2 months ago
Bengaluru, IndiaSenior
Responsibilities
- Own and evolve security architecture across cloud infrastructure, applications, and APIs.
- Identify, prioritize, remediate, and validate security issues with engineering teams.
- Perform threat modeling and security design reviews and embed security into the development lifecycle.
- Define security standards, reference architectures, and hardening baselines and drive adoption.
- Coordinate penetration testing, vulnerability management, remediation tracking, and closure of findings.
- Translate regulatory and privacy requirements into technical and organizational controls.
- Own technical audit and assessment activities, including evidence, control mapping, and remediation.
- Represent security in customer questionnaires, due-diligence calls, trust discussions, and auditor interactions.
- Partner with privacy and data-protection teams on GDPR and other requirements involving personal and biometric data.
- Contribute to incident detection, investigation, response readiness, and post-incident improvement.
- Mentor and eventually manage junior security engineers as the team grows.
Requirements
- 7 to 9 years of experience in security engineering, security architecture, or a closely related field, securing production systems at scale.
- Hands-on ability to reason about application code, cloud infrastructure, and API design and work with engineers on fixes.
- Strong cloud-security knowledge covering network segmentation, IAM, secrets and key management, workload and container security, and infrastructure-as-code.
- Deep application and API security knowledge, including access-control flaws, injection, SSRF, authentication, authorization, secure design patterns, and secure SDLC practices.
- Current understanding of SOC 2, ISO/IEC 27001, GDPR, and related security and privacy frameworks.
- Experience handling certification, enterprise-client, and regulatory audits and assessments, including evidence preparation and finding remediation.
- Strong communication skills with engineers, executives, auditors, customers, and regulators.
- Sound judgment balancing security, business needs, and delivery.
- Experience in fintech, regtech, identity verification, or another regulated data-sensitive domain is valued.
- Experience handling personal, biometric, or identity data and related privacy obligations is valued.
- Background in penetration testing, red teaming, or vulnerability research is valued.
- Familiarity with privacy regulations beyond GDPR and DevSecOps practices and tooling is valued.
- CISSP, CCSP, OSCP, CIPP, or CIPT certifications are valued.
- Experience mentoring or leading engineers and interest in building and managing a team is valued.
Categories
About AiPrise
AiPrise builds a B2B platform for fraud prevention, risk, and compliance that unifies KYC/KYB, identity verification, and business onboarding across 200+ countries. Banks, fintechs, payment providers, crypto firms, and marketplaces use it to consolidate data and design compliant onboarding flows. Founded in 2022 and based in San Jose, the privately held, YC-backed company is at the Series A stage.
