Information Security Engineer

Bureau

Bengaluru

On-site

INR 5,681,818 - 7,575,757

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Flexible PTO
Learning budget

Job summary

Bureau is looking for a Security Engineer in Bengaluru, India, who will manage both technical security and compliance programs. In this role, you will secure cloud infrastructure, manage vulnerability assessments, and enhance the organization's Information Security Management System.

Ideal candidates will have around 4 years of experience in security engineering or compliance roles, a bachelor's degree in a related field, and strong documentation skills. The role offers competitive salary, health benefits, and flexible working arrangements.

Qualifications

  • 4 years of experience in security engineering, cloud security, or GRC/compliance.
  • Understanding of cloud platforms and their security services.
  • Experience with ISO 27001, SOC 2, basic risk management.

Responsibilities

  • Secure AWS/EKS environment and perform vulnerability assessments.
  • Maintain ISMS and support audits including ISO 27001 and SOC 2.
  • Conduct risk assessments and collaborate with other teams for implementation.

Skills

Cloud security
Vulnerability management
Security engineering fundamentals
Strong documentation skills

Education

Bachelor’s degree in Computer Science or related discipline

Tools

AWS
Jira
Confluence

Job description

Why Bureau?

Bureau is a unified risk decisioning platform for Compliance, Fraud, and Transaction risks. Our platform is a single decision-making engine, powered by a 1 billion+ identity knowledge graph. Over 150 Banks, fintechs, retailers, and digital platforms use Bureau to verify identities faster and stop fraud earlier globally.

Bureau has raised $50M+ from renowned Silicon Valley and global investors including Sorenson Capital and PayPal Ventures and is expanding rapidly from APAC to Americas, Europe, and beyond.

About the Role

We are looking for a Security Engineer who can own both the hands‑on technical security stack and our governance/compliance programs.

What you’ll be doing

In this role, you will:

  • Harden and monitor our cloud & container infrastructure (AWS/EKS, endpoints, network).
  • Run vulnerability management, security tooling and incident response.
  • Help maintain our ISMS and support audits (ISO 27001, SOC 2, RBI, DPDP, etc.).

This is ideal for someone who doesn’t want to be only “checklist GRC” or only “pure blue‑team”, but wants a blended role across security engineering + GRC.

Key Responsibilities
1. Cloud & Infrastructure Security (Hands‑on)
  • Work with DevOps to secure our AWS/EKS environment:
  • IAM hardening, security groups, VPC, KMS, S3, RDS, etc.
  • Review infra‑as‑code (Terraform/Helm) for security issues and misconfigurations.
  • Own or co‑own key security tools:
  • Cloud security (CSPM / CNAPP, GuardDuty, Security Hub, WAF, etc.),
  • Container / runtime security where applicable.
  • Implement and maintain logging & monitoring for security events (CloudTrail, ALB/NLB logs, K8s logs, etc.), and integrate them with SIEM / alerting.
2. Vulnerability Management & Security Operations
  • Own the vulnerability management lifecycle:
  • Run periodic scans for cloud, endpoints, containers and apps.
  • Triage findings, prioritise based on risk, and drive closure with engineering.
  • Coordinate external pentests / bug bounties and track remediation.
  • Help investigate alerts, gather evidence, and contribute to RCA and CAPA.
  • Maintain and update incident runbooks.
3. Governance, Risk & Compliance (ISMS, Audits, DPDP)
  • Maintain and enhance the Information Security Management System (ISMS):
  • Policies, procedures, SoA, risk register, control evidence and audit trails.
  • Support internal and external audits: ISO 27001, SOC 2, RBI/CERT‑In, Data Protection.
  • Prepare and manage audit evidence, observations, closure reports and certification documentation.
  • Assist with risk assessments:
  • Maintain the risk register, risk treatment plans and residual risk reviews.
  • Conduct vendor security due diligence and maintain vendor security records (MSA, NDA, DPA, DPIA, etc.).
  • Support privacy & regulatory compliance operations (GDPR/DPDP basics: retention, consent, grievance logging).
4. Access, Asset & Control Assurance
  • Participate in and help automate access reviews, asset inventory checks, and configuration compliance checks.
  • Track control performance (vuln SLAs, access reviews, backup tests, etc.) and ensure gaps are documented and closed.
  • Maintain security awareness and training trackers (onboarding, annual refreshers, phishing simulations).
What You’ll Bring
  • Bachelor’s degree in Computer Science, IT, Cybersecurity or related discipline.
  • ~4 years of experience in security engineering, cloud security, or GRC/compliance (any mix, but must be comfortable hands‑on).
  • Good understanding of:
  • Security engineering fundamentals: Linux, networking, IAM, encryption, least privilege.
  • Cloud platforms (AWS preferred; GCP/Azure a plus) and their security services.
  • Core frameworks: ISO 27001, SOC 2, basic risk management and audit lifecycle.
  • Comfortable with:
  • Writing/debugging basic scripts (Bash/Python) for automation and data extraction.
  • Tools like Jira, Confluence, Excel/Sheets and at least one GRC / security platform (e.g., Scrut/Drata/Secureframe, etc.).
  • Strong documentation skills and ability to talk to both engineers and non‑technical stakeholders.
Preferred (Good to Have) / Willing to Learn
  • Cloud security certifications (e.g., AWS Security / AWS Cloud Practitioner).
  • Experience with:
  • EDR/XDR tools,
  • SIEM, WAF, runtime/container security (Falco, etc.).
  • Exposure to GDPR/DPDP or other data protection regimes.
Who You Are
  • Getting your hands dirty in logs, configs and cloud consoles, and
  • Keeping things clean in policies, risk registers and audit trackers.
  • You’re structured and process‑oriented, but still pragmatic and capable of shipping improvements.
  • You’re comfortable collaborating with DevOps, backend, data, HR and legal to get security actually implemented, not just written down.
  • You want to grow into either Security Engineering leadership (owning tools/architecture) or GRC leadership (owning audits and certifications) over the next few years.
Our Culture
  • We hire self‑motivated people and get out of their way
  • We value performance, not hours worked
  • Speed, ownership, and impact matter most
Compensation
  • Competitive salary + potential equity
  • Health benefits, flexible PTO, learning budget
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer (GRC)
Information Security Engineer (GRC)

Bureau • Bengaluru

On-site
INR 800,000 - 1,500,000
Flexible work hours
Healthcare for you and your family
Opportunities for growth
Senior Data Engineer
Senior Data Engineer

Mosaic.tech • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Health benefits
Flexible PTO
Learning budget
+1
Information Security Engineer (Application Security)
Information Security Engineer (Application Security)

Barracuda • Bengaluru Urban

On-site
INR 1,000,000 - 1,500,000
Internal mobility opportunities
Equity options
Security Architect (Bangalore, India)
Security Architect (Bangalore, India)

AiPrise • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Senior Information Security Engineer
Senior Information Security Engineer

Imagine Learning • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Manager - Technical Support
Manager - Technical Support

Bureau • Bengaluru

On-site
INR 2,000,000 - 4,500,000
Health benefits
Flexible PTO
Learning budget
+1
Senior Security Engineer
Senior Security Engineer

Radius Ois • Khordha

On-site
INR 1,500,000 - 2,500,000
Senior Data Engineer
Senior Data Engineer

Bureau • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Health benefits
Flexible PTO
Learning budget
Information Security Engineer (Application Security)
Information Security Engineer (Application Security)

Barracuda Networks Inc. • Bengaluru

On-site
INR 800,000 - 1,200,000
Equity in the form of non-qualifying options
Internal mobility and cross-training opportunities
Head of Security Engineering
Head of Security Engineering

Brevan Howard • Bengaluru Urban

On-site
INR 1,800,000 - 2,500,000