A

Lead Security Engineer

Angel One · Bengaluru, Karnataka, India

full_timePosted Today
Apply now →

Job description

**Role & responsibilities** - Lead the design and evolution of enterprise security architecture across endpoints, servers (Windows/Linux), network infrastructure, and multi-cloud environments (AWS and GCP). - Define and drive the implementation of scalable, resilient security solutions aligned with business priorities and risk posture. - Own and oversee critical security platforms and controls, ensuring high availability, effectiveness, and continuous optimization. - Provide technical leadership in security design reviews, setting standards and guiding teams toward secure-by-design architectures. - Partner with senior stakeholders across engineering, infrastructure, and product teams to embed security into system design, development lifecycles, and operational processes. - Establish and enforce enterprise-wide security baselines, standards, and reference architectures across on-premises and cloud environments. - Lead complex security initiatives and programs, from planning through execution, ensuring timely delivery and measurable outcomes. - Drive advanced threat modeling, attack surface analysis, and proactive risk reduction strategies. - Oversee integration of security telemetry into detection and response ecosystems, improving visibility, detection quality, and response readiness. - Guide audit and compliance efforts, ensuring alignment with regulatory requirements and internal governance standards. - Champion automation and engineering excellence by introducing scalable solutions, reducing manual effort, and improving operational efficiency. - Mentor and develop security engineers, fostering technical growth, accountability, and high performance within the team. - Act as a technical escalation point for complex security challenges and incidents. - Influence security strategy, tooling decisions, and long-term roadmap in collaboration with leadership within the CISO organization. - Define and implement security controls for enterprise use of AI/ML technologies, addressing risks such as data leakage, model misuse, and adversarial threats. **Preferred candidate profile** - 7 to 10+ years of experience in cybersecurity, with strong depth in security engineering and architecture. - Demonstrated experience leading the design and implementation of security solutions across enterprise-scale environments, including hybrid and multi-cloud infrastructures. - Deep expertise in multiple security domains, such as network security, endpoint protection, identity and access management, application/API security, and data protection. - Advanced hands-on experience with cloud security (AWS and/or GCP), including architecture design, workload protection, and cloud-native security controls. - Strong proficiency with enterprise security technologies such as firewalls, WAF, IDS/IPS, EDR/XDR, IAM platforms, API gateways, and data security solutions. - Extensive knowledge of system hardening, vulnerability management, and secure configuration practices aligned with industry benchmarks. - Strong understanding of security frameworks and standards such as NIST, ISO 27001/27002, CIS Controls, and cloud security best practices. - Proven ability to lead large-scale security initiatives, drive cross-functional collaboration, and influence technical decisions. - Experience with automation and scripting (e.g., Python, PowerShell, Bash) to build scalable and efficient security solutions. - Strong familiarity with DevSecOps practices, CI/CD security, and infrastructure-as-code security. - Deep understanding of Zero Trust architecture and modern defense strategies. - Ability to assess complex risks, make informed decisions, and balance security with business needs. - Excellent communication and stakeholder management skills, with the ability to translate technical risks into business impact. - Relevant certifications such as CISSP, CCSP, or equivalent are strongly preferred. - Solid understanding of AI/ML security risks, including model abuse, data exposure, and adversarial techniques, along with practical mitigation strategies.