Live opening · Posted 11 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The core responsibilities for the job include the following:
SOC 2 and Compliance (SaaS Security Governance):
SOC 2 Type 2 ownership: Drive the end-to-end certification process via Scrut.io policy authoring, evidence collection, control implementation, and audit readiness.
ISO 27001 and DPR/DPDP: Establish and maintain compliance with ISO 27001 GDPR, and India's DPDP Act. Conduct periodic risk assessments and gap analyses.
Define and enforce information security policies, access control frameworks, incident response plans, and data classification standards.
Serve as the primary point of contact for external auditors, client security questionnaires,
and due diligence requests.
DevSecOps and Application Security:
SAST/DAST integration: Implement and manage static and dynamic application security testing tools (e. g., SonarQube, Snyk, OWASP ZAP, and Burp Suite) within the CI/CD pipeline.
Embed security gates into GitHub-based workflows: pre-commit hooks, dependency scanning, container image scanning, and secrets detection.
Own vulnerability management: triage findings, coordinate remediation with engineering, and track SLA compliance.
Conduct periodic penetration testing (internal or coordinated third-party) and code review for security-critical modules.
AWS Administration and Cloud Security:
AWS estate ownership: Manage IAM policies, VPCs, security groups, S3 bucket policies, KMS, CloudTrail, GuardDuty, and AWS Config.
Architect and enforce least-privilege access models, network segmentation, and encryption-at-rest/in-transit across all AWS services.
Implement infrastructure-as-code security (Terraform/CloudFormation guardrails) and drift detection.
Cost and ops hygiene: Monitor AWS spend, right-size resources, manage Reserved Instances/Savings Plans, and maintain tagging standards.
Design and maintain disaster recovery and business continuity procedures for cloud-hosted services.
Network Security:
Design and manage network security architecture, firewalls, VPNs, WAFs, DDoS mitigation, and DNS security.
Implement zero-trust principles for remote-first and hybrid team access.
Monitor network traffic and configure alerting for anomalous activity using cloud-native and third-party tools.
Manage endpoint security (MDM, EDR) for company-issued and BYOD devices.
Internal Tools and Vendor Management:
Google Workspace (Business Standard): Administer Google Workspace user provisioning/deprovisioning, security policies, DLP rules, OAuth app whitelisting, and drive sharing controls.
Splunk AI / SIEM: Set up and manage Splunk AI (or equivalent) for centralised log management, security event correlation, and alerting.
Vendor management: Own the security and compliance evaluation of third-party SaaS tools. Maintain a vendor risk register, conduct periodic reviews, and negotiate security terms in vendor contracts.
Manage internal helpdesk and IT support operations, including onboarding/offboarding, access provisioning, hardware procurement, and license management.
Evaluate, procure, and sunset internal tools based on cost, security posture, and team needs.
Requirements:
6-12 years of progressive experience in information security, IT operations, or DevSecOps with at least 2 years in a leadership or sole-owner capacity.
Hands-on experience driving SOC 2 Type 2 or ISO 27001 certification in a SaaS or cloud-native environment.
Strong working knowledge of AWS services (IAM, VPC, GuardDuty, CloudTrail, KMS, S3 EC2 ECS/EKS) and infrastructure-as-code tools.
Proven experience implementing SAST/DAST tools and integrating security into CI/CD pipelines (GitHub Actions, Jenkins, or similar).
Experience administering Google Workspace and managing SaaS vendor security.
Solid understanding of network security principles, firewalls, VPNs, WAFs, DNS, and zero-trust architecture.
Good-to-Have:
Experience with Scrut.io, Vanta, Drata, or similar compliance automation platforms.
Familiarity with Splunk, Datadog Security, or equivalent SIEM/observability tools.
Relevant certifications: CISSP, CISM, CCSP, AWS Security Speciality, or CompTIA Security+.
Experience in a startup or early-stage environment where you built security/IT programs from scratch.
Exposure to procurement technology, electronics supply chains, or B2B SaaS platforms.
Certifications (Preferred / Required): CISM, CISA, or CISSP certification preferred.
Experience
6-10 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.