Information & Cybersec Lead

Apply Now โ†—
๐Ÿ“ Gautam Buddha Nagar, India

About this role

Job Summary

Role Summary

The Security by Design Engineer will be responsible for embedding security into the application design and architecture lifecycle. The role will lead secure design reviews, threat modeling, architecture risk assessments, and security consulting to help teams identify and address security risks early in the SDLC.

Key Responsibilities

  • Perform architecture and design security reviews for new applications, major changes, and technology implementations.
  • Review architecture diagrams, data flows, trust boundaries, integration points, deployment models, and privileged components.
  • Conduct threat modeling exercises using structured approaches such as STRIDE and document applicable threats and mitigations.
  • Evaluate security controls for authentication, authorization, input validation, data protection, encryption, session management, logging, and error handling.
  • Provide security recommendations for web applications, APIs, cloud-native workloads, SaaS/COTS integrations, and third-party connectivity.
  • Work with architects, application owners, developers, product teams, and AppSec stakeholders to close design-level security risks.
  • Track security observations, mitigation plans, residual risks, and sign-off decisions in alignment with Secure SDLC governance.
  • Create reusable secure design patterns, checklists, and guidance for application teams.
  • Support management reporting, audit evidence, and governance reviews related to Security by Design activities.
  • Conduct awareness sessions for architects and development teams on secure design expectations.

Required Technical Skills

  • Strong understanding of Secure SDLC and Security by Design principles.
  • Hands-on experience in threat modeling, architecture risk assessment, and secure design review.
  • Knowledge of application architecture, API security, identity and access management, cloud security, encryption, and integration security.
  • Understanding of OWASP Top 10, OWASP ASVS, secure coding practices, and common application vulnerability categories.
  • Ability to analyze design artifacts, identify attack paths, recommend practical controls, and articulate risk clearly to stakeholders.
  • Good documentation, facilitation, and stakeholder communication skills.

Preferred Skills

  • Experience with Azure, AWS, or GCP security architecture reviews.
  • Exposure to API gateways, IAM patterns, secrets management, encryption/key management, and logging/monitoring requirements.
  • Knowledge of security frameworks, control mapping, risk acceptance, and audit evidence preparation.
  • Certifications such as CISSP, CSSLP, CCSP, SABSA, or equivalent are added advantage.

Experience

  • 6 to 10 years of experience in Application Security, Security Architecture, Secure Design Review, or Secure SDLC governance.
  • Prior experience working directly with architects, engineering teams, product teams, and business stakeholders.

Expected Deliverables

  • Secure design review reports and control recommendations.
  • Threat modeling outputs with risks, mitigations, and residual risk decisions.
  • Security sign-off inputs for new applications and major changes.
  • Reusable secure architecture patterns, checklists, and awareness material.
  • Status reporting for design review coverage, open observations, and closure progress.

Key Responsibilities

Key Responsibilities

  • Perform architecture and design security reviews for new applications, major changes, and technology implementations.
  • Review architecture diagrams, data flows, trust boundaries, integration points, deployment models, and privileged components.
  • Conduct threat modeling exercises using structured approaches such as STRIDE and document applicable threats and mitigations.
  • Evaluate security controls for authentication, authorization, input validation, data protection, encryption, session management, logging, and error handling.
  • Provide security recommendations for web applications, APIs, cloud-native workloads, SaaS/COTS integrations, and third-party connectivity.
  • Work with architects, application owners, developers, product teams, and AppSec stakeholders to close design-level security risks.
  • Track security observations, mitigation plans, residual risks, and sign-off decisions in alignment with Secure SDLC governance.
  • Create reusable secure design patterns, checklists, and guidance for application teams.
  • Support management reporting, audit evidence, and governance reviews related to Security by Design activities.
  • Conduct awareness sessions for architects and development teams on secure design expectations.

Skill Requirements

Other Requirements

Frequently Asked Questions

Is the salary disclosed for the Information & Cybersec Lead position at HCLTech?
The salary for this Information & Cybersec Lead role at HCLTech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Information & Cybersec Lead position at HCLTech located?
This Information & Cybersec Lead role at HCLTech is based in Gautam Buddha Nagar, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
How do I apply for the Information & Cybersec Lead position at HCLTech?
Click the "Apply Now" button on this page. You will be redirected to HCLTech's official application portal hosted on successfactors where you can submit your application directly.
When was the Information & Cybersec Lead job at HCLTech posted?
This Information & Cybersec Lead position at HCLTech was posted on Aug 31, 2026. Apply as soon as possible โ€” early applications are often reviewed first.
Information & Cybersec Lead
HCLTech
Apply for this role โ†—

You'll be redirected to HCLTech's official application page on successfactors.