Infosec Engineer
Experience : 6+ years Project Location(s) : Hybrid / Remote
Job Description
You’ll be a senior hands‑on engineer executing Capacity’s security program at a pivotal moment. We’ve grown significantly through acquisition, which means we have a multi‑company, multi‑cloud footprint across AWS and Azure spanning 15+ platforms, and a security roadmap with real, meaty work: enforcing authentication security across every acquired cloud account, hardening cloud posture, and building the compliance automation that keeps SOC, ISO, PCI, and HIPAA evidence flowing without manual toil. You’ll report to the Director, Infrastructure Security and be the primary engineering muscle behind the security roadmap for our infrastructure and DevOps processes. Where the Director sets direction,you make it real: in the cloud console, in the IaC, in the SIEM, and in the compliance platform. You’llwork closely with Infrastructure, DevOps, Engineering, and Global Risk and Compliance teams across the full portfolio of platforms.
Key Responsibilities
Cloud Security Engineering
- Implement and maintain cloud security posture across AWS and Azure environments: guardrails, configuration baselines, and drift detection (AWS Config, Lacework, Datadog)
- Investigate and triage security alerts and findings; drive remediation to closure with platform owners
- Implement network segmentation, encryption standards, and secrets management improvements
- Codify security controls as infrastructure as code (Terraform, OpenTofu) wherever possible Identity and Access Management
- Execute MFA enforcement and SSO integration across the full cloud portfolio, including acquired-company accounts
- Implement and maintain IAM policies across AWS Identity Center, Azure PIM / Entra ID, and enterprise SSO
- Ensure best practices related to IAM are enforced across the portfolio, including avoidance of long‑lived credentials without MFA, principle of least privilege, etc.
Application Security and Vulnerability Management
- Operate and tune AppSec tooling (Snyk, GitHub Advanced Security) across the organization’s repositories; partner with engineering teams to remediate findings
- Run vulnerability management: scanning coverage, triage, prioritization, patching coordination, and MTTR tracking
- Review infrastructure and application changes for security impact Incident Response
- Participate in security incident response: detection, containment, root cause analysis, and post‑incident hardening
- Author and maintain security runbooks, standards, and documentation
Requirements
- 5+ years in security engineering or a closely related infrastructure role with a security focus
- Hands-on experience securing AWS and Azure environments: IAM, network segmentation,
encryption, logging, and posture management - Experience with security tooling across the stack: cloud posture management (Lacework or
equivalent), AppSec scanning (Snyk, GitHub Advanced Security, or equivalent), and
SIEM/monitoring (Datadog or equivalent) - Experience running vulnerability management programs in production environments
- Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI, HIPAA) and
compliance automation platforms (Vanta or equivalent) - Comfortable with infrastructure as code (Terraform/OpenTofu or equivalent)
- Previous experience with using scripting languages (Python, Bash, etc) to automate process, Evidence collection, or information gathering is a plus.
- Experience using Claude, Gemini, Cursor, or equivalent to assist with application
development and other tasks - Experience working across a multi-account, multi-company cloud environment is a big plus
- Security certifications (e.g. CISSP, AWS Security Specialty, AZ‑500) are a plus
- Strong cross‑functional communication; comfortable driving remediation with engineers who don’t report to you
- Experience in a SaaS engineering environment with containerized workloads
InApp India Office
121 Nila, Technopark CampusTrivandrum, Kerala 695581
+91 (471) 277 -1800
mktg@inapp.com
InApp USA Office
999 Commercial St. Ste 210Palo Alto, CA 94303
+1 (650) 283-7833
mktg@inapp.com
InApp Japan Office
6-12 Misuzugaoka, Aoba-ku
Yokohama,225-0016
+81-45-978-0788
mktg@inapp.com