First seen by Alion on Sep 18, 2026.
Role & Responsibilities :
- Act as the Cybersecurity Subject Matter Expert (SME) for software products, platforms, and cloud services.
- Perform security architecture reviews and provide secure design recommendations.
- Lead Threat Modeling, Threat & Risk Assessments (TRA), and cybersecurity risk analysis.
- Drive Secure Software Development Lifecycle (SSDLC) practices across engineering teams.
- Coordinate vulnerability management, penetration testing, and remediation activities.
- Guide teams on Application Security tools including SAST, DAST, SCA, and SBOM.
- Implement security best practices for Azure/AWS cloud environments, containers, and Kubernetes.
- Ensure compliance with OWASP Top 10, NIST, ISO 27001/27002, and other applicable security standards.
- Collaborate with global engineering, DevOps, QA, and product teams to embed security-by-design.
- Mentor engineering teams and provide technical leadership on cybersecurity practices.
Preferred Candidate Profile :
- Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, or a related field.
- 8+ years of experience in Software Engineering, Cloud Engineering, Platform Engineering, or Cybersecurity.
- 5+ years of hands-on experience in Product Security, Application Security, or Security Architecture.
- Strong expertise in Secure SDLC, Threat Modeling, Security Architecture, and Risk Assessment.
- Hands-on experience with Azure/AWS Security, Kubernetes, Docker, IAM, and Vulnerability Management.
- Experience using SAST, DAST, SCA, and SBOM tools.
- Good understanding of OWASP Top 10, NIST, ISO 27001/27002, and secure coding practices.
- Excellent communication and stakeholder management skills with experience working in global teams.
- Experience in healthcare, medical devices, or other regulated industries is preferred.
- Certifications such as CISSP, CSSLP, CCSP, CEH, Azure Security Engineer Associate, or CKS are an added advantage.
Skills
Cyber Security, Security, Security Architect, Threat Modeling, Threat Detection, SAST, DAST, Vulnerability Management, Penetration Testing, OWASP, NIST

