Manager- Information security (ISO 27001 LA) at Glan management Consultancy · Gurugram · 7 - 15 years · ₹12L - ₹25L / yr · Bootstrapped · Posted 23 Aug 2025
Job Title: Manager Information Security – IT
Job Purpose: Acting in a key technical management & execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure MSR information technology needs are managed consistently, following professional IT and global standards, and delivered with a high level of quality and customer satisfaction.
Reward level: Middle Management
Job Location Gurgaon
Experience 10+ years
Relevant Experience 7+ years
Reporting to: General Manager
Qualification: Bachelor’s degree in IT
Key Deliverables:
· Provide support as Lead auditor towards ISMS and PIMS policies, procedures, and guidelines and perform regular review and update.
· Perform deep assessment to gather evidence of continuous compliance with ISO 27001:2022 and ISO 27701:2019, DPDPA, IT Act and Cert In Regulation including audit logs, records of reviews, timely closure of open audit and risks and sharing the report with management.
· Conduct regular, documented information security and privacy risk assessments identifying assets, threats, vulnerabilities, likelihood, and impact with stakeholders.
· Prioritize identified vulnerabilities, detailed findings, remediation recommendations, trending reports on vulnerability posture towards closure with stakeholders.
· Development and implementation of a comprehensive, ongoing security awareness and training program for all employees.
· Encourage secure behaviours among colleagues and reinforce the importance of information security and privacy in daily operations.
· Prepare regular report on overall information security posture, GRC maturity, and risk landscape to relevant stakeholders
· Ability to collect lessons learned from incidents, audits, and assessments to drive continuous improvement in ISMS/PIMS and security processes.
Key Relationships:
· Internal IT and business customers in MSR.
· Global IT Vendor, market and global (HQ) colleagues, Local vendor partners
· Internal staff - direct reports (where applicable)
· IT vendors, contractors (where applicable)
Knowledge Skills and Abilities:
· Must possess and demonstrate ISO 27001 Lead Implementer/Auditor and ISO 27701 Lead Implementer/Auditor certifications and knowledge.
· In depth understanding of IT Act, DPDPA, Cert In regulations, CIS Controls as well as UK DPA and ISO 31000
· Good to have certification on CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional) and Cloud Security certifications (e.g., CCSK, CCSP, vendor-specific like AWS Security Specialty)
· Familiarity with common vulnerability scanning tools like Qualys (features, reporting, agent-based vs. network scans) and Cloud Security Posture Management (CSPM) tools like Wiz (cloud service provider configurations, misconfigurations, compliance checks in AWS, Azure, GCP).
· Understanding of various penetration testing types (e.g., network, web application, API, mobile, cloud) and methodologies
· Knowledge of common attack vectors and exploitation techniques like MITRE ATTACK and DEFEND framework.
· Basic to intermediate knowledge of common security controls and technologies (e.g., firewalls, EDR, Cloud Security, VAPT tools, SIEM, WAF, DLP, encryption).
· Understanding of network protocols, operating systems (Windows, Linux), and common application architectures.
· Knowledge of audit principles and practices (internal and external audits).
· Understanding of corrective action planning and non-conformity management.
· Understanding of third-party risk management principles and vendor due diligence processes.
· Excellent technical writing skills for creating clear, concise, and comprehensive security policies, standards, and procedures.
· Ability to analyse complex risk data and present actionable insights.
· Hands-on experience with Qualys for configuring scans, analysing reports, and managing vulnerabilities.
· Hands-on experience with Wiz CSPM for monitoring cloud environments, identifying misconfigurations, and generating compliance reports.
· Proficiency with GRC platforms or tools for managing policies, risks, and controls
· Exceptional verbal and written communication skills to articulate complex security concepts to technical and non-technical stakeholders
· Ability to build strong relationships and collaborate effectively with diverse teams (IT, Legal, HR, Development, Business Units).
· Skills in influencing behaviour and driving change across the organization to improve security posture.
· Strong analytical skills to diagnose security issues, identify root causes, and develop effective solutions.
· Ability to critically evaluate security controls and identify gaps.
· Contract review and negotiation skills specifically for security-related services.
· Ability to effectively manage vendor relationships and performance.
· Ability to develop and deliver engaging security training sessions and awareness campaigns.
· Ability to stay updated with the latest security threats, vulnerabilities, technologies, and regulatory changes.
· Capacity to quickly learn and adapt to new tools and methodologies.
· Meticulous attention to detail in policy creation, audit documentation, and vulnerability analysis.
· Ability to act calmly and effectively during security incidents and contribute to incident response efforts.
mail updated resume- etalenthire[at]gmail[dot]com
satish: 88O 27 49 743

Similar jobs (10)
We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
Location: Jaipur, Rajasthan (Work From Office)
Experience: 5+ Years
Job Type: Full-Time
We're looking for an IT Compliance Officer to lead information security and compliance initiatives across our SaaS products and IT infrastructure. You'll ensure compliance with industry standards while strengthening our security and governance framework.
Key Responsibilities
- Manage compliance for SOC 2, ISO 27001, GDPR, and ITGC.
- Coordinate security audits, VAPT, and risk assessments.
- Develop and maintain security policies, SOPs, and compliance documentation.
- Ensure data protection, access control, and incident response best practices.
- Collaborate with IT, Development, QA, and Product teams to improve security controls.
- Conduct compliance training and stay updated on cybersecurity regulations.
Requirements
- 5+ years of experience in IT Compliance, Information Security, or IT Audit (preferably in a SaaS/Product company).
- Strong knowledge of SOC 2, ISO 27001, ITGC, VAPT, Risk Management, and Compliance Audits.
- Experience with security documentation, audit processes, and risk assessments.
- Excellent analytical, communication, and documentation skills.
Preferred: ISO 27001 Lead Auditor, CISA, CISM, CompTIA Security+, or Six Sigma certification.
Apply Now
Application Form: https://zfrmz.com/pAKb2ynfomIsuNwRfRbV?utm_source=cutshort
Job Summary
We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.
Key Responsibilities
- Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
- Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
- Review policies, procedures, controls, and audit evidence.
- Identify gaps, risks, observations, and recommend remediation.
- Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
- Support clients during certification, surveillance, and external audits.
- Conduct client meetings, interviews, and control walkthroughs.
- Coordinate evidence collection and remediation tracking.
- Develop and review information security policies and procedures.
- Stay updated with cybersecurity standards, regulations, and best practices.
Required Skills
- Strong understanding of Information Security, GRC, Risk & Compliance.
- Good knowledge of ISO 27001:2022 and SOC 2.
- Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
- Strong analytical, documentation, communication, and report-writing skills.
- Ability to independently manage client engagements.
Qualifications
- Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
- 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
- Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.
About Nerve Solutions
Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.
We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.
About the Role
We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.
The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.
Roles & Responsibilities
- Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
- Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
- Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
- Set up user accounts, systems, and required software for new employees and support onboarding activities.
- Monitor network performance and employee network activities to ensure system security and compliance.
- Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
- Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
- Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
- Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
- Assist in implementing information security best practices, security audits, and compliance initiatives.
- Coordinate with internal teams to ensure IT services effectively support business operations.
- Stay updated with the latest cybersecurity threats, technologies, and industry best practices.
Required Skills
- 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
- Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
- Experience troubleshooting hardware, software, network, and user-related issues.
- Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
- Experience with Active Directory, user access management, and system administration.
- Familiarity with Microsoft 365 administration is an added advantage.
- Understanding of backup, disaster recovery, and IT asset management.
- Strong analytical and problem-solving skills with attention to detail.
- Good communication and documentation skills.
- Ability to work independently and collaboratively in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Information Technology, Computer Science, or a related field.
- Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.
Key Responsibilities
- Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
- Conduct vulnerability assessments, penetration testing, and risk analysis.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
- Collaborate with IT and business teams to integrate security into system architecture and processes.
- Lead incident response drills and disaster recovery planning.
- Provide guidance and mentorship to junior cybersecurity staff.
- Stay updated on emerging threats, tools, and technologies.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5–10 years of proven experience in cybersecurity engineering or related roles.
- Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
- Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
- Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.
Skills
- Advanced problem-solving and analytical skills.
- Strong communication and leadership abilities.
- Ability to manage complex projects and handle escalations effectively.
- Proactive mindset with adaptability to evolving cyber threats.
IT Compliance Manager – Web3 & Digital Assets
📍 Location: Dubai, UAE
💼 Employment Type: Full-Time
🏢 Department: Technology / Compliance
📊 Experience: 5+ Years
🌐 Industry: FinTech / Web3 / Digital Assets
About the Role
We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.
The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.
Key Responsibilities
- Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
- Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
- Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
- Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
- Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
- Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
- Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
- Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
- Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
- Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.
Requirements
- Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
- 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
- Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
- Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
- Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
- Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
- Experience working with auditors, regulators, and cross-functional technology teams.
- Strong analytical, documentation, communication, and stakeholder-management skills.
UAE / Web3 Experience – Preferred
- Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
- Experience supporting VASP licensing or regulatory approvals.
- Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
- Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- CAMS
Key Skills
IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management
Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles
2
Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,
3
Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.
4
Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.
5
Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.
6
Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.
7
Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.
8
Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.
About the role
We’re hiring an IT Systems Administrator for an NBFC to secure endpoints, SaaS, and networks across ~50 branches, ~250+ field staff, and ~50+ office users.
This is primarily an IT Admin + Security role, with secondary exposure to AWS cloud ops + light DevOps + basic DB access management.
If you’re an IT Admin aiming to break into AWS Cloud Ops + DevOps, this role is a strong next step — you’ll own core IT/security and get hands-on exposure to cloud operations and deployments.
Key responsibilities (Primary: IT Admin + Security)
- Manage endpoint security for laptops and mobiles (policies, patching, encryption, antivirus/EDR); drive MDM implementation now/future (e.g., Intune/Jamf).
- Administer Google Workspace (Gmail/Drive/Calendar): users, groups, permissions, SSO, MFA, sharing controls.
- Own joiner–mover–leaver lifecycle: provisioning/deprovisioning, access controls, periodic access reviews.
- Secure branch connectivity: VPN, internal Wi-Fi, internet usage controls; coordinate troubleshooting and standardization across branches.
- Manage HO security stack: firewall operations, rule changes with change control, monitoring/log review (basic but consistent).
- Secure SaaS tools (CRM/HRMS/comms like Slack/Zoom): role-based access, MFA enforcement, offboarding, integration/OAuth controls.
- Maintain IT asset inventory: procurement coordination, issuance/return, audits, warranty/AMC, license renewals; remote lock/wipe for lost devices.
- Handle security incidents: phishing, account compromise, device loss/theft — contain, investigate, recover, and prevent recurrence.
- Run backups and basic DR testing; maintain SOPs/documentation and train staff on cyber hygiene.
- Provide hands-on user support: laptop builds, software installs, Outlook/Excel issues, VPN/Wi-Fi troubleshooting, escalations and vendor coordination.
Secondary responsibilities (AWS + DevOps + DB ops support)
- Support AWS administration: IAM users/roles/policies, MFA, access key hygiene, basic log review (e.g., CloudTrail).
- Manage AWS access controls: security groups/firewall rules, IP allowlists/whitelisting (admin tools, databases, vendor access).
- Assist engineering with DevOps operations:
- CI/CD support (deployment coordination, rollbacks, environment configuration)
- Secrets/credentials management and rotation (no shared creds)
- DNS + SSL/TLS certificates, basic monitoring/alerting coordination
- Bonus: Docker/Kubernetes and Terraform exposure
- Basic database operations (admin-lite):
- DB user creation, roles/permissions, least-privilege access
- IP allowlisting/whitelisting for DB access via VPN/approved sources
- Backup/restore verification coordination and basic monitoring signals (connections/storage)
Requirements
- 3+ years in IT security / systems administration (BFSI or branch-heavy org preferred).
- Hands-on with Google Workspace or Microsoft 365 administration.
- Must have hands-on experience leading or executing an email suite migration (e.g., Google Workspace ↔ Microsoft 365), including mailbox migration, DNS cutover, MX/SPF/DKIM/DMARC reconfiguration, and user transition management.
- Strong endpoint/security fundamentals: encryption, patching, AV/EDR, remote support, device compliance.
- Comfortable with networks: VPN/Wi-Fi/LAN troubleshooting; firewall basics and change discipline.
- Strong operational discipline: asset tracking, vendor management, documentation, ticketing, user communication.
- Practical AWS familiarity (IAM, access controls, logging) and ability to support DevOps workflows.
Nice to have
- Experience implementing MDM at scale (Intune/Jamf/SureMDM).
- Exposure to SOC2 / ISO27001 evidence, controls, and audit workflows.
- Scripting for automation (PowerShell/Bash/Python).
- Familiarity with managed databases and secure access patterns.
Job Title: AppSec / AI Security Engineer
Employment Type: Full-time/ Permanent
Location: Indore (Work from Office)
About the Role
We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.
If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.
Key Responsibilities
- Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
- Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
- Develop structured code review workflows incorporating specifications, scan results, and code provenance.
- Optimize security scanning tools to reduce false positives and drive developer adoption.
- Investigate and manage security findings using established remediation and documentation processes.
- Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
- Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.
Required Skills & Experience
- Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
- Experience implementing automated security scanning and enforcement — not just operating existing tools.
- Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
- Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
- Ability to design, build, and own security automation and governance solutions from the ground up.
- Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
- Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
- Strong analytical mindset and ability to independently assess security risk across internal and external codebases.
Preferred Qualifications
- ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
- Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
- Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
- AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
- Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
- Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).
About Company:
Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.
For more info, please visit our website: https://5exceptions.com






