Solution Architect - IT security
India
Job Description
Solution Architect - IT security
Noida, Uttar Pradesh

Job Summary

 Service Owner – BIS Role Purpose The Service Owner – Application Security, SDLC & Security Architecture is accountable for the strategy, governance, architecture alignment, and continuous improvement of enterprise application security capabilities across Research & Development, Commercial, and Corporate application portfolios. The role owns the application security roadmap, secure software development lifecycle (SDLC) practices, security architecture review processes, application security testing standards, and security support model. The Service Owner ensures applications are designed, developed, tested, and operated securely while enabling business teams to deliver secure solutions efficiently. The role partners with application development teams, solution architects, cybersecurity teams, business stakeholders, and technology teams to embed security throughout the application lifecycle. Key Responsibilities • Define and maintain the enterprise application security strategy, roadmap, and future-state capability model. • Own and continuously improve secure SDLC practices across R&D, Commercial, and Corporate application environments. • Establish security governance processes for application development, enhancement, and support activities. • Own the security architecture review process and provide governance for application security design decisions. • Partner with solution architects, application owners, developers, and business stakeholders to identify security risks and recommend appropriate security controls. • Define and govern application security testing practices, including: o Security assessments o Vulnerability testing o Application security reviews o Penetration testing coordination o Security validation activities • Establish application security standards, documentation requirements, and reusable security patterns. • Support application teams throughout the application lifecycle, including design, development, implementation, and ongoing support. • Evaluate application security tools and recommend improvements to enhance security effectiveness and developer experience. • Drive adoption of secure engineering practices and security-by-design principles. • Define service KPIs, maturity objectives, and continuous improvement initiatives. • Ensure application security capabilities align with regulatory, privacy, and healthcare requirements, including HIPAA where applicable. Required Skills & Experience • 10+ years of experience in application security, cybersecurity, software engineering, or security architecture. • Experience owning enterprise application security capabilities across multiple business domains. • Experience supporting application portfolios within complex organizations, including R&D, Commercial, and Corporate environments. • Strong understanding of: o Secure SDLC practices o Security architecture reviews o Application security testing methodologies o Vulnerability management o DevSecOps principles o Application risk management • Experience partnering with development teams, architects, and business stakeholders. • Experience defining security standards, governance processes, and operating models. • Experience working in regulated environments; healthcare experience and knowledge of HIPAA/security controls is preferred.

Key Responsibilities

 Service Owner – BIS Role Purpose The Service Owner – Application Security, SDLC & Security Architecture is accountable for the strategy, governance, architecture alignment, and continuous improvement of enterprise application security capabilities across Research & Development, Commercial, and Corporate application portfolios. The role owns the application security roadmap, secure software development lifecycle (SDLC) practices, security architecture review processes, application security testing standards, and security support model. The Service Owner ensures applications are designed, developed, tested, and operated securely while enabling business teams to deliver secure solutions efficiently. The role partners with application development teams, solution architects, cybersecurity teams, business stakeholders, and technology teams to embed security throughout the application lifecycle. Key Responsibilities • Define and maintain the enterprise application security strategy, roadmap, and future-state capability model. • Own and continuously improve secure SDLC practices across R&D, Commercial, and Corporate application environments. • Establish security governance processes for application development, enhancement, and support activities. • Own the security architecture review process and provide governance for application security design decisions. • Partner with solution architects, application owners, developers, and business stakeholders to identify security risks and recommend appropriate security controls. • Define and govern application security testing practices, including: o Security assessments o Vulnerability testing o Application security reviews o Penetration testing coordination o Security validation activities • Establish application security standards, documentation requirements, and reusable security patterns. • Support application teams throughout the application lifecycle, including design, development, implementation, and ongoing support. • Evaluate application security tools and recommend improvements to enhance security effectiveness and developer experience. • Drive adoption of secure engineering practices and security-by-design principles. • Define service KPIs, maturity objectives, and continuous improvement initiatives. • Ensure application security capabilities align with regulatory, privacy, and healthcare requirements, including HIPAA where applicable. Required Skills & Experience • 10+ years of experience in application security, cybersecurity, software engineering, or security architecture. • Experience owning enterprise application security capabilities across multiple business domains. • Experience supporting application portfolios within complex organizations, including R&D, Commercial, and Corporate environments. • Strong understanding of: o Secure SDLC practices o Security architecture reviews o Application security testing methodologies o Vulnerability management o DevSecOps principles o Application risk management • Experience partnering with development teams, architects, and business stakeholders. • Experience defining security standards, governance processes, and operating models. • Experience working in regulated environments; healthcare experience and knowledge of HIPAA/security controls is preferred.

Skill Requirements

 Service Owner – BIS Role Purpose The Service Owner – Application Security, SDLC & Security Architecture is accountable for the strategy, governance, architecture alignment, and continuous improvement of enterprise application security capabilities across Research & Development, Commercial, and Corporate application portfolios. The role owns the application security roadmap, secure software development lifecycle (SDLC) practices, security architecture review processes, application security testing standards, and security support model. The Service Owner ensures applications are designed, developed, tested, and operated securely while enabling business teams to deliver secure solutions efficiently. The role partners with application development teams, solution architects, cybersecurity teams, business stakeholders, and technology teams to embed security throughout the application lifecycle. Key Responsibilities • Define and maintain the enterprise application security strategy, roadmap, and future-state capability model. • Own and continuously improve secure SDLC practices across R&D, Commercial, and Corporate application environments. • Establish security governance processes for application development, enhancement, and support activities. • Own the security architecture review process and provide governance for application security design decisions. • Partner with solution architects, application owners, developers, and business stakeholders to identify security risks and recommend appropriate security controls. • Define and govern application security testing practices, including: o Security assessments o Vulnerability testing o Application security reviews o Penetration testing coordination o Security validation activities • Establish application security standards, documentation requirements, and reusable security patterns. • Support application teams throughout the application lifecycle, including design, development, implementation, and ongoing support. • Evaluate application security tools and recommend improvements to enhance security effectiveness and developer experience. • Drive adoption of secure engineering practices and security-by-design principles. • Define service KPIs, maturity objectives, and continuous improvement initiatives. • Ensure application security capabilities align with regulatory, privacy, and healthcare requirements, including HIPAA where applicable. Required Skills & Experience • 10+ years of experience in application security, cybersecurity, software engineering, or security architecture. • Experience owning enterprise application security capabilities across multiple business domains. • Experience supporting application portfolios within complex organizations, including R&D, Commercial, and Corporate environments. • Strong understanding of: o Secure SDLC practices o Security architecture reviews o Application security testing methodologies o Vulnerability management o DevSecOps principles o Application risk management • Experience partnering with development teams, architects, and business stakeholders. • Experience defining security standards, governance processes, and operating models. • Experience working in regulated environments; healthcare experience and knowledge of HIPAA/security controls is preferred.

Other Requirements

 Service Owner – BIS Role Purpose The Service Owner – Application Security, SDLC & Security Architecture is accountable for the strategy, governance, architecture alignment, and continuous improvement of enterprise application security capabilities across Research & Development, Commercial, and Corporate application portfolios. The role owns the application security roadmap, secure software development lifecycle (SDLC) practices, security architecture review processes, application security testing standards, and security support model. The Service Owner ensures applications are designed, developed, tested, and operated securely while enabling business teams to deliver secure solutions efficiently. The role partners with application development teams, solution architects, cybersecurity teams, business stakeholders, and technology teams to embed security throughout the application lifecycle. Key Responsibilities • Define and maintain the enterprise application security strategy, roadmap, and future-state capability model. • Own and continuously improve secure SDLC practices across R&D, Commercial, and Corporate application environments. • Establish security governance processes for application development, enhancement, and support activities. • Own the security architecture review process and provide governance for application security design decisions. • Partner with solution architects, application owners, developers, and business stakeholders to identify security risks and recommend appropriate security controls. • Define and govern application security testing practices, including: o Security assessments o Vulnerability testing o Application security reviews o Penetration testing coordination o Security validation activities • Establish application security standards, documentation requirements, and reusable security patterns. • Support application teams throughout the application lifecycle, including design, development, implementation, and ongoing support. • Evaluate application security tools and recommend improvements to enhance security effectiveness and developer experience. • Drive adoption of secure engineering practices and security-by-design principles. • Define service KPIs, maturity objectives, and continuous improvement initiatives. • Ensure application security capabilities align with regulatory, privacy, and healthcare requirements, including HIPAA where applicable. Required Skills & Experience • 10+ years of experience in application security, cybersecurity, software engineering, or security architecture. • Experience owning enterprise application security capabilities across multiple business domains. • Experience supporting application portfolios within complex organizations, including R&D, Commercial, and Corporate environments. • Strong understanding of: o Secure SDLC practices o Security architecture reviews o Application security testing methodologies o Vulnerability management o DevSecOps principles o Application risk management • Experience partnering with development teams, architects, and business stakeholders. • Experience defining security standards, governance processes, and operating models. • Experience working in regulated environments; healthcare experience and knowledge of HIPAA/security controls is preferred.

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.