Security Compliance Engineer

Infrrd Inc.

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Flexible work options
Career growth opportunities

Job summary

Infrrd Inc. in Bengaluru is seeking a Security Compliance Engineer responsible for overseeing information security from governance to technical implementation. You'll collaborate with various teams to enhance security posture while ensuring compliance with standards such as ISO 27001 and GDPR.

The ideal candidate has substantial experience in Information Security, particularly in cloud environments like AWS. Join Infrrd to be part of a transformative AI company with competitive compensation and a culture of learning.

Qualifications

  • 6–12 years of experience in Information Security, with a balance of GRC and hands-on security.
  • Experience implementing security controls in AWS environments.
  • Practical experience securing databases and APIs.

Responsibilities

  • Design and harden AWS security controls.
  • Manage compliance initiatives and audits.
  • Develop and improve security policies.

Skills

Information Security
Governance, Risk & Compliance
AWS security controls
Database security
API security
Risk assessments
Vulnerability management
Stakeholder management
Analytical skills
Communication skills

Education

Bachelor’s degree in information security or related field

Tools

AWS
SIEM/log monitoring tools
Encryption/KMS
Vulnerability scanning tools

Job description

Hello there! Infrrd here. Infrrd is a leading AI-powered Intelligent Document Processing (IDP) company that helps enterprises automate complex document-centric processes using proprietary machine learning and computer vision models. Our platform enables global enterprises to unlock valuable insights from unstructured data at scale, driving efficiency, compliance, and better decision‑making.

We are currently looking for a Security Compliance Engineer to own information security end‑to‑end: governance/compliance (ISO 27001, SOC 2, GDPR, HIPAA, mortgage‑industry data protection) and hands‑on technical implementation (hardening AWS infrastructure, databases, application APIs). You will work with Engineering, IT, Product, Legal, and Customer Success to strengthen our security posture, drive compliance initiatives, and support customers with their security and governance requirements.

Key Responsibilities
Hands‑On Technical Security Implementation
  • Design, configure, and harden AWS security controls: IAM least‑privilege policies, VPC/network segmentation, security groups, KMS encryption, Guard Duty, Security Hub, CloudTrail, AWS Config, WAF, and Secrets Manager.
  • Assess and remediate database security across our environments (RDS/PostgreSQL, MongoDB, DynamoDB): encryption at rest and in transit, least‑privilege access, credential rotation, audit logging, and backup/DR testing.
  • Review and harden application API security: authentication/authorization (OAuth2/JWT), input validation, rate limiting, API gateway configuration, and remediation of OWASP API Security Top 10 risks.
  • Partner directly with Engineering on architecture and code‑level security reviews, not just governance sign‑off.
  • Own the vulnerability management and penetration testing program: schedule scans/tests, triage findings, and personally verify that fixes are correctly implemented.
  • Evaluate and roll out security tooling as needed (SIEM/log monitoring, cloud security posture management, IaC scanning such as Checkov/tfsec, SAST/DAST).
Governance, Risk & Compliance
  • Lead and manage compliance initiatives across ISO 27001, SOC 2, GDPR, HIPAA, GLBA, and other applicable frameworks, including those specific to mortgage/financial‑services customers.
  • Own and coordinate internal and external security audits, certification processes, and compliance assessments.
  • Develop, maintain, and continuously improve security policies, procedures, and documentation and verify they are actually being followed, not just published.
  • Conduct periodic risk assessments and drive remediation to closure with the owning teams.
  • Manage customer security questionnaires, due diligence requests, and compliance documentation during sales and customer onboarding.
  • Monitor adherence to internal security policies and recommend improvements to the organization’s security posture.
  • Collaborate with vendors and third parties to perform security and compliance assessments.
  • Stay current on evolving cybersecurity regulations, compliance requirements, and industry best practices.
  • Drive security awareness initiatives and promote a culture of security across the organization.
Qualifications
  • 6–12 years of experience in Information Security, spanning both Governance, Risk & Compliance (GRC) and hands‑on security engineering. Candidates with compliance/audit experience only will not be a fit for this role.
  • Demonstrable, hands‑on experience personally implementing and configuring security controls in a cloud environment (AWS strongly preferred): IAM, network security, encryption/KMS, logging and monitoring.
  • Practical experience securing databases and APIs in a production SaaS environment.
  • Strong understanding of security frameworks such as ISO 27001, SOC 2, NIST, GDPR, HIPAA, and mortgage/financial‑services compliance requirements (GLBA).
  • Experience managing security audits, compliance programs, and risk assessments.
  • Familiarity with vulnerability scanning and penetration testing, either hands‑on or in direct coordination with testers, including remediation verification.
  • Excellent communication and stakeholder management skills, able to work across technical and business teams.
  • Strong analytical, documentation, and project management skills.
  • Bachelor’s degree in information security, Computer Science, Information Technology, Engineering, or a related field.
  • Certifications that signal hands‑on capability are a strong plus: AWS Certified Security – Specialty, OSCP, CCSP, in addition to governance certifications such as CISSP, CISA, CISM, CRISC, or ISO 27001 Lead Auditor/Lead Implementer.
Why Join Infrrd
  • Be part of a fast‑growing AI company that is transforming how global enterprises extract value from documents.
  • Own security end‑to‑end: policy and implementation, rather than just one half of the job.
  • Work alongside passionate engineers, AI experts, and business leaders to solve complex security and compliance challenges.
  • Enjoy a culture of ownership, transparency, and continuous learning.
  • Competitive compensation, flexible work options, and opportunities for career growth.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security & Compliance Lead
Information Security & Compliance Lead

Infra360 Solutions Pvt. Ltd. • Haryana

On-site
INR 1,000,000 - 1,500,000
Security Engineer (Bangalore, India)
Security Engineer (Bangalore, India)

AiPrise • Karnataka

On-site
INR 1,800,000 - 4,000,000
Equity upside
YC-backed startup
In-person collaboration in San Jose
Security Architect (Bangalore, India)
Security Architect (Bangalore, India)

AiPrise • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Information Security Engineer
Information Security Engineer

Bureau • Bengaluru

On-site
INR 5,681,000 - 7,576,000
Health benefits
Flexible PTO
Learning budget
Sr. Security Compliance Engineer
Sr. Security Compliance Engineer

Pratiti Technologies Pvt Ltd • Pune District

On-site
INR 1,000,000 - 1,500,000
Security Compliance & GRC Lead
Security Compliance & GRC Lead

Cybrilla • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Interesting Job Opportunity: Security Engineer - Cloud & Infrastructure Security
Interesting Job Opportunity: Security Engineer - Cloud & Infrastructure Security

SMC • Delhi

On-site
INR 1,500,000 - 2,500,000
Information Security Manager
Information Security Manager

SaaS Labs • Bengaluru

On-site
INR 450,000 - 800,000
Senior Security Engineer
Senior Security Engineer

Radius Ois • Khordha

On-site
INR 1,500,000 - 2,500,000