Information Security Architect

Responsibility

Position: Information Security Architect
Experience: 8+ Years
Location: Bengaluru, India
Employment Type: C2H


Role Summary

We are looking for an experienced Information Security Architect to own information security across the Aura platform, infrastructure, and organization. The role covers security architecture, hands-on security engineering, compliance certifications, customer security assurance, governance, and incident response.

The ideal candidate will be able to drive security certifications, strengthen cloud and application security, and act as a trusted security partner for regulated financial customers.


Key Responsibilities

Security Architecture & Engineering

  • Define and maintain security architecture covering network segmentation, encryption, access control, API security, and key management.
  • Review and approve infrastructure changes, integrations, and API exposure decisions.
  • Own the vulnerability management program, including dependency scanning, CVE triage, patching, and remediation tracking.
  • Oversee security monitoring through Wazuh SIEM, EWACS, CloudWatch, or equivalent platforms.

Hands-On Security Engineering

  • Design and implement AWS security controls, including IAM, VPC/security groups, KMS, WAF, and GuardDuty.
  • Lead remediation of penetration testing and vulnerability assessment findings across infrastructure and application layers.
  • Configure and tune SIEM detection rules, alerting logic, and security use cases.
  • Own certificate lifecycle management and encryption implementation across environments.
  • Harden infrastructure configurations against CIS benchmarks and similar security standards.
  • Work with engineering teams on secure coding practices and security checks within development pipelines.

Compliance & Certifications

  • Maintain and continuously improve the ISO 27001 ISMS, including annual surveillance audits.
  • Drive SOC 2 Type II compliance, including scope definition, controls, evidence collection, and auditor engagement.
  • Own DORA compliance covering ICT risk management, incident classification/reporting, resilience testing, and third-party risk management.
  • Ensure GDPR compliance for platform data processing in collaboration with the DPO.

Customer Security Assurance

  • Handle customer security questionnaires, due diligence requests, and audit evidence packages.
  • Prepare security reports and present security posture at customer governance meetings.
  • Support RFPs and customer proposals with relevant security content.

Incident Response & Testing

  • Own the security incident response plan, including severity levels, escalation, communication, and post-incident reviews.
  • Act as incident commander for security-related P1/P2 incidents and deliver RCAs within defined SLAs.
  • Commission and manage annual third-party penetration testing.

Policy & Governance

  • Review and evolve security policies to align with ISO 27001, SOC 2, DORA, and applicable requirements.
  • Conduct annual security risk assessments and maintain the security risk register.
  • Oversee security awareness training and secure coding practices.

Required Skills & Experience

  • 8+ years of experience in Information Security, Security Architecture, Security Engineering, or hands-on Security Lead roles.
  • Experience maintaining an ISO 27001 ISMS through certification and surveillance cycles.
  • Working knowledge of DORA or similar financial-sector ICT risk frameworks.
  • Hands-on AWS security experience with IAM, VPC, KMS, WAF, GuardDuty, or equivalent.
  • Experience with SIEM platforms such as Wazuh, Splunk, Microsoft Sentinel, or similar.
  • Strong understanding of Application Security, including OWASP Top 10, API Security, OAuth, JWT, and SAML.
  • Ability to communicate security posture effectively with customer executives, auditors, and regulators.
  • Fluent English communication skills.

Nice-to-Have Skills

  • Experience with SOC 2 Type II audits.
  • Background in SaaS organizations serving regulated financial institutions.
  • Practical experience with GDPR compliance.
  • Relevant certifications such as:
    • CISSP
    • CISM
    • ISO 27001 Lead Auditor
    • AWS Certified Security – Specialty

Apply Now

    Contact Us