Secure Development Lifecycle (SDL) / Cybersecurity Architect

Reposted 8 Hours Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Agency • Artificial Intelligence • Cloud • Internet of Things • Software • Automation
The Role
The role focuses on defining and implementing a Secure Development Lifecycle, embedding security in product design, conducting risk assessments, and providing strategic security advice.
Summary Generated by Built In

AVEVA is creating software trusted by over 90% of leading industrial companies.

Job Title: Secure Development Lifecycle (SDL) / Cybersecurity ArchitectLocation: Hyderabad, IndiaEmployment Type: Full-time, hybrid work arrangementThe job We are seeking a senior cybersecurity leader with deep expertise in Secure Development Lifecycle (SDLC), enterprise security architecture, and strong knowledge of the Cyber Resilience Act (CRA).This role will drive secure-by-design engineering practices, ensure regulatory compliance for products with digital elements, and embed cybersecurity governance across the product lifecycle.The candidate will act as a strategic advisor to Engineering, Product, Legal, and Compliance teams while defining security architecture standards aligned with global cybersecurity regulations.Key Responsibilities
  • Define and institutionalize Secure SDLC framework across AVEVA solutions
  • Embed security controls into design, development, testing, deployment, and maintenance.
  • Establish and perform threat modeling, secure coding standards, and code review practices.
  • Own security architecture for applications, APIs, cloud workloads, and supporting platforms.
  • Establish & perform secure coding standards and developer enablement (secure coding playbooks, training, guardrails).
  • Ensure vulnerability management and patch governance across product lifecycle.
  • Develop reference architectures focused on cyber security for cloud, on-prem, IoT, and hybrid environments.
  • Conduct architecture risk assessments and security design reviews.
  • Lead Zero Trust, identity, encryption, and data protection strategies.
  • Define security patterns aligned to industry standards (ISO 27001, NIST, IEC 62443, etc.).
  • Conduct product risk assessments and cybersecurity impact analysis.
  • Has knowledge of EU Cyber Resilience Act
  • Ensure “secure-by-default” configuration in products with digital elements.
  • Prepare for regulatory audits and compliance certifications.
  • Conduct product risk assessments and cybersecurity impact analysis.
  • Guide developers & tester for secure testing.
  • Support creation of compliance artifacts (architecture documentation, risk assessments, security requirements, SBOM processes, vulnerability handling process
Must Have
  • 8-12 years in development (.Net, Web, Cloud) and cybersecurity with strong experience in security architecture and application/product security.
  • Strong experience in Architecting & design experience in developing multi-tier software or solution.
  • Expertise in Secure Development Lifecycle frameworks in agile/DevOps environments.
  • Strong experience in
    • Static Code analysis tools
    • Threat modelling (STRIDE, attack trees)
    • Security design reviews, secure coding practices
    • Cloud security (AWS, Azure, GCP) nice to have
    • OWASP Top 10, API security, authentication/authorization (OAuth2/OIDC, SSO, RBAC/ABAC)
    • Secure Testing (Fuzz Testing, Penetration Testing)
    • Secure API practices: input validation, rate limiting, secure headers, CORS, secrets handling
    • API design & development (REST/GraphQL), versioning, pagination, error handling
  • Vulnerability management lifecycle and tooling integration
  • Writing high-quality code: unit/integration tests, code reviews, refactoring, clean architecture
  • Preparing technical documentation for regulatory audits.
 Nice to Have
  • Experience in Industrial automation company or domain is desirable.
  • Knowledge of EU Cyber Resilience Act (CRA) concepts and practical implementation needs is desirable
  • Knowledge of global cybersecurity regulations (NIS2, GDPR, etc.) is desirable
Services at AVEVAOur dynamic global team of 700+ engineers, developers, consultants, solution architects and project managers are at the forefront of delivering AVEVA cutting-edge solutions to customers. The work is complex and technical, but immensely rewarding: we empower customers to harness the full transformative potential of AVEVA’s solutions. If you’re analytical, pragmatic, and driven to make a tangible impact on the sustainability of the industrial sector, our team is the perfect place for you.Find out more: https://www.aveva.com/en/about/careers/

India Benefits include:  

Gratuity, Medical and accidental insurance, very attractive leave entitlement, emergency leave days, childcare support, maternity, paternity and adoption leaves, education assistance program, home office set up support (for hybrid roles), well-being support

It’s possible we’re hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.

Find out more: aveva.com/en/about/careers/benefits/

Hybrid working

By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based. Roles supporting particular customers or markets are sometimes remote.

Hiring process

Interested? Great! Get started by submitting your cover letter and CV through our application portal. AVEVA is committed to recruiting and retaining people with disabilities. Please let us know in advance if you need reasonable support during your application process.

Find out more: aveva.com/en/about/careers/hiring-process

About AVEVA

AVEVA is a global leader in industrial software with more than 6,500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life – such as energy, infrastructure, chemicals, and minerals – safely, efficiently, and more sustainably.

We are committed to embedding sustainability and inclusion into our operations, our culture, and our core business strategy. Learn more about how we are progressing against our ambitious 2030 targets: sustainability-report.aveva.com/

Find out more: aveva.com/en/about/careers/

AVEVA requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check.  Certain positions dealing with sensitive and/or third-party personal data may involve additional background check criteria.

AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business.  AVEVA provides reasonable accommodation to applicants with disabilities where appropriate. If you need reasonable accommodation for any part of the application and hiring process, please notify your recruiter. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.

Skills Required

  • 10-15 years in cybersecurity
  • strong experience in security architecture and application/product security
  • proven experience building and running a Secure SDLC program in agile/DevOps environments
  • strong expertise in Secure SDLC frameworks
  • hands-on knowledge of threat modeling
  • strong knowledge of security design reviews and secure coding practices
  • experience with cloud security (AWS, Azure, GCP)

AVEVA Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about AVEVA and has not been reviewed or approved by AVEVA.

  • Leave & Time Off Breadth Time away from work is positioned as a meaningful part of the rewards mix, including paid time off that can increase with tenure and additional paid volunteering days. This breadth is reinforced by mentions of public holidays and emergency leave as part of the overall time-off offering.
  • Wellbeing & Lifestyle Benefits Wellbeing support appears broad and multi-channel, combining counseling access, coaching resources, and region-specific digital wellbeing tools. Flexible work hours and a hybrid model are also presented as lifestyle-supporting elements within the broader rewards package.
  • Career-Linked Recognition & Rewards Recognition is tied to tenure milestones through a formal program that provides rewards and symbolic recognition. Development-linked rewards also appear through learning access, mentorship, and education reimbursement that connects benefits to skill growth.

AVEVA Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Cambridge
6,970 Employees

What We Do

AVEVA is a global leader in industrial software, sparking ingenuity to drive responsible use of the world’s resources. The company’s secure industrial cloud platform and applications enable businesses to harness the power of their information and improve collaboration with customers, suppliers and partners. Over 20,000 enterprises in over 100 countries rely on AVEVA to help them deliver life’s essentials: safe and reliable energy, food, medicines, infrastructure and more. By connecting people with trusted information and AI-enriched insights, AVEVA enables teams to engineer efficiently and optimize operations, driving growth and sustainability. Named as one of the world’s most innovative companies, AVEVA supports customers with open solutions and the expertise of more than 6,400 employees, 5,000 partners and 5,700 certified developers. With operations around the globe, AVEVA is headquartered in Cambridge, UK. Learn more at www.aveva.com

Similar Jobs

Easy Apply
In-Office
Hyderabad, Telangana, IND
900 Employees

DigitalOcean Logo DigitalOcean

Staff Software Engineer

Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
In-Office
Hyderabad, Telangana, IND
1400 Employees

Crunchyroll Logo Crunchyroll

Senior MLOps Engineer

Digital Media • eCommerce • Gaming • Mobile • News + Entertainment
Hybrid
Hyderabad, Telangana, IND
1300 Employees

MetLife Logo MetLife

Data Governance EDAG Director

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
Hyderabad, Telangana, IND
43000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account