29 Aug
|
InvestCloud
|
Bengaluru
29 Aug
InvestCloud
Bengaluru
Company Description InvestCloud is a global financial technology company managing technology for over $6 trillion in wealth assets across the world's leading wealth management and asset management institutions. Recognized by CNBC as one of the World's Top FinTech Companies, InvestCloud powers digital wealth platforms used by some of the most demanding financial clients on the planet.
Our Bengaluru engineering hub is a center of gravity for hands-on technical talent, with 250+ engineers building and operating the platforms that serve global financial institutions. This is not a support function. It is a product engineering and platform operations center that is increasingly leading global capability development.
Security Engineer at Invest Cloud At InvestCloud, we are building an intelligent security response capability that determines what to fix first based on the actual risk to our clients and business, not a scanner's native severity.
Traditional vulnerability management produces disconnected findings and long backlogs. It often misses whether vulnerable code is deployed, reachable by an attacker, connected to a critical service, capable of lateral movement, or already being exploited. We are solving that problem by combining threat intelligence, runtime and deployment evidence, configuration management data, attack path analysis, business criticality, and validation results.
The platform will ingest findings from infrastructure, cloud, application, software supply chain, secrets, containers, infrastructure as code, and adversarial testing. It will reconcile them to a canonical asset and service model, deduplicate them into unique exposures, and rank the remediation actions that remove the most risk.
The product is being built in Python on AWS with source-controlled connectors, deterministic policy code, an AI reasoning layer, human approval gates, complete audit evidence, and closed-loop validation. Large language models (LLMs) can correlate evidence, recommend remediation, and explain decisions. They do not calculate the authoritative priority score.
This is not another scanner or dashboard. It is a security decision and remediation platform that must answer one question reliably: what is the single next action that will remove the most material risk, why is it first, who owns it, and how will we verify the risk is gone? Every engineer on this team will build production software,
operate what they build, and own the product after the initial consultant implementation.
Role Description As our Infrastructure & Cloud Security Engineer, you will own the data and platform foundation that every prioritization and remediation decision depends on. You will build the source adapters, canonical schema, normalization, reconciliation, and data quality controls that turn disconnected scanner, intelligence, asset, repository, and deployment records into trusted security data.
Jira Assets is the initial configuration management database (CMDB), but the harness must remain independent of Jira, Wiz, Rapid7, Tenable, Snyk, and every other vendor. You will design source contracts and AWS services so you can add new tools or a future data lake or warehouse without rewriting the scoring, reasoning, or remediation layers.
What you will Own
Security Data Ingestion: Build and operate source adapters for Wiz, Rapid7 or Tenable, Snyk, VVAH, Jira Assets, security testing platforms, SARIF producers, and threat intelligence feeds. Support bulk, incremental, event-based, and artifact-based ingestion with read-only source access.
Canonical Model & Reconciliation: Normalize findings, observations, assets, repositories, commits, pipelines, artifacts, deployments, services, clients, and remediation actions. Reconcile records to the correct entities, deduplicate repeated observations, and retain full source provenance and raw history.
Asset, Deployment & Coverage Context: Build the links from repository to pipeline, artifact, runtime asset, application service, business service, client, owner, and external route. Surface missing agents, broken mappings, stale data, and other coverage gaps as actionable work.
Threat & Vulnerability Intelligence Feeds: Ingest and maintain independent CVE, exploitation, advisory, fixed version, malicious package, and lifecycle data, including CVE or NVD, CISA KEV and Vulnrichment, EPSS, GitHub Security Advisories, OSV, vendor advisories, and equivalent sources.
AWS Data Platform Reliability: Own Lambda- or container-based connectors, SQS and dead letter queues, S3 raw history, Aurora PostgreSQL, secrets, identity, infrastructure as code, monitoring, and recovery. Define service-level expectations for freshness, completeness, reconciliation, and schema compatibility.
Production Engineering & Handover: Keep connectors, transformations, tests, schemas, and infrastructure under source control. Build automated tests and observability, participate in architecture and code reviews, document operating procedures, and take permanent ownership from Electric Mind.
Qualifications
7+ years in infrastructure security, cloud security, DevSecOps, security data engineering, or a closely related discipline, with explicit evidence of lead-level technical ownership. Advisory-only experience is not sufficient.
Production Python and SQL. You can design maintainable APIs, data pipelines, schemas, asynchronous processing, error handling, tests, and migrations, not just scripts.
Hands-on AWS engineering with services such as Lambda, SQS, S3, ECS or Fargate, Aurora or PostgreSQL, IAM, Secrets Manager, CloudWatch, and Terraform or CloudFormation.
Security data depth across cloud and infrastructure findings, application and dependency findings, SBOMs, SARIF, vulnerability intelligence, and scanner APIs. You understand the security meaning of the data you are transforming.
Entity resolution and data quality experience. You can model relationships across assets, services, software, deployments, and clients, preserve unknown values, and diagnose conflicting or incomplete source data.
CMDB and data platform experience, ideally Jira Assets plus Snowflake, Fabric, or another warehouse. You can design an abstraction that supports today's source of truth and tomorrow's platform without a rewrite.
A builder's mindset with evidence of self-directed work, responsible use of AI to improve engineering quality and speed, concise communication, strong ownership, and the ability to collaborate without ego.
Core Tooling and Technologies
Python · SQL · PostgreSQL / Aurora · AWS Lambda · SQS / DLQ · S3 · ECS / Fargate · Terraform / CloudFormation · FastAPI · REST / GraphQL · Jira Assets · Wiz · Rapid7 / Tenable · Snyk · SARIF · CVE / KEV / EPSS · GitLab CI · Datadog
📌 Infrastructure & Cloud Security Engineer (Bengaluru)
🏢 InvestCloud
📍 Bengaluru