Lead Security Eng

Keka Inc.

Bengaluru

On-site

INR 4,200,000 - 6,400,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Keka HR in Bengaluru seeks a Lead Security Engineer to own security across cloud infrastructure, applications, and platform engineering. You will mentor a team, drive critical security initiatives, and shape a scalable security program for a fast-growing HRTech SaaS.

You will establish AI security governance, perform threat modeling, manage vulnerabilities, and ensure secure CI/CD practices across AWS, GCP, and multi-tenant environments. This is a high-visibility, hands-on leadership role.

Qualifications

  • 10+ years in Security Engineering, Cloud Security, or Platform Security; 3+ years in a senior/lead role
  • Proven experience building and mentoring security teams in startup or high-growth SaaS environments
  • Strong cloud security across AWS, GCP, or Azure; multi-cloud preferred
  • Experience with security tooling: Nessus, Burp Suite, Qualys, Prisma Cloud, Wiz, CrowdStrike
  • Proficiency in scripting/automation: Python, Bash, or Go
  • Ability to lead incident response and drive security as engineering quality

Responsibilities

  • Own end-to-end security posture across cloud infrastructure, applications, and engineering platforms
  • Define and drive multi-year security roadmap aligned with product and engineering growth
  • Lead AI security governance: acceptible use policies for LLMs and AI tools; mitigate AI-specific threats
  • Lead vulnerability assessment, penetration testing, and remediation with engineering teams
  • Embed security into CI/CD pipelines with SAST, DAST, SCA, and secrets scanning
  • Develop incident response playbooks, runbooks, and post-mortems; tune SIEM and alerts
  • Drive software supply chain security practices and secure-by-default development

Skills

Security leadership
Cloud security
Incident response
Threat modeling
Automation
Python/Bash/Go
CI/CD security

Tools

Nessus
Burp Suite
Qualys
Prisma Cloud
Wiz
CrowdStrike

Job description

Keka HR is one of India's fastest-growing HRTech platforms, trusted by thousands of businesses

across India, the GCC, and the United States. Built with an employee-first approach, Keka helps

organizations manage HR, Payroll, Performance, and Employee Experience — seamlessly, at

scale.

About the Role

This is a high-ownership, high-visibility role for a security engineer who operates both as a strategic

leader and a deeply technical individual contributor. You will lead Keka's security engineering

function — building and mentoring a team of junior engineers while personally driving critical

security initiatives across cloud infrastructure, product, and platform.

The security landscape has changed fundamentally with the rise of AI. We are looking for someone

who doesn't just understand that shift — but actively builds against it. Whether securing AI-powered

product features, defending against AI-augmented attacks, or establishing responsible AI usage

policies within engineering, you'll be defining the playbook.

The ideal candidate sees security not as a gatekeeping function, but as a force multiplier for

engineering velocity and customer trust.

Key Responsibilities
1. Security Leadership & Strategy

keka Lead Security Engineer — Job Description

  • Own end-to-end security posture across cloud infrastructure, applications, and engineering
  • platforms — from strategy to hands-on execution.
  • Define and drive a multi-year security roadmap aligned with Keka's product and engineering
  • growth trajectory.
  • Act as the primary security advisor to Engineering, Platform, and Product leadership;
  • Build, mentor, and grow a team of junior and mid-level security engineers — establishing a
  • culture of security ownership across the entire engineering org.
  • Lead threat modeling, security reviews, and risk assessments across new features and
2. AI-Era Security Practices

keka Lead Security Engineer — Job Description

  • Establish AI security governance: define acceptable use policies for LLMs, Copilot tools, and
  • Identify and mitigate AI-specific threat vectors — prompt injection, model inversion, training
  • Build detection capabilities for AI-augmented attacks: deepfake social engineering, AIgenerated phishing, and automated vulnerability exploitation.
  • Evaluate and red-team AI/ML integrations within Keka's product to uncover data leakage,
  • Insecure inference endpoints, and supply chain risks.
  • Stay current with the evolving threat landscape driven by AI — proactively update controls,
  • playbooks, and team readiness accordingly.
  • Strengthen and continuously improve cloud security architecture across AWS, GCP, and
  • Design and enforce security controls for large-scale distributed systems, multi-tenant SaaS
  • architecture, and high-volume databases.
  • Implement and mature IAM, network segmentation, secrets management, encryption, and
  • zero-trust principles.
  • Harden container and Kubernetes environments; ensure runtime security, image scanning,
  • and cluster access controls.
  • Drive adoption of Infrastructure-as-Code (IaC) security practices with automated policy
4. Vulnerability Management & Incident Response

keka Lead Security Engineer — Job Description

  • Lead end-to-end vulnerability assessment and remediation across applications, APIs,
  • databases, and infrastructure.
  • Coordinate and conduct penetration testing; partner with external vendors and drive
  • remediation with engineering teams.
  • Build and own incident response playbooks, runbooks, and post-mortems — ensuring each
  • incident measurably improves the system.
  • Implement and tune SIEM, logging, and alerting pipelines to reduce MTTD and MTTR across
  • security events.
  • Conduct regular security drills, tabletop exercises, and red team scenarios to build team
  • keka Lead Security Engineer — Job Description
  • Embed security natively into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and
  • container vulnerability checks as first-class gates.
  • Partner with Engineering and DevOps to establish secure-by-default development practices
  • — not security as an afterthought.
  • Build developer-facing security tooling, threat model templates, and secure coding playbooks
  • that scale across squads.
  • Drive adoption of software supply chain security practices (SBOM, dependency auditing, build
  • provenance).
  • Champion security as an engineering quality metric — not just a compliance checkbox.
6. Compliance & Governance

keka Lead Security Engineer — Job Description

  • Lead and support compliance initiatives for SOC2 Type II, ISO 27001, GDPR, and emerging
  • data privacy regulations.
  • Maintain audit readiness; own security documentation, control mappings, and evidence
  • collection.
  • Support enterprise customer security questionnaires, audits, and trust assessments — acting
  • as a credible technical voice.
What We're Looking For
Must Have
  • 10+ years in Security Engineering, Cloud Security, or Platform Security — with at least 3
  • years in a senior/lead role.
  • Proven experience building and mentoring security teams in startup or high-growth SaaS
  • database security, encryption, and secrets management.
  • Strong cloud security experience across AWS, GCP, or Azure — ideally multi-cloud.
  • Experience with security tooling: Nessus, Burp Suite, Qualys, Prisma Cloud, Wiz,
  • CrowdStrike, or equivalents.
  • Proficiency in scripting/automation: Python, Bash, or Go — for building detections,
  • remediations, and security tooling.
  • Ability to operate both as a strategic people leader and a deeply hands-on individual
  • Strong incident response instincts — you've owned P0 security incidents end-to-end.
  • Excellent stakeholder management and ability to translate technical risk into business impact.
Good to Have
  • Hands-on experience with AI/ML security — LLM threat modeling, agentic pipeline security, or adversarial ML.
  • Experience in HRTech, FinTech, or enterprise SaaS with multi-tenancy and PII at scale.
  • Certifications: CISSP, CCSP, CEH, AWS Security Specialty, or Google Cloud Security.
  • Exposure to building scalable security programs from scratch in lean team environments.
  • Experience with Zero Trust architecture implementation.
  • Familiarity with SOC2 Type II, ISO 27001, GDPR compliance frameworks.
Why Join Keka

Scale & Impact — Secure infrastructure powering HR for thousands of companies across India,

GCC, and the US. Your work protects real employee data at scale.

Build, Don't Just Run — Join early enough to shape security culture, tooling, and team from the

ground up — not inherit a legacy compliance checklist.

AI-Native Engineering — Keka is actively embedding AI across its product and engineering

workflows. You'll be at the frontier of AI security — not catching up to it.

Engineering-First Culture — Security here is treated as engineering quality — not an obstacle.

You'll have the trust, access, and influence to get things done right.

Ready to secure one of India's fastest-growing SaaS

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Manager
Engineering Manager

Keka HR • Hyderabad

On-site
INR 2,500,000 - 3,500,000
Real ownership of outcomes
AI tools used daily
People-first culture
Cybersecurity and Digital Trust Analyst
Cybersecurity and Digital Trust Analyst

KEO Group • Bengaluru

On-site
INR 900,000 - 1,500,000
Hybrid working arrangements
Study assistance sponsorship
Employee referral rewards
+1
Cybersecurity Engineer Engineering
Cybersecurity Engineer Engineering

Practice by Numbers • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Lead Software Engineer
Lead Software Engineer

Keka HR • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Product Security/Application Security
Product Security/Application Security

Huntingcube Recruitment Solution • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Lead DevSecOps Engineer
Lead DevSecOps Engineer

GoKwik Commerce Solutions Pvt Ltd • Bengaluru

On-site
INR 7,575,000 - 11,364,000
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Lead DevSecOps Engineer
Lead DevSecOps Engineer

GoKwik • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Sr Security Engineer
Sr Security Engineer

Kobie Marketing • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Lead DevSecOps Engineer
Lead DevSecOps Engineer

GoKwik • Gurugram District

On-site
INR 3,000,000 - 6,000,000