Position: Information Security Architect
Experience: 8+ Years
Location: Bengaluru, India
Employment Type: C2H
Role Summary
We are looking for an experienced Information Security Architect to own information security across the Aura platform, infrastructure, and organization. The role covers security architecture, hands-on security engineering, compliance certifications, customer security assurance, governance, and incident response.
The ideal candidate will be able to drive security certifications, strengthen cloud and application security, and act as a trusted security partner for regulated financial customers.
Key Responsibilities
Security Architecture & Engineering
- Define and maintain security architecture covering network segmentation, encryption, access control, API security, and key management.
- Review and approve infrastructure changes, integrations, and API exposure decisions.
- Own the vulnerability management program, including dependency scanning, CVE triage, patching, and remediation tracking.
- Oversee security monitoring through Wazuh SIEM, EWACS, CloudWatch, or equivalent platforms.
Hands-On Security Engineering
- Design and implement AWS security controls, including IAM, VPC/security groups, KMS, WAF, and GuardDuty.
- Lead remediation of penetration testing and vulnerability assessment findings across infrastructure and application layers.
- Configure and tune SIEM detection rules, alerting logic, and security use cases.
- Own certificate lifecycle management and encryption implementation across environments.
- Harden infrastructure configurations against CIS benchmarks and similar security standards.
- Work with engineering teams on secure coding practices and security checks within development pipelines.
Compliance & Certifications
- Maintain and continuously improve the ISO 27001 ISMS, including annual surveillance audits.
- Drive SOC 2 Type II compliance, including scope definition, controls, evidence collection, and auditor engagement.
- Own DORA compliance covering ICT risk management, incident classification/reporting, resilience testing, and third-party risk management.
- Ensure GDPR compliance for platform data processing in collaboration with the DPO.
Customer Security Assurance
- Handle customer security questionnaires, due diligence requests, and audit evidence packages.
- Prepare security reports and present security posture at customer governance meetings.
- Support RFPs and customer proposals with relevant security content.
Incident Response & Testing
- Own the security incident response plan, including severity levels, escalation, communication, and post-incident reviews.
- Act as incident commander for security-related P1/P2 incidents and deliver RCAs within defined SLAs.
- Commission and manage annual third-party penetration testing.
Policy & Governance
- Review and evolve security policies to align with ISO 27001, SOC 2, DORA, and applicable requirements.
- Conduct annual security risk assessments and maintain the security risk register.
- Oversee security awareness training and secure coding practices.
Required Skills & Experience
- 8+ years of experience in Information Security, Security Architecture, Security Engineering, or hands-on Security Lead roles.
- Experience maintaining an ISO 27001 ISMS through certification and surveillance cycles.
- Working knowledge of DORA or similar financial-sector ICT risk frameworks.
- Hands-on AWS security experience with IAM, VPC, KMS, WAF, GuardDuty, or equivalent.
- Experience with SIEM platforms such as Wazuh, Splunk, Microsoft Sentinel, or similar.
- Strong understanding of Application Security, including OWASP Top 10, API Security, OAuth, JWT, and SAML.
- Ability to communicate security posture effectively with customer executives, auditors, and regulators.
- Fluent English communication skills.
Nice-to-Have Skills
- Experience with SOC 2 Type II audits.
- Background in SaaS organizations serving regulated financial institutions.
- Practical experience with GDPR compliance.
- Relevant certifications such as:
- CISSP
- CISM
- ISO 27001 Lead Auditor
- AWS Certified Security – Specialty