About Loyalytics
Loyalytics is a fast‑growing analytics consulting and product organization based in Bangalore. We partner with large retail clients worldwide to monetize their data assets through consulting assignments and product accelerators. The company consists of a dynamic team of over 100 analysts, data scientists, and engineers working with cutting‑edge tools and technologies.
Who We Are
- Technical team of data scientists, data engineers, and business analysts handling over 1M data points daily.
- Massive multi‑billion‑$ global market opportunity.
- Combined leadership experience of 40+ years.
- Customer base includes major retail brands in GCC regions such as Lulu and GMG.
- Bootstrapped for 8 years and still expanding.
Our Product
Swan is a customer engagement platform that drives personalized, data‑driven engagement at scale. It is cloud‑native, multi‑tenant, and designed to handle sensitive customer data. Swan is fully deployed on Microsoft Azure and ISO 27001 certified.
Role Overview
We are looking for a dedicated Security Engineer (4–6 years of experience) to lead the security of the Swan platform, strengthen our cloud posture, handle compliance (ISO 27001, PDPL, GDPR), partner with external security agencies, and engage with enterprise customers on security matters.
Key Responsibilities
- Cloud & Infrastructure Security (Azure)
- Own end‑to‑end security of Azure infrastructure: App Services, Functions, Container Apps, Cosmos DB, Redis, Databricks
- Define and enforce best practices for identity & access management, network security, and secrets management
- Continuously improve Azure Security Score and proactively close gaps
- Application & API Security: review backend services in Node.js and Golang, implement secure APIs, authentication, rate limiting, abuse prevention, and PII handling
- Drive secure coding practices and threat modelling across services
- Data Security & Privacy: Design end‑to‑end data flow, manage PII, define retention, masking, encryption, access controls, and multi‑tenant data isolation
- Compliance & Governance: Own compliance readiness for ISO 27001, PDPL, GDPR; write and maintain security policies, risk registers, incident response plans, access control, and data protection policies
- Collaborate with external agencies and auditors to close findings, provide evidence, and drive certifications and assessments
- VAPT & Security Testing: plan, manage, and execute VAPT; coordinate vendors, perform internal testing, track findings, and ensure resolution
- CI/CD & DevSecOps: integrate security into CI/CD pipelines (GitHub Actions/Azure DevOps), perform secrets scanning, dependency scanning, basic SAST/DAST, and secure build/deploy/release processes
- AI & Data Usage Security: review AI usage, prevent exposure of confidential or PII data, and define guardrails from a security and privacy perspective
- Customer & Incident Handling: join security calls with enterprise customers, respond to security questionnaires, and execute incident response—including detection, containment, root‑cause analysis, and preventive actions
Must-Have Skills & Experience
- 4–6 years of hands‑on security engineering
- Strong experience securing cloud‑native systems on Azure
- Practical experience with ISO 27001, GDPR, PDPL or similar privacy laws
- Experience handling PII‑heavy, multi‑tenant SaaS platforms
- Comfortable drafting security policies and technical documentation
- Experience working with external security agencies and auditors
- Ability to work independently and take full ownership
Good‑to‑Have
- Hands‑on VAPT or penetration testing experience
- DevSecOps tooling experience
- Experience in customer‑facing security roles
- Startup or high‑growth SaaS experience
What Success Looks Like (First 6 Months)
- Clear visibility and documentation of data flows across the platform
- Improved Azure security posture and security score
- All critical/high VAPT findings closed
- PDPL & GDPR readiness with external agencies
- Security policies and incident response processes in place
- Engineering team following consistent security best practices
- Confidence from enterprise customers in Swan’s security posture