JobRaahGet matched free

Jobs

Senior Software- Security Agent Architect

Sisainfosec · Mumbai · India · On-site

Pay: INR 5,000,000 – 6,000,000 a year

Posted Aug 4, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

About the Role We build a distributed, agent-based endpoint security platform for the payment ecosystem, combining an endpoint agent (a core runtime plus pluggable security modules, built entirely in Go), an on-premise management component deployed at the customer site, a local telemetry relay component, and a cloud backend. Kernel-level components that hook into the OS are written in C/C++, as is standard for driver-level development. We're looking for a Senior/Principal Architect to own end-to-end architecture across this stack — from the control-plane protocol on the endpoint, through on-premise components, to secure egress into the cloud backend. This is a hands-on architecture role: you will be expected to review code and low-level design, not just produce diagrams. Key Responsibilities • Define the architecture for kernel-level components on the endpoint (drivers/kernel modules used for real-time monitoring, hooking, or enforcement), including their interaction with and isolation from the user-mode agent runtime and its modules. • Own architectural decisions across the full platform: the endpoint agent (core runtime + pluggable security modules), the on-premise management component, the on-premise telemetry relay component, and the cloud backend. • Define and evolve the control-plane (gRPC/Protobuf) and data-plane transport strategy between the endpoint agent, the on-premise management component, and the telemetry relay component. • Own version compatibility strategy across independently-versioned components (agent, core runtime, modules, management component, cloud backend). • Design secure, outbound-only, multi-tenant deployment topology — mTLS and certificate lifecycle management, IPSec/VPN egress design — suitable for PCI-regulated payment industry clients. • Own the client-facing security architecture narrative: per-hop network/port/protocol documentation, PCI-DSS scoping discussions, and direct engagement with client InfoSec/audit teams. • Architect the security-module lifecycle: subscription entitlement enforcement, binary distribution, staged/canary rollout and rollback, resource governance across concurrently running modules, and failure isolation so a single module cannot take down the core agent runtime. • Define HA/DR strategy for on-premise components deployed inside customer environments that are not directly operated by us. • Evaluate and decide on the design of any bi-directional channel between the cloud backend and on-premise components, ensuring it doesn't undermine the outbound-only security posture documented to clients. • Run architecture reviews, mentor senior and mid-level engineers, and own technical roadmap and tech-debt prioritization. • Represent the company in high-stakes architecture and security review calls with enterprise client stakeholders. Required Technical Skills • 15–20+ years in software engineering, including 8+ years in architecture or senior technical leadership roles. • Deep…