degree, computer science, or similar qualifications.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">At least <strong>3 years</strong> in software/product security, application security, or security architecture</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">At least <strong>7 years of</strong> hands-on software engineering / QA / DevOps earlier in career (or equivalent).</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">At least one security or privacy certification (CISSP, CIPT, CSSLP, CEH, ...) is a plus.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Proven ownership of at least one of: threat modeling program, secure design review governance, audit evidence management, security tooling strategy, penetration testing program or similar.</span></li> </ul> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong><br>Soft Skills<br></strong></span></p> <ul> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Ability to effectively communicate complex concepts clearly and effectively in the English language, both verbally and in writing.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Like training and knowledge-sharing, with a strong motivation to ensure the security program is successfully implemented by the teams.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Highly adaptable and approachable, fostering collaboration and open communication.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Ability to tailor your communication to different audiences such as product owners, development teams, architects, and other high-level users.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">Strong technical acumen with the ability to engage effectively with development teams and Continuous learning mindset<strong>.<br></strong></span></li> </ul> <h2> </h2> <h2><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Why apply?</strong></span></h2> <ul> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Empowerment:</strong> You’ll work as part of a global team in a flexible work environment, learning and enhancing your expertise. We welcome an opportunity to meet you and learn about your unique talents, skills, and experiences. You don’t need to check all the boxes. If you have most of the skills and experience, we want you to apply.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Innovation:</strong> You embrace challenges and want to drive change. We are open to ideas, including flexible work arrangements, job sharing or part-time job seekers.</span></li> <li style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt"><strong>Integrity:</strong> You are results-orientated, reliable, and straightforward and value being treated accordingly. We want all our employees to be themselves to feel appreciated and accepted.</span></li> </ul> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">This opportunity may be open to flexible working arrangements.</span></p> <p><span style="font-family:'times new roman', times, sans-serif;font-size:14.0pt">HID is an Equal Opportunity/Affirmative Action Employer – Minority/Female/Disability/Veteran/Gender Identity/Sexual Orientation.</span></p><p> </p> <p><strong>We make it easier for people to get where they want to go!</strong><br>On an average day, think of how many times you tap, twist, tag, push or swipe to get access, find information, connect with others or track something. HID technology is behind billions of interactions, in more than 100 countries. We help you create a verified, trusted identity that can get you where you need to go – without having to think about it. <br> <br>When you join our HID team, you’ll also be part of the ASSA ABLOY Group, the global leader in access solutions. You’ll have 63,000 colleagues in more than 70 different countries. We empower our people to build their career around their aspirations and our ambitions – supporting them with regular feedback, training, and development opportunities. Our colleagues think broadly about where they can make the most impact, and we encourage them to grow their role locally, regionally, or even internationally. As we welcome new people on board, it’s important to us to have diverse, inclusive teams, and we value different perspectives and experiences.</p> <p> #LI-HIDGlobal</p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores