11 Sep
|
bolttech
|
India
About us bolttech is an international insurtech with a mission to build the world’s leading, technology-enabled ecosystem for protection and insurance. With a full suite of digital and data-driven capabilities, bolttech powers connections between insurers, distributors, and customers to make it easier and more efficient to buy and sell insurance and protection products.
A part of Pacific Century Group, bolttech serves customers in multiple markets across North America, Asia and Europe.
In this position you will…
Oversee bolttech’s security engineering program - vulnerability management, workspace and endpoint security, security architecture, and cloud security - leading the managers and specialist teams who deliver each domain and setting the technical direction across them. You will also hold ultimate accountability for application and product security, delivered through the domain experts you oversee. Operating in the APAC time zone, you will serve as a senior security partner to regional top management and represent the CISO in regional engagements when the CISO is unavailable.
You will be responsible for…
- Overseeing the security engineering program - vulnerability management, workspace and endpoint security, security architecture, and cloud security - leading the managers and teams who run each domain and setting the technical direction and delivery standards that align with business objectives and regulatory requirements.
- Driving the design, implementation, and continuous improvement of security controls for AWS, GCP, Azure and M365 environments.
- Overseeing vulnerability management programs, including asset coverage, prioritization, remediation tracking, and reporting risk posture to senior stakeholders.
- Defining and maintaining security architecture — reference architectures, security design standards, and architecture review and threat-modeling processes across the technology estate.
- Managing the health, performance, and integration of security operations tooling, to ensure effective detection and response.
- Holding overall accountability for application security and product security, providing direction and support to the specialist leads who run these functions day to day.
- Championing the responsible adoption of AI across the security engineering function - using AI tooling to accelerate detection, vulnerability triage, and automation - while ensuring AI and GenAI systems adopted across the business are deployed securely and governed appropriately.
- Acting as a senior security partner to top management across the APAC time zone,
and representing the CISO in regional forums and escalations during periods when the CISO is unavailable.
- Building and maintaining robust relationships with business and technology leaders to influence security decisions and promote a culture of security-first thinking.
- Coordinating readiness for audits and certifications (ISO 27001, SOC 2, PCI DSS), ensuring evidence and controls meet compliance requirements.
- Developing and mentoring team members, setting clear objectives, and fostering a culture of accountability, innovation, and continuous improvement.
For you to be successful…
- You are passionate about cybersecurity and thrive on building secure, resilient systems that enable business growth.
- You are a strategic thinker who can balance technical depth with business priorities, making risk-based decisions that go beyond checkbox compliance.
- You bring strong technical depth across vulnerability management, endpoint, cloud, and security architecture - enough to direct, challenge, and earn the respect of the managers and specialists running each area, without needing to do the work yourself.
- You can set direction and hold accountability for specialist domains - such as application and product security - that are run by embedded experts, while staying close to the engineering areas you oversee.
- You embrace AI as part of how you and your teams work, using AI tools to raise engineering productivity and quality, and you stay current on how AI reshapes both the threat landscape and our defenses.
- You have strong leadership skills and enjoy developing high-performing teams, fostering collaboration, and influencing stakeholders at all levels.
- You are confident communicating complex security concepts in simple, actionable terms to both technical and non-technical audiences, and able to represent the security function credibly with senior leadership.
- You are proactive, detail-oriented, and comfortable working across global teams, cultures, and time zones, ensuring alignment and execution in a fast-paced environment.
- You can translate security requirements into scalable, practical solutions that support innovation and operational efficiency.
- You stay ahead of emerging threats, technologies, and regulatory trends, and you bring that knowledge to shape strategy and drive continuous improvement.
You will require the following qualifications and skills
- At least 10 years of experience in cybersecurity, with 3+ years in leadership roles managing security engineering or SecOps teams.
- Proven, in-depth expertise across vulnerability management, endpoint security, cloud security (AWS, Azure, GCP), and corporate security platforms such as Microsoft 365.
- Hands-on experience with security operations tooling, such as vulnerability management solutions (e.g., Qualys, Tenable, Rapid7).
- Strong experience defining security architecture and reference standards at enterprise scale.
- Familiarity with application security and product security practices, with the ability to oversee and hold accountability for the specialist teams that run them.
- Practical experience using AI and GenAI tools in day-to-day work, with sound judgment on where they add value and where they introduce risk.
- Familiarity with securing AI and machine-learning systems - model and data risks, secure deployment, and emerging AI governance and regulatory expectations (e.g., the EU AI Act, NIST AI RMF) - is highly desirable.
- Familiarity with compliance frameworks such as ISO 27001, SOC 2, and PCI DSS, and experience preparing for audits and certifications.
- Awareness of the APAC regulatory landscape, including data protection and financial services considerations, sufficient to engage regional stakeholders and management.
- Excellent analytical, troubleshooting, and problem-solving skills, with a focus on measurable outcomes and KPIs.
- Exceptional communication and stakeholder management skills, with the ability to influence executives and collaborate across global teams.
- Degree in Computer Science, Information Security, or related field; advanced security certifications such as CISSP, CISM, CCSP, or cloud security certifications are highly desirable.
Diversity and Inclusion
At bolttech, we are diverse and inclusive. We value each person's unique skills, background, and identity. We never discriminate on cultural background, religion, sex, gender, gender identity or expression, sexual orientation, age, disability, veteran status, genetic information, marital or family status or any legally protected status. Everyone belongs. And because everyone’s different, we’re also flexible in the ways we work, so each person can bring their best efforts every day.
📌 Senior Manager, Security Engineering & Architecture (India)
🏢 bolttech
📍 India