14 Sep
|
Arcana
|
Bengaluru
Job Description
Principal Security Engineer
n
Location: Bangalore (Hybrid)
n
As our Principal Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden infrastructure end-to-end. While your primary focus will be on our GCP resources, you'll also partner with teams across networking, applications, and compliance to ensure we're secure by design and resistant to drift.
n
Responsibilities:
n
n
- Enterprise Security Architecture - Governance and Compliance, including driving adherence to ISO 27001, SOC 2, GDPR, and enforcing CIS benchmarks on all infrastructure.
n
- Policy, Automation, and Guardrails - own the end-to-end security lifecycle by defining policy-as-code, embedding continuous compliance checks into CI/CD, and building automated, drift-resistant guardrails across cloud, containers, and VMs.
n
- Infrastructure Hardening and Drift Detection - implement automated drift alerts and self-healing playbooks for VPCs, firewall rules, Kubernetes clusters, and endpoints.
n
- Monitoring, Logging, and Incident Response - configure Cloud Audit Logs, SIEM exports, and custom alerts for critical security events; lead root-cause investigations,
build detection logic, and develop runbooks for cloud-wide incidents.
n
- Define security checkpoints for new products and features
n
n
Requirements:
n
n
- 8+ years driving security and compliance in dynamic, regulated environments- securing cloud-native platforms and hybrid infrastructures, with deep familiarity in fintech and portfolio-management standards, and best practices for supporting distributed, remote teams.
n
- Deep expertise with GCP security (IAM, KMS, VPC Service Controls, Cloud Logging/Audit, WAF, SecOps) and Kubernetes application hardening.
n
- Strong Infrastructure-as-Code skills (Terraform or equivalent) and GitOps experience (ArgoCD, Flux).
n
- Proficiency in Appsec and Secops tools.
n
- Proficiency in Python scripting and policy-as-code frameworks (OPA, Gatekeeper).
n
- Excellent communicator - able to translate technical findings into explicit policies and remediation plans.
n
n
Helpful Experience:
n
n
- Familiarity with multi-cloud security controls.
n
- Security certifications (GCP Professional Security Engineer, CISSP, CKA/CKS).
n
- Experience with service mesh (Istio/Anthos) or zero-trust architectures.
n
📌 Principal Security Engineer (Bengaluru)
🏢 Arcana
📍 Bengaluru