Security Lead
Bangalore, Karnataka, IndiaJobNo compensation foundPosted 2w agoVerified open 4 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Don't just apply. Show up ready.
Olive works from this exact posting — no sign-up to start.
At a glance
Compensation
No compensation found
Location
Bangalore, Karnataka, India
Work Authorization
Not specified
Job overview
The Security Lead will own operational HITRUST and SOC2 programs, build and improve cloud security across AWS, GCP, and Azure, assess AI/LLM systems, quantify risks, manage vendors, and communicate security decisions to leadership while operating hands‑on as an individual contributor.
Skills & qualifications
RequiredNice to have
Skills
CISSPComplianceIdentity & Access Management (IAM)HIPAAAmazon Web ServicesCloud SecurityVulnerability ManagementSOC 2Security Architecture DesignMicrosoft AzureAthenaGoogle Cloud PlatformSDLCArtificial IntelligenceFinancial TechnologyApplication SecurityInformation SecuritySoftware as a ServiceCISMFinancial ServicesHL7Penetration TestingHITRUSTSOC2AI LLM SecuritySecure SDLCSecurity ArchitectureRisk QuantificationVendor ManagementCommunication
Qualifications
7+ Years Information Security Experience3+ Years Securing Products in Regulated EnvironmentsCISSP, CISM, CCSP or Equivalent Security CertificationOperational SOC2 Type II OwnershipExperience Securing Healthcare Integrations Using HL7 FHIR, Epic, AthenaExperience Assessing Agentic AI SystemsExperience in High‑Growth SaaS or AI StartupExperience Supporting Enterprise Customer Security Reviews
Full job description
Requirements:
- 7+ years of information security experience.
- 3+ years securing products in regulated environments such as healthcare (HIPAA), financial services, fintech, banking, insurance, or government.
- Demonstrated ownership of operational HITRUST or SOC2 programs, including maintaining ongoing compliance, not just participating in certification audits.
- Experience building or significantly improving cloud security across AWS, GCP, or Azure.
- Proven ability to quantify security risks using business context, cost-benefit analysis, and executive-level recommendations.
- Experience evaluating and managing external security vendors, consultants, and penetration
- testing providers and compliance partners.
- Hands-on experience assessing and securing AI/LLM-powered systems, internal AI tools, or AI-enabled products.
- Strong understanding of Identity & Access Management (IAM), Cloud Security, Application Security, Secure SDLC, Vulnerability Management, and Security Architecture.
- Excellent communication skills with the ability to translate technical security risks into business decisions.
- Comfortable operating as a highly hands-on individual contributor without a large security team.
Preferred Qualifications:
- Operational SOC2 Type II ownership.
- CISSP, CISM, CCSP, or equivalent security certification.
- Experience securing healthcare integrations using HL7 FHIR, Epic, Athena, or similar healthcare interoperability standards.
- Experience assessing or securing Agentic AI systems, including tool-calling agents, multi-step workflows, and autonomous AI applications.
- Previous experience in a high-growth SaaS or AI startup (Series A-C).
- Experience supporting enterprise customer security reviews and responding to security questionnaires.
What We're Looking For
- We're looking for someone who has demonstrated the ability to:
- Build practical security programs, not just policies.
- Balance business velocity with security through thoughtful risk-based decision-making.
- Recommend when security controls are unnecessary, rather than always advocating for the strictest option.
- Influence engineering teams through technical depth rather than authority.
- Secure modern cloud-native and AI-enabled software products while remaining hands-on.
- 7+ years in security, with 3+ years in a regulated environment (HIPAA, finance, or government), must be evidenced in bullets, not just worked at a healthcare company.
- Operational HITRUST or SOC2 experience, managed/maintained an ongoing program, not just audit participation or a one-time certification push.
- Structured risk quantification to non-technical leadership (documented cost vs. risk recommendations, not just identified risks).
- Built or significantly improved security infrastructure in a cloud-native environment (GCP, AWS, or Azure).
- Track record evaluating and managing external security vendors/consultants (scoping, risk assessment, delivery accountability).
- Direct hands-on AI/LLM security workassessing risk in an AI product, governing internal LLM tool usage, or building controls for LLM systems.
- Evidenced cost vs. risk judgmenta recommended against decision or documented trade-off, not just risk-averse defaults.
- Comfortable as a solo IC with no team to delegate torecent hands-on security work, not pure people management.
You've read the whole posting — now see how you match it.