Kpmg India Services Llp

Associate Director- GTS Security Architect

Kpmg India Services Llp
Hyderabad
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 14 yearsMin. 14 years

Job Description

Associate Director- GTS Security Architect

 Roles & responsibilities
1. Security Architecture & Design 
Own, govern, and continuously evolve security architecture standards, patterns, reference architectures, and implementation guidance. 
Ensure security requirements are integrated throughout the Secure/System Development lifecycle (S/SDLC). 
Review and approve solution architectures and act as the final design authority for enterprise security standards. 
Define security requirements for cloud-native, hybrid-cloud, SaaS, and on-premises solutions. 
Design security architectures that support confidentiality, integrity, availability, and regulatory compliance requirements. 
Set the technology direction by evaluating emerging technologies and recommending security controls and architectures to mitigate risks.

2. Cloud Security & DevSecOps 
Act as the principal Subject Matter Expert (SME) for cloud security across Azure, AWS, and GCP. 
Provide guidance on secure cloud architecture, workload protection, identity security, data protection, and network security. 
Partner with engineering teams to integrate security controls into CI/CD pipelines and DevSecOps processes. 
Promote Infrastructure-as-Code (IaC) security practices and automated security validation.

3. Risk & Compliance 
Lead security architecture reviews and identify design-level risks across the portfolio. 
Develop remediation recommendations and risk treatment strategies. 
Support industry standard compliance e.g. SOC 1 / SOC 2, ISO, COBIT, NIST, CIS, GDPR. 
Define and implement compensating controls where required. 
Partner with risk management and audit leadership to address security findings and drive remediation to closure. 

4. Application Security 
Review application designs for secure coding and architectural vulnerabilities. 
Partner with development teams to implement secure development lifecycle practices. 
Evaluate authentication, authorization, encryption, API security, and secrets management strategies. 
Support threat modeling exercises and security design reviews. 
Assess application architectures against OWASP Top 10 and industry best practices.

5. Security Governance 
Own and mature the security architecture governance process across the organization. 
Chair or lead architecture review boards and change advisory activities. 
Ensure alignment between business objectives and cybersecurity requirements. 
Support development and maintenance of security policies, standards, and technical guidelines.

6. Stakeholder Engagement 
Engage senior business leaders, application owners, infrastructure teams, audit teams, and cybersecurity functions. 
Communicate security risks and recommendations to both technical and non-technical stakeholders. 
Act as a trusted advisor to senior leadership on security architecture and strategic technology investments. 
Lead, mentor, and develop architects and engineering teams on security best practices. 

 Roles & responsibilities
1. Security Architecture & Design 
Own, govern, and continuously evolve security architecture standards, patterns, reference architectures, and implementation guidance. 
Ensure security requirements are integrated throughout the Secure/System Development lifecycle (S/SDLC). 
Review and approve solution architectures and act as the final design authority for enterprise security standards. 
Define security requirements for cloud-native, hybrid-cloud, SaaS, and on-premises solutions. 
Design security architectures that support confidentiality, integrity, availability, and regulatory compliance requirements. 
Set the technology direction by evaluating emerging technologies and recommending security controls and architectures to mitigate risks.

2. Cloud Security & DevSecOps 
Act as the principal Subject Matter Expert (SME) for cloud security across Azure, AWS, and GCP. 
Provide guidance on secure cloud architecture, workload protection, identity security, data protection, and network security. 
Partner with engineering teams to integrate security controls into CI/CD pipelines and DevSecOps processes. 
Promote Infrastructure-as-Code (IaC) security practices and automated security validation.

3. Risk & Compliance 
Lead security architecture reviews and identify design-level risks across the portfolio. 
Develop remediation recommendations and risk treatment strategies. 
Support industry standard compliance e.g. SOC 1 / SOC 2, ISO, COBIT, NIST, CIS, GDPR. 
Define and implement compensating controls where required. 
Partner with risk management and audit leadership to address security findings and drive remediation to closure. 


4. Application Security 
Review application designs for secure coding and architectural vulnerabilities. 
Partner with development teams to implement secure development lifecycle practices. 
Evaluate authentication, authorization, encryption, API security, and secrets management strategies. 
Support threat modeling exercises and security design reviews. 
Assess application architectures against OWASP Top 10 and industry best practices.

5. Security Governance 
Own and mature the security architecture governance process across the organization. 
Chair or lead architecture review boards and change advisory activities. 
Ensure alignment between business objectives and cybersecurity requirements. 
Support development and maintenance of security policies, standards, and technical guidelines.

6. Stakeholder Engagement 
Engage senior business leaders, application owners, infrastructure teams, audit teams, and cybersecurity functions. 
Communicate security risks and recommendations to both technical and non-technical stakeholders. 
Act as a trusted advisor to senior leadership on security architecture and strategic technology investments. 
Lead, mentor, and develop architects and engineering teams on security best practices. 

Mandatory  technical & functional skills
Strong expertise in security architecture across enterprise, solution, and cloud environments. 
Deep hands-on experience with Microsoft Azure, AWS, and Google Cloud Platform (GCP). 
Strong knowledge of: 
NIST CSF, NIST SP 800-53, NIST SSDF, ISO 27001/27002, SABSA, TOGAF 
Zero Trust Architecture and secure-by-design principles 
Cloud, network, application, and data security 
Identity, privileged access, and key management 
Solid understanding of security monitoring and detection, vulnerability management, and cryptography. 
Proficiency in security architecture documentation, patterns, and reference architectures. 

 This role is for you if you have  the below
Educational qualifications 
Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, Engineering, or a related field (Master’s preferred).


Work experience
14+ years of overall IT experience, including 8+ years in security architecture. 
Proven experience leading enterprise-scale security architecture programs across cloud and on-premises platforms. 
Experience leading architecture review boards, risk assessments, and embedding security into Agile and DevSecOps delivery. 

Experience Level

Mid Level

Job role

Work location
Work locationHyderabad, Telangana, India
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 14 years

About company

Name
NameKpmg India Services Llp
Job posted by Kpmg India Services Llp

Similar jobs you can apply for

Manufacturing / Production

Installation Engineer

Bharti Airtel Services
Ameerpet, Hyderabad
₹20,000 - ₹23,000
Field Job
Full Time
Any experience
Basic English
Jayasree Technologies

Hardware & Network Engineer

Jayasree Technologies
Ramgopal Pet, Hyderabad
₹12,000 - ₹15,000
Work from Office
Full Time
Min. 6 months
Basic English
Vasavi Group

Network Administrator

Vasavi Group
Banjara Hills, Hyderabad
₹20,000 - ₹35,000
Work from Office
Full Time
Min. 3 years
Good (Intermediate / Advanced) English

Multi Skill Technician Trainer

Srikalash Edu Skills Private Limited
Jubilee Hills, Hyderabad
₹15,000 - ₹25,000
Work from Office
Full Time
Any experience
Good (Intermediate / Advanced) English
HR Globe Recruitment Service

Field Installation Engineer

HR Globe Recruitment Service
Hyderabad
₹25,000 - ₹35,000
Work from Office
Full Time
Any experience
Basic English
VR Elite

Odiya Tele Caller

VR Elite
Gundlapochampalli, Hyderabad
₹20,000 - ₹25,000
Work from Office
Full Time
Min. 1 year
Basic English

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 14 to 31 years are eligible to apply for this job. You can apply for more jobs in Hyderabad to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Hyderabad at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Hyderabad . Through apna, you can find jobs in 64 cities across India. Join NOW!