Security Lead (Bengaluru)

Security Lead (Bengaluru)

10 Aug
|
GTMfund
|
Bengaluru

10 Aug

GTMfund

Bengaluru

Security And Risk Management The candidate will have responsibilities across the following functions: Own and continuously improve the company's security program across cloud infrastructure, applications, and engineering processes.

Drive operational compliance programs including HITRUST and SOC2 Type II, ensuring continuous compliance rather than point-in-time certification.

Develop structured risk assessments that clearly communicate business impact, implementation cost, mitigation options, and recommendations to technical and executive stakeholders.

Build and maintain security policies, standards, controls, and governance frameworks.

Lead customer security reviews, vendor security questionnaires, and enterprise trust assessments.

Cloud And Infrastructure Security

Design and strengthen security architecture across AWS, GCP, or Azure environments.

Improve Identity and Access Management (IAM), secrets management, encryption, network segmentation, vulnerability management, and infrastructure hardening.

Embed security controls into CI/CD pipelines and software development workflows.

Partner with Engineering teams to implement secure-by-design practices across cloud-native applications. AI And Application Security Assess security risks associated with AI/LLM-powered applications and internal AI tooling.

Define governance and security controls for LLM usage across engineering teams.

Evaluate risks such as prompt injection, sensitive data leakage, model abuse, excessive permissions, and agent execution risks.

Partner with Engineering to implement secure AI development practices for agentic workflows and LLM-enabled products.

Vendor And Compliance Management

Evaluate security vendors, penetration testing partners,



compliance consultants, and external assessors.

Define security requirements, assess risks, monitor deliverables, and ensure accountability across external engagements.

Own remediation planning and long-term security improvement initiatives.

Incident Preparedness

Define incident response processes, security runbooks, and post-incident improvement plans.

Drive continuous security monitoring, vulnerability management, and operational readiness.

Requirements 7+ years of information security experience.

3+ years securing products in regulated environments such as Healthcare (HIPAA), Financial Services, FinTech, Banking, Insurance, or Government.

Demonstrated ownership of operational HITRUST or SOC2 programs, including maintaining ongoing compliance, not just participating in certification audits.

Experience building or significantly improving cloud security across AWS, GCP, or Azure.

Proven ability to quantify security risks using business context, cost-benefit analysis, and executive-level recommendations.

Experience evaluating and managing external security vendors, consultants, penetration testing providers, and compliance partners.

Hands-on experience assessing and securing AI/LLM-powered systems, internal AI tools, or AI-enabled products.

Strong understanding of: Identity and Access Management (IAM), Cloud Security,



Application Security, Secure SDLC, Vulnerability Management, Security Architecture.

Excellent communication skills with the ability to translate technical security risks into business decisions.

Comfortable operating as a highly hands-on Individual Contributor without a large security team.

Preferred Qualifications Operational SOC2 Type II ownership.

CISSP, CISM, CCSP, or equivalent security certification.

Experience securing healthcare integrations using HL7 FHIR, Epic, Athena, or similar healthcare interoperability standards.

Experience assessing or securing Agentic AI systems, including tool-calling agents, multi-step workflows, and autonomous AI applications.

Previous experience in a high-growth SaaS or AI startup (Series A-C).

Experience supporting enterprise customer security reviews and responding to security questionnaires.

Good To Have

We're looking for someone who has demonstrated the ability to: Build practical security programs- not just policies.

Balance business velocity with security through thoughtful risk-based decision-making.

Recommend when security controls are unnecessary, rather than always advocating for the strictest option.

Influence engineering teams through technical depth rather than authority.

Secure contemporary cloud-native and AI-enabled software products while remaining hands-on.

Nice To Have Healthcare Revenue Cycle

Management (RCM) or HealthTech experience.

Security awareness and developer training programs.

GCP security expertise.

Multi-tenant SaaS architecture experience.

Public speaking, conference presentations, blogs, or open-source security contributions.

📌 Security Lead (Bengaluru)
🏢 GTMfund
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security lead (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: security lead (bengaluru) / bengaluru