Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About Acefone
Acefone,(Formerly Servetel) is a part of RTDS group (founded in 2010). The company focuses on simplifying communication for businesses. We are a product company that’s making interactions simple, powerful, and customer focused. Our cloud-based omnichannel Customer Experience (CX) platform, AceX hosts powerful products, including:
Interactions Hub: A unified communication platform to host cross-channel customer engagement on a single platform.
Contact Center Studio: A powerful dialer to enhance calling experience between business and customers while boosting agent productivity.
API Connect: A unique communication API suite to assist communication needs for mobile and web applications.
Campaigns: Mass outreach product to connect with last audience in an efficient and productive manner.
These products are designed to help businesses deliver exceptional experiences at every touchpoint of the customer journey.
Headquartered in Gurgaon, we are trusted by 5000+ global businesses and bring seamless communication with industry-leading integrations to ensure an efficient, yet effective CX. Our ISO 27001 certification vouch for our top-notch security and a 99.95% uptime guarantee.
Acefone's user-friendly, insight-driven products offer 300+ features, serving different channels, like Voice, WhatsApp, SMS and more. With custom integrations powered by neat APIs, it smoothly aligns with every business’ unique demands.
Job responsibilities
Lead security architecture reviews for new and existing systems, applications, and platforms hosted on AWS, ensuring designs follow secure-by-design principles.
Conduct threat modeling (e.g., STRIDE, attack trees) for applications, services, and infrastructure changes across AWS and Kubernetes environments.
Review high-level and low-level designs (HLD/LLD) from a security perspective and provide actionable, risk-based recommendations.
Define and maintain security architecture standards, patterns, and reference architectures for AWS and Kubernetes workloads.
Partner with engineering and product teams early in the design lifecycle to identify and remediate security risks before implementation.
Review AWS account, network, and workload architectures against security best practices (AWS Well-Architected Framework – Security Pillar, CIS AWS Benchmarks).
Assess IAM policies, roles, and permission boundaries across AWS environments for least-privilege design.
Review firewall, IDS/IPS, and network security architecture and rule sets to ensure secure segmentation and threat detection across AWS and hybrid environments.
Evaluate the architecture and integration of security tooling — including EDR, Zscaler (SSE/ZTNA), Qualys (vulnerability management), and similar platforms — for coverage gaps and alignment with the overall security architecture.
Review Kubernetes cluster architecture, workload configurations, and RBAC/network policy design for security risks.
Evaluate container image build pipelines, base image hardening, and runtime security controls for containerized workloads.
Perform application-level security architecture reviews, including API design, authentication/authorization models, and data protection.
Identify design-level risks aligned to OWASP Top 10 and relevant threat categories, working with development teams to embed security into the SDLC.
Ensure architecture reviews consider relevant compliance standards and frameworks (ISO 27001, NIST, CIS, SOC 2, PCI-DSS, GDPR as applicable).
Review VoIP configuration, architecture, and best practices to ensure secure, resilient, and compliant voice communication infrastructure.
Act as the Single Point of Contact (SPOC) for DoT (Department of Telecommunications) and CERT-In, and for external communication on security-related matters.
Maintain documentation of architecture review findings, risk decisions, and remediation tracking, and present risk assessments to engineering leadership.
Mentor engineers and junior security staff on secure design principles and threat modeling techniques, and contribute to security awareness training.
Required Skills
Strong hands-on expertise in AWS security architecture (IAM, VPC, KMS, GuardDuty, Security Hub, WAF, Well-Architected Framework – Security Pillar).
Solid experience in Kubernetes and container security (RBAC, network policies, pod security standards, image hardening, service mesh).
Proven experience conducting security architecture reviews and threat modeling for applications and infrastructure.
Strong understanding of application security principles (OWASP Top 10, secure SDLC, API security).
Familiarity with Infrastructure-as-Code (Terraform, CloudFormation) sufficient to review IaC for security misconfigurations.
Working knowledge of security and compliance frameworks: ISO 27001, NIST, CIS Benchmarks, SOC 2, and PCIDSS.
Experience producing HLD/LLD security documentation and architecture diagrams.
Deep understanding of security architecture principles with a Security by Design mindset.
Knowledge of data encryption techniques for data at rest and in transit.
Experience with security tooling relevant to AWS and Kubernetes environments, such as cloud-native security posture tools, container scanning, and SAST/DAST.
Working knowledge of firewall and IDS/IPS architecture and rule design, with the ability to review network security controls for effectiveness and gaps.
Familiarity with reviewing and evaluating security tools such as EDR platforms, Zscaler, Qualys, and similar solutions as part of architecture and vendor security assessments.
Exposure to DevSecOps practices and secure CI/CD pipeline design.
Strong communication and stakeholder management skills, with the ability to present risk clearly to both technical and non-technical audiences.
Qualifications
5–8+ years of experience in Security Architecture, Application Security, or related security engineering/leadership roles.
Demonstrated experience specifically with AWS and Kubernetes security (multi-cloud experience across Azure or GCP is not required for this role).
Relevant certifications preferred: AWS Certified Security – Specialty, CKS (Certified Kubernetes Security Specialist), CISSP, CCSP, or equivalent.
Mission: To make communication easy and efficient for businesses.
Vision: To be the global leader in business communication technologies.
Values that drive us:
❖ Collaboration - "Together We Achieve More"
❖ Integrity - "Upright, all the time"
❖ Striving for Excellence - "Brilliance is Basic Benchmark"
❖ Customer Centricity - "Partner in success"
❖ We Care - "Nurturing a Better Tomorrow"
CONTACT INFORMATION
Website: https://www.acefone.com
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.