AVEVA is creating software trusted by over 90% of leading industrial companies.
Job Title: Secure Development Lifecycle (SDL) / Cybersecurity ArchitectLocation: Hyderabad, IndiaEmployment Type: Full-time, hybrid work arrangementThe job We are seeking a senior cybersecurity leader with deep expertise in Secure Development Lifecycle (SDLC), enterprise security architecture, and strong knowledge of the Cyber Resilience Act (CRA).This role will drive secure-by-design engineering practices, ensure regulatory compliance for products with digital elements, and embed cybersecurity governance across the product lifecycle.The candidate will act as a strategic advisor to Engineering, Product, Legal, and Compliance teams while defining security architecture standards aligned with global cybersecurity regulations.Key Responsibilities- Define and institutionalize Secure SDLC framework across AVEVA solutions
- Embed security controls into design, development, testing, deployment, and maintenance.
- Establish and perform threat modeling, secure coding standards, and code review practices.
- Own security architecture for applications, APIs, cloud workloads, and supporting platforms.
- Establish & perform secure coding standards and developer enablement (secure coding playbooks, training, guardrails).
- Ensure vulnerability management and patch governance across product lifecycle.
- Develop reference architectures focused on cyber security for cloud, on-prem, IoT, and hybrid environments.
- Conduct architecture risk assessments and security design reviews.
- Lead Zero Trust, identity, encryption, and data protection strategies.
- Define security patterns aligned to industry standards (ISO 27001, NIST, IEC 62443, etc.).
- Conduct product risk assessments and cybersecurity impact analysis.
- Has knowledge of EU Cyber Resilience Act
- Ensure “secure-by-default” configuration in products with digital elements.
- Prepare for regulatory audits and compliance certifications.
- Conduct product risk assessments and cybersecurity impact analysis.
- Guide developers & tester for secure testing.
- Support creation of compliance artifacts (architecture documentation, risk assessments, security requirements, SBOM processes, vulnerability handling process
- 8-12 years in development (.Net, Web, Cloud) and cybersecurity with strong experience in security architecture and application/product security.
- Strong experience in Architecting & design experience in developing multi-tier software or solution.
- Expertise in Secure Development Lifecycle frameworks in agile/DevOps environments.
- Strong experience in
- Static Code analysis tools
- Threat modelling (STRIDE, attack trees)
- Security design reviews, secure coding practices
- Cloud security (AWS, Azure, GCP) nice to have
- OWASP Top 10, API security, authentication/authorization (OAuth2/OIDC, SSO, RBAC/ABAC)
- Secure Testing (Fuzz Testing, Penetration Testing)
- Secure API practices: input validation, rate limiting, secure headers, CORS, secrets handling
- API design & development (REST/GraphQL), versioning, pagination, error handling
- Vulnerability management lifecycle and tooling integration
- Writing high-quality code: unit/integration tests, code reviews, refactoring, clean architecture
- Preparing technical documentation for regulatory audits.
- Experience in Industrial automation company or domain is desirable.
- Knowledge of EU Cyber Resilience Act (CRA) concepts and practical implementation needs is desirable
- Knowledge of global cybersecurity regulations (NIS2, GDPR, etc.) is desirable
India Benefits include:
Gratuity, Medical and accidental insurance, very attractive leave entitlement, emergency leave days, childcare support, maternity, paternity and adoption leaves, education assistance program, home office set up support (for hybrid roles), well-being support
It’s possible we’re hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.
Find out more: aveva.com/en/about/careers/benefits/
Hybrid working
By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based. Roles supporting particular customers or markets are sometimes remote.
Hiring process
Interested? Great! Get started by submitting your cover letter and CV through our application portal. AVEVA is committed to recruiting and retaining people with disabilities. Please let us know in advance if you need reasonable support during your application process.
Find out more: aveva.com/en/about/careers/hiring-process
About AVEVA
AVEVA is a global leader in industrial software with more than 6,500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life – such as energy, infrastructure, chemicals, and minerals – safely, efficiently, and more sustainably.
We are committed to embedding sustainability and inclusion into our operations, our culture, and our core business strategy. Learn more about how we are progressing against our ambitious 2030 targets: sustainability-report.aveva.com/
Find out more: aveva.com/en/about/careers/
AVEVA requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third-party personal data may involve additional background check criteria.
AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business. AVEVA provides reasonable accommodation to applicants with disabilities where appropriate. If you need reasonable accommodation for any part of the application and hiring process, please notify your recruiter. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
Skills Required
- 10-15 years in cybersecurity
- strong experience in security architecture and application/product security
- proven experience building and running a Secure SDLC program in agile/DevOps environments
- strong expertise in Secure SDLC frameworks
- hands-on knowledge of threat modeling
- strong knowledge of security design reviews and secure coding practices
- experience with cloud security (AWS, Azure, GCP)
AVEVA Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about AVEVA and has not been reviewed or approved by AVEVA.
-
Leave & Time Off Breadth — Time away from work is positioned as a meaningful part of the rewards mix, including paid time off that can increase with tenure and additional paid volunteering days. This breadth is reinforced by mentions of public holidays and emergency leave as part of the overall time-off offering.
-
Wellbeing & Lifestyle Benefits — Wellbeing support appears broad and multi-channel, combining counseling access, coaching resources, and region-specific digital wellbeing tools. Flexible work hours and a hybrid model are also presented as lifestyle-supporting elements within the broader rewards package.
-
Career-Linked Recognition & Rewards — Recognition is tied to tenure milestones through a formal program that provides rewards and symbolic recognition. Development-linked rewards also appear through learning access, mentorship, and education reimbursement that connects benefits to skill growth.
AVEVA Insights
What We Do
AVEVA is a global leader in industrial software, sparking ingenuity to drive responsible use of the world’s resources. The company’s secure industrial cloud platform and applications enable businesses to harness the power of their information and improve collaboration with customers, suppliers and partners. Over 20,000 enterprises in over 100 countries rely on AVEVA to help them deliver life’s essentials: safe and reliable energy, food, medicines, infrastructure and more. By connecting people with trusted information and AI-enriched insights, AVEVA enables teams to engineer efficiently and optimize operations, driving growth and sustainability. Named as one of the world’s most innovative companies, AVEVA supports customers with open solutions and the expertise of more than 6,400 employees, 5,000 partners and 5,700 certified developers. With operations around the globe, AVEVA is headquartered in Cambridge, UK. Learn more at www.aveva.com









