05 Oct
|
Catalysts
|
Bengaluru
05 Oct
Catalysts
Bengaluru
About the roleNodGuard is a consent and data-protection platform built for India's Digital Personal Data Protection Act (DPDP). Catalysts is the company behind it. We are hiring a Security Engineer to set up security from the ground up and own it across both: the NodGuard platform on AWS, the DPDP breach and security features inside the product, and Catalysts' own systems and people.
You will be our first dedicated security person, so we are looking for someone who enjoys taking ownership, likes building things from scratch, and wants to grow with the company.
What you will own• Platform security. Harden NodGuard's AWS estate: IAM, network, encryption, key management, logging and alerting. Protect the data stores and keep every client's data isolated from every other's.
- Secure releases. Put security gates into the build pipeline (dependency, secret and code scanning) so a risky change cannot ship.
- DPDP breach features. Design how NodGuard detects, records and notifies personal-data breaches within the law's timelines, with tamper-evident evidence. Review every new feature for security before it ships.
- Incident response. Be the incident commander. Write the plan, rehearse it, run it when needed, and write the report after.
- Company security. SSO and MFA everywhere, device encryption and patching, same-day offboarding, plain-language policies, and security training for the team.
- Compliance. Map our controls to DPDP, the DPDP Rules and CERT-In directions. Drive NodGuard towards ISO 27001 and SOC 2. Answer client security questionnaires.
- Ownership. Keep the security roadmap, report monthly on what is protected and what is not, and help developers build security into their everyday work.
What you bring• 4+ years in security, with real hands-on time in cloud security (AWS preferred) and application security.
- You have hardened a production cloud setting yourself:
IAM policies, VPCs, KMS, CloudTrail, GuardDuty, WAF.
- You have found and fixed OWASP Top 10 issues, threat-modelled features, and set up scanning in a CI/CD pipeline. You can read TypeScript or Node.js well enough to review a pull request.
- You have handled at least one real security incident end to end.
- You know the DPDP Act and Rules: breach notification, the Data Protection Board, Consent Managers. You know CERT-In's six-hour incident reporting rule.
- You have worked against ISO 27001 or SOC 2 controls, ideally through an audit.
- You have set up SSO, MFA, device management and access reviews for a team.
- You write clearly. Your policies and runbooks are followed by people who are not security experts.
- You want ownership. You have worked somewhere small enough that you had to set things up from nothing.
Good to have: experience with consent, ad-tech or martech platforms; mobile SDK and browser security; policy-as-code (OPA); ClickHouse or DynamoDB; SIEM and detection rules; answering enterprise security questionnaires in India.
CertificationsNo certification is mandatory. Please list any security, cloud or privacy certifications you have completed (for example AWS Security Specialty, CEH, OSCP, CISSP, CCSP, CIPP/E, ISO 27001) in your application; they count in your favour.
Details• Title: Security Engineer
- Companies: NodGuard and Catalysts
- Reports to: Founder
- Location: On-site at the Catalysts office, full time in the office; this is not a remote or hybrid role. Occasional travel to client sites.
- Type: Full time
- Team: You are the first dedicated security hire and will work closely with the engineering team
You are joining early, which means real influence: the security practices you set up now become how the company works. You will have the founder's backing, a supportive engineering team, and room to grow into a leadership role as the team expands.
📌 Security Engineer (Bengaluru)
🏢 Catalysts
📍 Bengaluru