Information Security Architect

Aura Cloud AB

Karnataka

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Aura Cloud AB is seeking an experienced information security leader to own security across the Aura platform, infrastructure, and organization. You will drive certifications, strengthen architecture, and act as the trusted security voice to regulated customers.

Responsibilities include defining security architecture, managing vulnerabilities, overseeing SIEM and monitoring tools, and hands-on AWS security control implementation.

Qualifications

  • 8+ years in information security — architecture, engineering, or hands-on security lead roles.
  • Experience maintaining an ISO 27001 ISMS through certification and surveillance cycles.
  • Working knowledge of DORA or similar financial sector ICT risk frameworks.
  • Hands-on AWS security experience — IAM, VPC, KMS, WAF, GuardDuty, or equivalent.
  • Experience with SIEM tools (Wazuh, Splunk, Sentinel, or similar).
  • Understanding of application security — OWASP Top 10, API security, OAuth/JWT/SAML.
  • Ability to communicate security posture to customer executives, auditors, and regulators.

Responsibilities

  • Define and maintain the platform's security architecture — network segmentation, encryption, access control, API security, and key management.
  • Review and approve infrastructure changes, new integrations, and API exposure decisions.
  • Own the vulnerability management program — dependency scanning, CVE triage, patching, and remediation tracking.
  • Oversee security monitoring tooling (Wazuh SIEM, EWACS, CloudWatch) — detection rules, alert triage, and tuning.
  • Design and implement AWS security controls directly — IAM policies, security groups, KMS key policies, WAF rulesets, GuardDuty tuning.
  • Lead remediation of penetration test and vulnerability assessment findings across infrastructure and application layers, working hands-on with engineering teams to close gaps.
  • Configure and tune SIEM detection rules and alerting logic (Wazuh or equivalent) — build use cases, not just monitor dashboards.
  • Own certificate lifecycle management and encryption implementation (at-rest and in-transit) across environments.
  • Review and harden infrastructure configurations against CIS benchmarks and similar standards.
  • Work with engineering on secure coding practices and help embed security checks into the development pipeline.
  • Maintain and evolve the ISO 27001 ISMS through surveillance audits and continuous improvement.
  • Drive SOC 2 Type II compliance — scope, control implementation, evidence collection, and auditor engagement.
  • Own DORA compliance — ICT risk management, incident classification/reporting, resilience testing, and third-party risk management.
  • Ensure GDPR compliance for platform data processing; work alongside the DPO.
  • Handle customer security questionnaires, due diligence requests, and audit evidence packages.
  • Produce regular security reports for customers and present at governance meetings.
  • Support RFP responses with security content.
  • Own the incident response plan — severity levels, escalation, communication, and post-incident review.
  • Act as incident commander for security-related P1/P2 incidents; deliver RCA within SLA.
  • Commission and manage annual third-party penetration testing.
  • Review and evolve the existing security policy suite to align with ISO 27001, SOC 2, and DORA.
  • Conduct annual security risk assessments and maintain the risk register.
  • Oversee security awareness training and secure coding practices.

Skills

Information security leadership
Security governance
Executive communication

Tools

Wazuh
Splunk
Sentinel
AWS security

Job description

Aura Cloud is a Nordic SaaS core banking platform provider. Our Aura platform powers banks and financial institutions across the Nordics and Baltics — processing deposits, loans, payments, and cards for regulated customers.

The Role

You will own information security across the Aura platform, infrastructure, and organization — from security architecture and compliance certifications to customer-facing security assurance and incident response.

We are ISO 27001 certified and continuously strengthening our compliance posture across SOC 2, DORA, and other regulatory frameworks. We need someone who can drive certifications, strengthen our security architecture, and be the trusted security voice to our regulated customers.

What You Will Own
Security Architecture & Engineering
  • Define and maintain the platform's security architecture — network segmentation, encryption, access control, API security, and key management
  • Review and approve infrastructure changes, new integrations, and API exposure decisions
  • Own the vulnerability management program — dependency scanning, CVE triage, patching, and remediation tracking
  • Oversee security monitoring tooling (Wazuh SIEM, EWACS, CloudWatch) — detection rules, alert triage, and tuning
Hands-On Security Engineering
  • Design and implement AWS security controls directly — IAM policies, security groups, KMS key policies, WAF rulesets, GuardDuty tuning
  • Lead remediation of penetration test and vulnerability assessment findings across infrastructure and application layers, working hands-on with engineering teams to close gaps
  • Configure and tune SIEM detection rules and alerting logic (Wazuh or equivalent) — build use cases, not just monitor dashboards
  • Own certificate lifecycle management and encryption implementation (at-rest and in-transit) across environments
  • Review and harden infrastructure configurations against CIS benchmarks and similar standards
  • Work with engineering on secure coding practices and help embed security checks into the development pipeline
Compliance & Certifications
  • Maintain and evolve the existing ISO 27001 ISMS through annual surveillance audits and continuous improvement
  • Drive SOC 2 Type II compliance — scope, control implementation, evidence collection, and auditor engagement
  • Own DORA compliance — ICT risk management, incident classification/reporting, resilience testing, and third-party risk management
  • Ensure GDPR compliance for platform data processing; work alongside the DPO
Customer Security Assurance
  • Handle customer security questionnaires, due diligence requests, and audit evidence packages
  • Produce regular security reports for customers and present at governance meetings
  • Support RFP responses with security content
  • Own the incident response plan — severity levels, escalation, communication, and post-incident review
  • Act as incident commander for security-related P1/P2 incidents; deliver RCA within SLA
  • Commission and manage annual third-party penetration testing
Policy & Governance
  • Review and evolve the existing security policy suite to align with ISO 27001, SOC 2, and DORA
  • Conduct annual security risk assessments and maintain the risk register
  • Oversee security awareness training and secure coding practices
What We Are Looking For
Must Have
  • 8+ years in information security — architecture, engineering, or hands-on security lead roles
  • Experience maintaining an ISO 27001 ISMS through certification and surveillance cycles
  • Working knowledge of DORA or similar financial sector ICT risk frameworks
  • Hands-on AWS security experience — IAM, VPC, KMS, WAF, GuardDuty, or equivalent
  • Experience with SIEM tools (Wazuh, Splunk, Sentinel, or similar)
  • Understanding of application security — OWASP Top 10, API security, OAuth/JWT/SAML
  • Ability to communicate security posture to customer executives, auditors, and regulators
Nice to Have
  • Experience with SOC 2 Type II audits
  • Background in SaaS companies serving regulated financial institutions
  • Certifications: CISSP, CISM, ISO 27001 Lead Auditor, AWS Security Specialty
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Radius Ois • Khordha

On-site
INR 1,500,000 - 2,500,000
Information Security
Information Security

Aspora • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Cloud Security Engineer
Cloud Security Engineer

Portway Solutions India Private Limited • Dadri

On-site
INR 1,500,000 - 2,100,000
Cloud Security Consultant
Cloud Security Consultant

Payatu BV • Gurugram District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Cloud Security Architect
Cloud Security Architect

Liminal Custody • Bengaluru

On-site
INR 2,000,000 - 3,000,000
. Security Engineer — Security Operations
. Security Engineer — Security Operations

Aistra • Pune District

On-site
INR 3,000,000 - 4,200,000
Security Architect
Security Architect

Tech Mahindra • Bengaluru

On-site
INR 4,000,000 - 7,000,000
IT Security Team Lead
IT Security Team Lead

Creative Capsule • Goa

On-site
INR 2,500,000 - 4,500,000
Security Architect
Security Architect

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,000,000
Senior Information Security Engineer (DevSecOps)
Senior Information Security Engineer (DevSecOps)

WLEN WorldJobs LLP • Bengaluru

On-site
INR 2,500,000 - 5,000,000