Director, Information Security
IT
India · Bengaluru, Karnataka, India
Posted on Jul 30, 2026
- Technical Leadership: Lead a team of 4 senior security engineers — setting technical direction, reviewing code, owning architecture decisions, and ensuring every engineer grows in both traditional InfoSec depth and agentic AI engineering capability.
- Automated Security Platform: Own the design, deployment, and ongoing evolution of our intelligent security response platform — a Python-based, AI-driven pipeline that automates vulnerability discovery, contextual triage, reasoning, and graduated remediation across our full product estate.
- Autonomy Policy & Governance: Define and own the graduated automation policy — what the platform may execute automatically, what requires human approval, and what constitutes a break-glass escalation. You hold the senior technical authority for automated remediation decisions.
- Global InfoSec Interlock: Operate as the primary technical representative of the Bengaluru security engineering team in global InfoSec forums — owning the security posture reporting, KPI tracking (MTTA, SAST coverage, remediation velocity), and executive-level updates.
- InfoSec Transformation: Lead the progressive transition from reactive, manual vulnerability management to a proactive, automated, evidence-driven security practice — retiring manual triage queues, spreadsheet tracking, and ad hoc patching in favour of platform-driven workflows.
- Team Development: Hire, develop, and retain security engineers who are genuinely dual-track — capable of operating traditional security tooling and building and maintaining the agentic layer that reasons over it.
WHAT WE ARE LOOKING FOR
- 15+ years in information security engineering, with at least 8 years in a technical leadership or senior engineering management role — you must be credible as an engineer to the team you lead.
- Hands-on Python development experience — you write production-quality Python, not just review it. Security automation, API integration, and pipeline development are your native territory.
- Proven experience delivering a security engineering programme at scale — SAST/SCA/DAST across a multi-product estate, CI/CD security gate enforcement, vulnerability lifecycle management end-to-end.
- Direct experience with agentic AI or LLM-based automation in a production security context — confidence-scored decision pipelines, human-in-the-loop gate design, automated evidence generation.
- Experience designing and governing automated remediation policies — graduated autonomy models, kill-switch protocols, audit trail requirements, and SOC 2 or equivalent compliance mapping.
- Track record of building and developing dual-track security engineering teams — engineers who are both InfoSec practitioners and automation/AI builders.
- Background in FinTech, enterprise SaaS, or a regulated technology environment — practical understanding of how compliance obligations shape security architecture decisions.
CORE TOOLING & TECHNOLOGIES
Python (production-level) · Snyk · SonarQube · Tenable · Wiz · LangChain / LangGraph · Claude / GPT-4o APIs · Jira / JSM · CI/CD (GitLab CI) · Datadog · OWASP ASVS · SOC 2 · CVSS