Experience
7 - 12 yrs
Job Location
Chennai, India
Vacancy
1
Designation
Product Security Engineer
Job Type
Not specified
Job Description
Product Security and Privacy Architect
- Chennai, IN
- Mid-senior level
- Engineering Science
- No Travel Required
Profile Summary:
As part of the Product Security and Privacy team, reporting to the Chief Product Security Privacy Architect, you will support product teams in adopting and implementing HID's security and privacy program. Accountable for the quality, consistency, and defensibility of all security privacy related artifacts you guarantee that outputs are audit-ready, and not just done. You will have opportunities to work on a very wide portfolio of applications based on different technologies (Web, Embedded, Mobile, Desktop) within a very diverse and international context covering all five HID Business Areas.
Qualifications
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Roles Responsibilities (Other duties may be assigned)
- Leads day-to-day security/privacy architecture governance, escalates and obtains approval from the Chief Product Security Privacy Architect as required.
- Define corporate wide security and privacy requirements, controls, and standards.
- Define corporate wide Secure Coding, third-party, deployment policies other architecture-related standards.
- Define required training content.
- Define paved roads/security and privacy-by-design patterns and libraries.
- Lead development of AI-enabled PSP Architecture capabilities: define use cases, requirements, and success criteria.
- Own the threat modeling framework and quality bars.
- Run/approve security privacy architecture reviews.
- Lead audit/assessment planning, evidence of expectations, and defensibility.
- Responsible for tooling selection and integration related to security privacy architecture domain.
- Architect for compliance, analyze new regulations and standards to identify gaps in the platforms capabilities, standards, and controls.
- Assess New Acquisitions Architecture and contribute to due diligence on a needed basis.
Primary Duties: These define the broader responsibilities and areas of ownership within the role
- Provide recommendations for risk acceptance and exception requests.
- Provide input on tooling strategy and integration guidance for non-architecture related domains.
- Provide guidance on security requirements for supply chain tooling, pipeline architecture, and associated standards.
- Validate that platform architecture enables enforcement of PSP security controls.
- Provide expert input on exploitability, attack paths, and mitigation options during Incident handling process
- Provide guidance on true risk vs noise for security tool outputs and penetration tests.
- Provide subject-matter depth during training delivery: advanced QA, edge cases, Offer office hours or follow-ups for complex topics
Technical Skills:
- Experience contributing to at least one Secure Software Development Lifecycle (SSDL) program, either as a security architect, security champion, or similar role.
- Working knowledge of general principles of application security
- Working knowledge of threat modeling principles.
- Working Knowledge of security standards (OWASP, ISO, NIST, ...).
- Knowledge of security regulations, such as the Radio Equipment Directive (RED), Cyber Resilience Act (CRA), Federal Information Processing Standards (FIPS), and Common Criteria (CC) or equivalent.
- Good understanding of cryptographic principles, including algorithms, key management, and protocols.
- Experience using security tools (SAST, DAST, SCA, Vulnerability Scanners, Secret Scanners).
- Hands-on experience in at least one, preferably more, of these application domains:
- Embedded device Security
- Mobile security
- Web API security
- Desktop security.