Cutshort logo
For Employers
Credilio Financial Technologies Pvt. Ltd. logo
Information Security Officer

Information Security Officer at Credilio Financial Technologies Pvt. Ltd. · Mumbai · 4 - 8 years · Raised funding · Posted 21 Jul 2026

Credilio Financial Technologies Pvt. Ltd.'s logo

Information Security Officer

Munjal Dhamecha's profile picture
Posted by Munjal Dhamecha
4 - 8 yrs
Best in industry
Mumbai
Skills
Information security
Information security management system
Audit
Compliance
PCI DSS
Risk assessment

Job Summary

 

We are looking for an Information Security & Compliance Officer to own and drive information security governance, risk management, audit readiness, compliance execution, and cybersecurity coordination.

 

The person will maintain compliance readiness across ISO 27001, PCI DSS, DL-SAR, CICRA, bank/partner audits, RBI requirements, Digital Lending Guidelines, and data protection requirements, while supporting readiness for ISO 27701, SOC 2 Type 2, DPDP, and other future compliance needs.

 

Responsibilities

·      Own and drive information security governance, risk management, compliance, and audit readiness.

·      Manage the audit and compliance calendar, including bank audits, regulatory reviews, partner reviews, security questionnaires, and external assessments.

·      Maintain audit and compliance readiness for ISO 27001, PCI DSS, DL-SAR, CICRA, RBI Cyber Security Framework, Digital Lending Guidelines, DPDP/data privacy, and other applicable requirements.

·      Maintain policies, procedures, risk registers, audit evidence, compliance trackers, security documentation, and closure reports.

·      Conduct and coordinate internal reviews for access control, privileged access, policy compliance, vendor security, cloud security, and security configurations.

·      Coordinate VAPT, source code reviews, cloud security reviews, configuration reviews, SAST/DAST activities, and remediation tracking.

·      Work with Technology, DevOps, IT, Compliance, HR/Admin, vendors, and business teams to close vulnerabilities, audit findings, security gaps, incidents, and risks.

·      Own and drive security incident response execution, including escalation coordination, RCA tracking, corrective actions, evidence documentation, closure reports, and periodic drills.

 

Required Skills

·      Good understanding of information security, GRC, IT risk, audits, compliance, and cybersecurity controls.

·      Working knowledge of application security, API security, cloud security, IAM, vulnerability management, incident response, secure SDLC, and vendor security.

·      Understanding of ISO 27001, PCI DSS, RBI Cyber Security Framework, Digital Lending Guidelines, banking/fintech requirements, and data protection requirements.

·      Ability to assess technical security risks, define controls, and coordinate remediation with technical teams.

·      Strong audit handling, evidence management, documentation, communication, follow-up, and ownership.

·      Ability to work independently with auditors, banks, vendors, technical teams, and business stakeholders.

 

Required Qualification

·      3–8 years of experience in information security, GRC, IT risk, cybersecurity coordination, audit, or compliance.

·      Experience handling bank audits, regulatory audits, ISO 27001, PCI DSS, VAPT coordination, access reviews, risk registers, audit evidence, and remediation tracking is preferred.

·      Experience in fintech, banking, NBFC, payments, lending, or regulated technology environments is preferred.

·      Bachelor’s degree in Computer Science, IT, Information Security, or a related field.

Relevant certification preferred, such as ISO 27001 LA/LI, CISA, CISM, PCI DSS, ISO 27701, Security+, CEH, or equivalent.

Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About Credilio Financial Technologies Pvt. Ltd.

Founded :
2020
Type :
Product
Size :
100-500
Stage :
Raised funding

About

Credilio is founded with the idea of digitizing the distribution value chain of personal finance products. The mission of Credilio is to create a nationwide army of multi-branded trained advisors who can assist in the digital onboarding of loans and cards. Credilio enables a small financial advisor to educate customers and recommend lending products that are best suited to meet their unique requirements and further enables them to subscribe for credit cards or loans digitally.


The company does this by providing a large range of product offerings and a customized recommendation tool through a simple mobile app that empowers advisors to be truly digital and future-ready. In addition, the platform allows for instant online approval by leveraging open banking APIs of Banks and NBFCs, thus making the purchase process transparent and paperless. It has reduced the average prospecting-to-onboarding time to less than 10 minutes in a single session as compared to the industry average of an interrupted process over 2-3 days.


A challenger start-up, Credilio is the brainchild of second-time entrepreneurial duo Mr. Aditya Gupta and Mr. Anand Kapadia. It’s backed by a clutch of Venture Capital funds namely Cornerstone Venture Capital Partners, Exfinity Venture Partners, and Param Capital founder Mukul Agarwal.


The platform currently partners with 20+ leading Banks and NBFCs and has over 10,000 Financial Advisors who have assisted more than 0.5 million customer applications getting processed fully digitally in a span of less than a year. The capital raised will power Credilio’s ambitious plans to meet an ARR of 100 cr. by March 2023 and serve 25 million customers through a million advisors in the next 3 years.

Read more

Tech stack

skill iconNodeJS (Node.js)
TypeScript
AdonisJS
skill iconPostgreSQL
skill iconFlutter
skill iconVue.js

Photos

Company featured pictures

Connect with the team

Profile picture
Munjal Dhamecha
Profile picture
Yusuf Qureshi

Company social profiles

instagramlinkedintwitterfacebook

Similar jobs (10)

company logo
CyberAlpha ConsultingLLP
Posted by CyberAlpha ConsultingLLP
Noida
2 - 6 yrs
₹3L - ₹6L / yr
GRC
PCI DSS
ISO/IEC 27000-series

Job Summary

We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.


Key Responsibilities

  • Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
  • Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
  • Review policies, procedures, controls, and audit evidence.
  • Identify gaps, risks, observations, and recommend remediation.
  • Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
  • Support clients during certification, surveillance, and external audits.
  • Conduct client meetings, interviews, and control walkthroughs.
  • Coordinate evidence collection and remediation tracking.
  • Develop and review information security policies and procedures.
  • Stay updated with cybersecurity standards, regulations, and best practices.


Required Skills

  • Strong understanding of Information Security, GRC, Risk & Compliance.
  • Good knowledge of ISO 27001:2022 and SOC 2.
  • Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
  • Strong analytical, documentation, communication, and report-writing skills.
  • Ability to independently manage client engagements.


Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
  • 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
  • Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.


Read more
company logo
Dubai
4 - 10 yrs
₹25L - ₹39L / yr
ISO/IEC 27001:2005
Web3js

IT Compliance Manager – Web3 & Digital Assets

📍 Location: Dubai, UAE

💼 Employment Type: Full-Time

🏢 Department: Technology / Compliance

📊 Experience: 5+ Years

🌐 Industry: FinTech / Web3 / Digital Assets


About the Role

We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.

The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.


Key Responsibilities

  • Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
  • Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
  • Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
  • Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
  • Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
  • Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
  • Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
  • Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
  • Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
  • Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.


Requirements

  • Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
  • 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
  • Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
  • Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
  • Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
  • Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
  • Experience working with auditors, regulators, and cross-functional technology teams.
  • Strong analytical, documentation, communication, and stakeholder-management skills.

UAE / Web3 Experience – Preferred

  • Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
  • Experience supporting VASP licensing or regulatory approvals.
  • Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
  • Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.

Preferred Certifications

  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • CAMS

Key Skills

IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management


Read more
company logo
Ramya Munirathnam
Posted by Ramya Munirathnam
Bengaluru (Bangalore), Chennai, Hyderabad, Mumbai, Pune
5 - 7 yrs
₹6L - ₹12L / yr
Cyber Security
GRC
Security Compliance

This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).

Key responsibilities:

  • Perform security control assessments against organizational policies, security standards, and regulatory requirements.
  • Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
  • Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
  • Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
  • Conduct control testing and risk assessments and support internal/external security audits.
  • Review security policies, procedures, standards, and governance frameworks for compliance.
  • Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
  • Support overall security governance, regulatory compliance, and IT risk management activities.

Required Skills

  • Cyber Security Risk & Compliance / GRC
  • IT Risk & Controls
  • Security Control Assessment & Testing
  • Security Audits
  • Backup & Disaster Recovery
  • BCP / DR
  • Risk Assessment
  • Compliance & Governance
  • Security Policies & Standards
  • Audit Finding & Remediation Management
Read more
company logo
Yashaswini Bangera
Posted by Yashaswini Bangera
Mumbai
5 - 7 yrs
₹8L - ₹15L / yr
ISO/IEC 27001:2005
Information security governance
Compliance
Risk Management
Stakeholder management

We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the

design, implementation, and maintenance of our ISO 27001 Information Security Management

System (ISMS). This is a hands-on leadership role responsible for establishing a robust security

governance framework, achieving ISO 27001 certification, and embedding a culture of

continuous security improvement across the organization.

Key Responsibilities

● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation

from gap analysis through to successful Stage 1 and Stage 2 certification audits;

manage external auditor relationships

● Risk Management: Develop and operationalize the information security risk

management framework; conduct risk assessments, treatment planning, and risk

acceptance processes.

● Policy & Governance : Author, approve, and maintain the Statement of Applicability

(SoA), information security policies, standards, and procedures aligned with ISO 27001

Annex A controls.

● Control Implementation: Translate ISO 27001 Annex A controls into operational

security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to

implement and validate controls.

● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and

KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective

actions.

● Third-Party Risk: Oversee vendor security assessments and ensure supply chain

security controls meet organizational and ISO 27001 standards.

● Stakeholder Management: Report ISMS performance, risks, and compliance status to

senior leadership and the board; act as primary liaison for external auditors and

regulators.

Required Qualifications

● 5+ years of experience in information security governance, risk, and compliance

● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap

analysis → certification)

● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS

documentation requirements

● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,

OCTAVE, FAIR)

● Familiarity with internal audit practices and managing external certification bodies

● Excellent stakeholder management and ability to influence across technical and non-

technical teams

● Strong documentation and communication skills — able to translate complex standards

into actionable guidance

Preferred Qualifications

● Experience implementing ISMS in fintech, healthcare, or regulated industries

● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks

● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments

● Knowledge of automation for compliance evidence collection and control testing

● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead

Implementer

Why Join Us

● Opportunity to build the security governance function from the ground up

● High-visibility role with direct impact on customer trust and market differentiation

● Collaborative environment that values security as a business enabler, not a blocker

Company Profile:

We are a one-stop financial services shop, widely known for quality of its advice, personalized

service and cutting-edge technology. We started our journey in 2008. Currently we are serving

more than 50,000 investors with a team of 100 members. Our core product offering is mutual

fund, FD, Govt. Bonds, Debenture, etc.



Read more
company logo
Vijayshree Purohit
Posted by Vijayshree Purohit
Mumbai
3 - 5 yrs
₹8L - ₹9L / yr
Comp TIA A+
Microsoft
CCNA
Security+
Network +
+1 more

About Nerve Solutions

Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.

We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.


About the Role

We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.

The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.


Roles & Responsibilities

  • Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
  • Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
  • Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
  • Set up user accounts, systems, and required software for new employees and support onboarding activities.
  • Monitor network performance and employee network activities to ensure system security and compliance.
  • Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
  • Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
  • Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
  • Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
  • Assist in implementing information security best practices, security audits, and compliance initiatives.
  • Coordinate with internal teams to ensure IT services effectively support business operations.
  • Stay updated with the latest cybersecurity threats, technologies, and industry best practices.



Required Skills

  • 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
  • Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
  • Experience troubleshooting hardware, software, network, and user-related issues.
  • Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
  • Experience with Active Directory, user access management, and system administration.
  • Familiarity with Microsoft 365 administration is an added advantage.
  • Understanding of backup, disaster recovery, and IT asset management.
  • Strong analytical and problem-solving skills with attention to detail.
  • Good communication and documentation skills.
  • Ability to work independently and collaboratively in a fast-paced environment.



Preferred Qualifications

  • Bachelor's degree in Information Technology, Computer Science, or a related field.
  • Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.


Read more
company logo
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
company logo
Zeeshan Sheikh
Posted by Zeeshan Sheikh
Kolkata
6 - 10 yrs
₹4L - ₹5L / yr
Cyber Security
Security Information and Event Management (SIEM)
Network Security
Information security management system
Information security

A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.

Key Responsibilities

  • Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
  • Conduct vulnerability assessments, penetration testing, and risk analysis.
  • Monitor and respond to security incidents, ensuring timely resolution and documentation.
  • Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
  • Collaborate with IT and business teams to integrate security into system architecture and processes.
  • Lead incident response drills and disaster recovery planning.
  • Provide guidance and mentorship to junior cybersecurity staff.
  • Stay updated on emerging threats, tools, and technologies.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
  • 5–10 years of proven experience in cybersecurity engineering or related roles.
  • Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
  • Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
  • Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.

Skills

  • Advanced problem-solving and analytical skills.
  • Strong communication and leadership abilities.
  • Ability to manage complex projects and handle escalations effectively.
  • Proactive mindset with adaptability to evolving cyber threats.


Read more
company logo
Ananya  Arenavaru
Posted by Ananya Arenavaru
Bengaluru (Bangalore)
5 - 10 yrs
₹15L - ₹18L / yr
Jump Cloud
Sophos
google workspace
SSO
Sophos Central administration
+10 more

IT Systems Engineer

Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure

Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership

Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at

scale.

The Mission

About Metadome.ai

Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the

Metaverse Standards Forum and the VR/AR Association.


About the Role

We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.

This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.


Core Responsibilities

● Identity & Access Management — JumpCloud:

○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.

○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.

○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.

○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.

○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.

● Google Workspace Administration — GWS:

○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.

○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,

and sharing / visibility policies.○

○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.


Endpoint & Threat Protection — Sophos:

○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and

servers.

○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.

○ Maintain endpoint encryption, web / application control, and device-hardening standards.

○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.


Network, Firewall & Wi-Fi:

○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.

○ Administer enterprise Wi-Fi and wired networks (switches, access points), including

RADIUS-backed authentication.

○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.

○ Implement network monitoring, intrusion detection, and centralized logging.

Hardware, Software & Asset Management:

○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and

decommissioning.

○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.

○ Maintain an accurate hardware and software inventory and asset register.

○ Manage software deployment, patch management, and license compliance.


Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:

○ Operate and continuously improve the company's Information Security Management System

(ISMS).

○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control

implementation, evidence collection, and continuous monitoring.

○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA

assessments.

○ Serve as a primary point of contact during external audits and customer security reviews.

○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response

runbooks.

○ Drive security-awareness and phishing-simulation programs across the organization.


IT Operations & Support:

○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.

○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.

○ Manage backups, disaster recovery, and business-continuity testing.

○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within

budget.

○ Maintain documentation, runbooks, and standard operating procedures.

○ Own and report on the IT budget and asset allocation.


Required Skills & Experience

● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems

below rather than purely supervisory exposure.

● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.

● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.

● Sophos — hands-on endpoint / XDR administration and threat response.

● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.

● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one

full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.


Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.

System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.


Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.


Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.


Preferred Qualifications


●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.

●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.

●Scripting and automation for IT operations (Bash, PowerShell, or Python).

●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.

●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.


Why Join Us

You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running

flawlessly.



Read more
company logo
Mayank Choudhary
Posted by Mayank Choudhary
icon

The recruiter has not been active on this job recently. You may apply but please expect a delayed response.

Bengaluru (Bangalore)
3 - 7 yrs
₹40L - ₹45L / yr
Cloud security

Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles

2

Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,

3

Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.

4

Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.

5

Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.

6

Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.

7

Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.

8

Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.

Read more
company logo
Neha Daka
Posted by Neha Daka
Indore
4 - 8 yrs
₹3.5L - ₹10L / yr
ApplicationSecurity,Cybersecurity, DevSecOps,CI/CD
DAST
SAST
Cloud Computing

Job Title: AppSec / AI Security Engineer


Employment Type: Full-time/ Permanent

Location: Indore (Work from Office)


About the Role

We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.

If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.

 

Key Responsibilities

  • Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
  • Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
  • Develop structured code review workflows incorporating specifications, scan results, and code provenance.
  • Optimize security scanning tools to reduce false positives and drive developer adoption.
  • Investigate and manage security findings using established remediation and documentation processes.
  • Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
  • Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.


Required Skills & Experience

  • Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
  • Experience implementing automated security scanning and enforcement — not just operating existing tools.
  • Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
  • Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
  • Ability to design, build, and own security automation and governance solutions from the ground up.
  • Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
  • Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
  • Strong analytical mindset and ability to independently assess security risk across internal and external codebases.


Preferred Qualifications

  • ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
  • Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
  • Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
  • AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
  • Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
  • Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).


About Company:

Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.

 

For more info, please visit our website:  https://5exceptions.com

Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos