Head of Information Security

Aurigo Software Technologies

Bengaluru

Hybrid

INR 6,000,000 - 9,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equal Opportunity Employer

Job summary

Aurigo Software Technologies is seeking a senior security leader to own the build and run of a multi-geo security program across AI-native SaaS products.

You will manage vulnerability operations, identity and endpoint security, cloud security, and data protection at scale, with governance across FedRAMP, GovRAMP, and other standards. This role reports to the CIO and is based in Bengaluru with hybrid work.

Qualifications

  • 14+ years in information and cyber security with leadership experience.
  • Experience running vulnerability management at scale with SLAs and risk-based prioritization.
  • Governing machine and non-human identity, and practical AI/LLM security risk management.
  • Hands-on depth in at least four: IAM, EDR/detection engineering, cloud security (AWS/Azure), app security, CASB or SSO/EOF security, data protection.
  • Experience operating within FedRAMP, GovRAMP, DoD IL4/IL5, PCI DSS or HITRUST regimes.

Responsibilities

  • Own vulnerability management across code, containers, cloud, and endpoints across environments.
  • Lead security governance for AI initiatives, with agent registry, least privilege, and review.
  • Oversee identity security across human and non-human identities with lifecycle management.
  • Manage product security posture for cloud and data, including threat modelling, SAST/DAST, and data loss prevention.
  • Serve as Incident Commander for major security incidents and coordinate with leadership and customers.

Skills

Security leadership
Vulnerability management
AI/LLM security
Identity & access management
Endpoint security
Cloud security
Data protection

Tools

FedRAMP
GovRAMP
DoD IL4/IL5
PCI DSS
HITRUST

Job description

Aurigo is an AI-native capital program management platform trusted by over 300 customers managing more than $450 billion in capital programs across North America. With over 40,000 projects delivered, Aurigo helps organisations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence. Recognised as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes. At Aurigo, we don't just build software — we help shape the future of infrastructure.

Work Mode

Hybrid

About the Role

You report to the Chief Information & Security Officer (CI&SO), and you own the build and run of our security program company wide.

Aurigo builds mission critical AI native SaaS for capital infrastructure and government. Masterworks, Primus, Essentials and our AI product Lumina are trusted with highly regulated public sector and private sector data across four geographies. We hold SOC 1 and SOC 2 Type II, FedRAMP, GovRAMP and ISO 22301, with ISO 42001 close behind. Bangalore is a Global Capability Centre where global functions are owned and held accountable, and this role is one of them.

Aurigo runs a mature, advanced defense in depth posture. This role takes it further: operating it with greater precision, governing an identity and agent population growing faster than any human one, and using AI to defend at the speed our adversaries now attack.

Key Responsibilities
Vulnerability operations
  • Own vulnerability management as one operational discipline across product code, dependencies, containers, cloud, endpoints and SaaS. One view, one queue, one owner, with remediation driven through engineering rather than tickets handed across a wall.
  • Prioritize on real risk rather than raw CVSS: exploitability, reachability in our code paths, asset criticality and threat intelligence. Hold published SLAs by severity and measure recurrence as well as closure.
  • Own the technical execution of continuous monitoring under FedRAMP and GovRAMP: authenticated scanning, POA&M delivery, deviation requests and significant change security review.
AI and agent security governance
  • Own security governance for AI company wide: an enterprise LLM assistant for all staff, a low code automation platform, and team built agents. Mandatory agent registry and security intake, every agent carrying a named owner, risk tier and approved scope. Nothing reaches production unreviewed.
  • Treat agents as first class identities: least privilege credentials under privileged access management, full audit trail, tested kill switches, human in the loop on privileged actions. Vet third party AI services for data residency, sub processors and training data handling.
  • Extend adversarial AI testing across the portfolio for prompt injection, data exfiltration and agent abuse, aligned to the OWASP Top 10 for LLMs, MITRE ATLAS, ISO 42001 and the NIST AI RMF. Put AI to work on defense too, through agentic triage and automated evidence collection, so the function scales on output per engineer rather than headcount.
Identity, endpoint and threat defense
  • Own identity security across both populations, with non human identity the larger and faster growing: service accounts, machine identities, keys, tokens, certificates, workload identities and agents, each with a named human owner, vaulted and automatically rotated credentials, and least privilege scope enforced through the full lifecycle including deprovisioning.
  • Own identity threat detection and response, phishing resistant multi factor authentication, endpoint security across a mixed Windows and macOS fleet, detection engineering and the virtual SOC partnership, measured on coverage mapped to ATT&CK and on response time rather than ticket volume.
Product security, cloud and data
  • Own product security across Masterworks, Primus, Essentials and Lumina, supporting roughly 250 engineers: threat modelling, SAST, DAST and SCA gated in CI, secrets scanning, SBOM, code signing, guardrails on AI coding assistants, penetration test and bug bounty remediation as a tracked programme, and a security champions model so security moves at the pace of engineering.
  • Own runtime cloud posture across AWS and Azure, SaaS posture across the corporate estate, and data security engineering: classification, data loss prevention, encryption and key management, control over how regulated data moves into and out of AI systems, and the engineering controls behind India's DPDP Act and US state privacy obligations.
Incident response, platform and team
  • Serve as Incident Commander for Sev1. Own the severity model, escalation, on call structure and forensics retainer, our ability to meet the FedRAMP one hour window, the CERT-In six hour directive and customer contractual clocks, and an exercise program of tabletops across all four geographies plus a full scope live test each year.
  • Lead consolidation onto fewer platforms and own vendor strategy and commercial negotiation. Lead and grow the security engineering organization covering SOC, detection, application security, cloud and offensive testing, with funded headcount growth. Report posture, risk and roadmap to the CI&SO and the executive leadership team, with defined escalation to the Audit Committee.
Certifications: where your accountability sits

GRC owns the certification. You own the controls it rests on.

GRC owns authorization packages, the System Security Plan, 3PAO and agency relationships, the audit calendar, policy, privacy and third party risk. You own what every certification rests on: that technical controls are implemented, effective, continuously monitored and evidenced as a byproduct of how we operate. If a certification is ever at risk because a control failed or evidence was missing, that is yours. If it is because a policy or authorization artefact was wrong, that is GRC’s.

Candidate Profile
Required
  • 14+ years in information and cyber security, including 6+ years leading security teams and at least 2 leading managers or principal level engineers. You have owned security for a SaaS product company at scale, building and running it rather than only governing it.
  • You have run vulnerability management as an operational discipline at scale, with published SLAs, risk based prioritisation and remediation delivered through engineering. You can talk about ageing curves and recurrence rates from memory.
  • Direct experience governing machine and non-human identity, and practical command of AI and LLM security risk with real experience applying AI to security operations rather than only defending against it.
  • Hands on depth in at least four of: identity and privileged access; endpoint detection and response and detection engineering; cloud security across AWS and Azure; application and product security; secure access service edge and CASB; data protection. You have operated inside a live authorization regime such as FedRAMP, GovRAMP, DoD IL4 or IL5, PCI DSS or HITRUST.
  • You have been incident commander for a material security incident, including the executive and customer communication that came with it. You can brief a board or audit committee and hold a technical argument with a staff engineer on the same day, and you have led a global function from an India GCC with genuine accountability rather than delivery support.
Preferred
  • Security leadership for SaaS in government or otherwise regulated markets. CISSP, CISM, CCSP or senior cloud provider credentials. Experience building agentic security workflows. Vendor consolidation and negotiation at seven figure scale.

Aurigo Software Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable law

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Information Security
Head of Information Security

Aurigo Software Technologies Inc. • Bengaluru

On-site
INR 4,000,000 - 8,000,000
AI Security Engineer
AI Security Engineer

Aurigo Software Technologies • Bengaluru Urban

On-site
INR 2,500,000 - 3,800,000
Manager - IT Infrastructure & Operations
Manager - IT Infrastructure & Operations

Aurigo Software Technologies Inc. • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Software Engineer II
Software Engineer II

Aurigo Software Technologies • Bengaluru

On-site
INR 1,600,000 - 2,600,000
Information Security Manager
Information Security Manager

Mondee • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Information Security Architect
Information Security Architect

Aura Cloud AB • Karnataka

On-site
INR 1,200,000 - 1,800,000
Principal Security Engineer, AI Security & SecOps
Principal Security Engineer, AI Security & SecOps

Uniphore Software Systems Private Limited • Bengaluru

On-site
INR 1,800,000 - 2,500,000
Diversity and equal opportunity workplace
Principal Security Engineer, AI Security & SecOps
Principal Security Engineer, AI Security & SecOps

Uniphore • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Director - Engineering
Director - Engineering

Aurigo Software Technologies Inc. • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Director, Security Engineering (Application & Cloud Security)
Director, Security Engineering (Application & Cloud Security)

Uniphore • Bengaluru

Hybrid
INR 3,500,000 - 5,500,000