Tech Architect_Security
Your Role and
Responsibilities
You will research, lead, collaborate, mentor and provide Secure architecture
programming practices for ELM in such a way to ensure secure compliance to
audit activities across not only ELM, but its supporting AI stack that protects
IBM's and our clients assets via agile methodologies.
Responsibilities
Recommend and implement security tools, processes and procedures
to assist with maintaining compliance of development systems
Drive and maintain security throughout the entire Software
Development Life cycle, incorporating Security and Privacy by Design
principles
Oversee application security testing including Static and Dynamic Code
scans (SAST/DAST), Vulnerability Assessment and Penetration Testing
(VAPT)
Ensure product compliance with corporate policy, evolving industry
standards, and relevant regulatory controls
Ongoing reporting of compliance posture to senior management
Document and communicate security features and best practices to
internal and external stakeholders
Participate in product risk assessments and threat modelling
Support product team through internal and external audits
Posting Country India
State / Province GUJARAT
City / Township
/ Village Ahmedabad
Travel Required No Travel
Position Type Professional
Required
Education Bachelor's Degree
Required
Technical and
Professional
Expertise
10+ years of relevant industry experience
5+ years of Information Security experience, including 3+ years in
Software Development
Good exposure to various Architecture and Design Modelling Practices
and Tools.
Detailed technical knowledge of techniques, standards and state-of-the
art capabilities for authentication/authorization/identity-management
(SSO/OAuth/OpenID/RBAC/ABAC etc), applied cryptography, security
vulnerabilities and remediation.
Familiar with common threats and vulnerabilities applicable to Web
Applications and Middleware (eg. OWASP Top 10)
3+ years experience working with SQL (Oracle, DB2) data storage and
database servers
Understanding and experience with noSQL data storage (MongoDB,
CouchDB, etc.)
Experience with development of application's with application servers
(WAS, Liberty, Tomcat)
Full stack development experience with Java backend.
Preferred
Technical and
Professional
Experience
Ability to adapt to changing requirements.
Exposure to security architecture and design practices in the Cloud
Native systems will be an added advantage and a key differentiator.
Proven interpersonal skills
Understanding of Web proxying/scaling technologies
Excellent written and verbal communication skills as well as business
acumen and a commercial outlook
Security certifications are an added bonus (CISSP, CCSP, CISM, CEH,
etc)
Preferred
Education Master's Degree
Experience : 10+ years
