27 Sep
|
Economic Impact Catalyst
|
Bengaluru
27 Sep
Economic Impact Catalyst
Bengaluru
Economic Impact Catalyst (EIC) is the #1 SaaS platform for building and scaling economic development efforts. Our software helps organizations drive economic growth through data-driven decisions and strategic interventions serving 100+ economic development agencies and thousands of entrepreneurs across the US. We are a 35-person team distributed across the US, Philippines, India, and Mexico, currently undergoing a critical platform transformation.
The Role
We are looking for an experienced IS/IT Security Engineer with 3+ years of cybersecurity experience to strengthen and continuously improve EIC's multi-tenant SaaS security posture. This is not a role where the work is handed to you you will be expected to identify what needs to be done, build the systems and controls to do it, and follow through with minimal oversight. You will help protect our data, applications, cloud infrastructure, and business systems by improving security controls, reviewing risk, supporting security technologies, and leading incident investigation and response.
This role is available in a hybrid or fully remote arrangement for candidates based in India or Mexico.
What You'll Do
- Identify threats and vulnerabilities, conduct complex security investigations, and lead incident response, containment, recovery, and follow-up activities.
- Architect, design, and implement security technologies and processes in partnership with engineering, infrastructure, application, and business owners.
- Manage, administer, monitor, and support multiple security applications; troubleshoot issues and automate operational workflows to reduce risk and improve response time.
- Measure and report on enterprise security capabilities using automated and manual tools, with clear metrics for risk, coverage, and remediation progress.
- Develop and maintain security policies, standards, procedures, runbooks, roadmaps, and business cases, and communicate them clearly to technical and business partners.
- Review new and existing systems before and after implementation to confirm security requirements and complete risk, architecture, and impact assessments.
- Develop, maintain, audit, and enhance security controls across endpoints, servers, networks, databases, cloud services, applications, identities, and data.
- Support security awareness, audits, assessments, compliance requests, and remediation activities aligned with EIC's security and governance requirements.
- Deliver security projects, mentor and cross-train team members, maintain technical documentation, and strengthen tenant isolation and secure-by-default controls across the multi-tenant SaaS platform.
What We're Looking For How You Work The skills and certifications below matter but what determines success in this role is how you approach the work, especially when the path forward isn't clearly defined.
We're looking for someone who:
- Investigates without being pointed. You notice gaps, follow threads, and keep digging until you understand a problem not because someone assigned it, but because incomplete information bothers you. This shows up every day in threat identification, vulnerability review, and incident response.
- Builds to last. You don't just fix the immediate problem you document what you found,
automate what can be repeated, and hand off work in a way that doesn't require you to be in the room. Runbooks, roadmaps, and operational handoff aren't administrative overhead to you; they're part of doing the job well.
- Moves without waiting. In a remote, distributed environment, you manage your own priorities, identify what needs attention next, and make progress without needing constant direction. During your first 90 days and beyond, you'll be expected to orient yourself, ask good questions, and get to work not wait for a detailed plan.
- Translates risk for the room. You communicate clearly with engineers, business owners, and leadership and you adjust how you explain things based on who's listening. You help people understand what's at stake without creating unnecessary alarm or friction.
- Shares what you know. You cross-train teammates, write documentation others can actually use, and treat security as a shared organizational responsibility — not a gate you control.
Experience and Technical Skills
- 3+ years of mid-level cybersecurity experience as a security analyst, security engineer, systems engineer, or in a similar technical security role.
- Bachelor's degree or equivalent experience in Cybersecurity, Computer Science, Information Technology, or another relevant technical discipline.
- An advanced, professional, or expert-level security certification is preferred.
- Hands-on experience leading, supporting, administering, or managing at least one enterprise security application or platform.
- Experience leading security projects and initiatives from planning through implementation, operational handoff, and continuous improvement.
- In-depth knowledge of information security principles and advanced security incident investigation techniques, with a practical understanding of threats and risk.
- Working knowledge of network, application, endpoint, cloud, identity, and systems security architecture.
- Experience documenting, designing, and implementing desktop, server, network, database, cloud, and application security controls.
- Strong troubleshooting, automation, leadership, project management, organization, customer service, and written communication skills.
Security Platforms and Domain Knowledge
- Experience securing multi-tenant SaaS platforms, including tenant isolation, role-based access control, secure configuration, data protection, threat detection, vulnerability remediation, incident response, and security operations.
- Hands-on experience with security tools such as email security, data loss prevention, IDS/IPS, SIEM, EDR/XDR, anti-malware, proxy, identity security, and vulnerability management platforms.
- Experience with security orchestration, automation, and response, cloud security posture management, and cloud-native application protection platforms.
- Experience improving cloud security, data protection, DLP, SIEM, SOAR, and related security capabilities in an AWS-based multi-tenant SaaS environment.
- Working knowledge of NIST and SOC 2 security and compliance frameworks, including supporting audits, assessments, evidence collection, and remediation activities.
Our Values in Action Our values aren't aspirational — they describe how the work actually gets done here.
- Curiosity means you stay genuinely interested in the domain. You follow security developments because the space interests you, not because someone told you to stay current. When you encounter an unfamiliar threat, system, or architecture, you investigate before you conclude. You ask questions that get to the root of a problem, and you share what you learn with the people around you.
- Ownership means you see things through. You take responsibility for security technologies and controls from design to implementation to ongoing monitoring — including the documentation, automation, and handoff work that makes your contributions durable. When an incident happens, you stay calm, communicate clearly, drive toward resolution, and follow up to make sure the underlying issue is addressed — not just contained.
- Empathy means you design and communicate with other people in mind. Security processes that create unnecessary friction get ignored; you know this, and you build accordingly. You explain risk in terms that help engineers and business owners make better decisions — not in terms that demonstrate how much you know. You mentor teammates in a way that builds capability, not dependence.
What We Offer
Professional Growth
- Hands-on experience building and owning a security function across cloud infrastructure, application security, compliance, and incident response.
- Direct collaboration with Engineering, Product, and business leadership on security architecture, risk decisions, and platform controls.
- Deep exposure to multi-tenant SaaS security, SOC 2 compliance, and AWS environments — experience that maps directly to certifications like CISSP, CISM, and AWS Security Specialty.
- Room to grow into senior security leadership, GRC, DevSecOps, or product security roles as EIC scales.
Work Environment
- Fully distributed team with flexible working arrangements.
- Collaborative, detail-oriented culture that values follow-through and clear communication.
- Supportive workplace where questions and learning are encouraged.
Impact
- Help entrepreneurs and economic developers get unstuck so they can focus on building their businesses and communities.
- See the direct results of your troubleshooting and documentation in smoother client experiences across dozens of states.
Compensation & Benefits
- Competitive salary and benefits package based on overall experience.
- Opportunities for professional growth, learning, and certification development.
Ready to Build Something That Matters If you're the kind of security engineer who notices what's missing before being asked, builds systems that outlast your own attention, and finds the work itself genuinely interesting — we'd like to hear from you.
Let's build something meaningful together!
📌 Security Engineer (Bengaluru)
🏢 Economic Impact Catalyst
📍 Bengaluru