Commvault
About this role
A security architecture role at Commvault focused on reviewing and designing secure software rather than running operations. The core of the job is security architecture review and threat modelling across cloud, on premises and hybrid environments, using structured methodologies such as STRIDE, PASTA and OCTAVE, and working with development, DevOps and product teams early enough in the lifecycle to change design decisions. There is a modern angle in the requirement list: reviewing the architecture of generative AI solutions, which is still uncommon on security postings. Automated architecture analysis tooling like IriusRisk or ThreatModeler is named as familiarity. Five years is the stated bar, making this a reachable senior security role. Bangalore.
Who this is for
What the posting asks for:
- 5+ years of experience in application or software security architecture.
- Strong knowledge of threat modelling methodologies such as STRIDE, PASTA and OCTAVE.
- Hands on experience conducting security architecture reviews for complex systems.
- Familiarity with automated security architecture tools such as IriusRisk, ThreatModeler or the Microsoft Threat Modeling Tool.
- Experience reviewing the architecture of generative AI solutions.
Preferred: experience with automated tools for security architecture analysis, and relevant security certifications. The posting says these are strongly preferred rather than required.
Day to day: conducting in depth security architecture reviews across cloud, on premises and hybrid environments; performing threat modelling to identify risks and define mitigations early in the development lifecycle; working with development teams, DevOps and product owners to guide secure design decisions; evaluating and implementing automated tooling for architecture review and continuous assessment; creating and maintaining security architecture documentation and reusable patterns; and contributing to internal security standards and processes.
Location and office reality: Bangalore. The posting does not publish an office day policy.
One thing to be aware of: Commvault opens this posting with a recruitment fraud warning, stating it does not interview by email or text and will never request sensitive documents before your first day.
Honest fit guidance: this is a design and review role, not a penetration testing or SOC role. If your security experience is entirely operational, the threat modelling methodology requirement is where the interview will focus. Five years plus real architecture review experience clears the stated bar.
- 5+ years of experience in application or software security architecture.
- Strong knowledge of threat modelling methodologies such as STRIDE, PASTA and OCTAVE.
- Hands on experience conducting security architecture reviews for complex systems.
- Familiarity with automated security architecture tools such as IriusRisk, ThreatModeler or the Microsoft Threat Modeling Tool.
- Experience reviewing the architecture of generative AI solutions.
Preferred: experience with automated tools for security architecture analysis, and relevant security certifications. The posting says these are strongly preferred rather than required.
Day to day: conducting in depth security architecture reviews across cloud, on premises and hybrid environments; performing threat modelling to identify risks and define mitigations early in the development lifecycle; working with development teams, DevOps and product owners to guide secure design decisions; evaluating and implementing automated tooling for architecture review and continuous assessment; creating and maintaining security architecture documentation and reusable patterns; and contributing to internal security standards and processes.
Location and office reality: Bangalore. The posting does not publish an office day policy.
One thing to be aware of: Commvault opens this posting with a recruitment fraud warning, stating it does not interview by email or text and will never request sensitive documents before your first day.
Honest fit guidance: this is a design and review role, not a penetration testing or SOC role. If your security experience is entirely operational, the threat modelling methodology requirement is where the interview will focus. Five years plus real architecture review experience clears the stated bar.
Apply on company site
Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.