Padmi

Information Security Lead

IndiaPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at RoboMQ

Opens the source posting on shine.com

Source description

About the role

View original

Job Description: Role Overview: You will be joining RoboMQ, a fast-growing SaaS company specializing in delivering disruptive Identity Governance and Administration (IGA) solutions to mid-market enterprise customers. The flagship product, Hire2Retire, focuses on automating the employee identity lifecycle, integrating HR systems with Identity Management and other applications to ensure seamless onboarding, off-boarding, compliance, and security with a zero-trust and least-privilege security posture. Key Responsibilities: - Application Security (AppSec): - Drive and secure the SDLC practices across product lines. - Oversee threat modeling, secure code reviews, and integrate robust Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) into the deployment pipeline. - Vulnerability & Risk Governance: - Own the end-to-end vulnerability management lifecycle. - Architect risk assessment methodologies, run remediation tracking, and ensure systematic patching of application and infrastructure weak points. - Security Assessments: - Conduct hands-on technical scanning and security assessments utilizing industry-standard tools, network scanners, and assessment utilities such as Nmap, OWASP ZAP, or commercial equivalents. - Network & Cloud Architecture: - Secure cloud-native infrastructure hosted on AWS. - Oversee network security architectures including firewalls, micro-segmentation, IDS/IPS, and Web Application Firewalls (WAFs) to actively manage the company's external attack surface. - Compliance & Frameworks: - Implement, scale, and maintain critical organizational security controls aligned tightly with industry frameworks such as SOC 2, HIPAA, and continuous regulatory standards. - Enterprise Governance: - Formulate, publish, and enforce comprehensive enterprise-wide security policies, standards, and operational procedures across all corporate branches. - Third-Party Risk Management (TPRM): - Manage the organization's vendor security posture. - Architect the assessment framework to audit third-party risk profiles, SaaS integrations, and supply chain vendors. - Incident Response & Collaboration: - Lead corporate security incident responses. - Act as the primary bridge guiding engineering, DevOps, and leadership through mitigation protocols and root-cause compliance. Qualifications Required: - 5+ years of experience in Cyber Security, Information Security, Application Security, or related domains. - Proven track record of leading security initiatives across engineering, operations, and infrastructure teams. - Technical degree (B. Tech / B.E.) from a premier engineering institute with exceptional technical acumen. - Deep architectural and practical understanding of network security, cloud ecosystems, and modern attack surface management. - Exceptional stakeholder management, communication, and leadership skills with the ability to influence cross-functional business teams. - Strong ownership mindset to champion a culture of zero-trust security across the entire organization. Please note that the job description does not contain any additional details about the company. Job Description: Role Overview: You will be joining RoboMQ, a fast-growing SaaS company specializing in delivering disruptive Identity Governance and Administration (IGA) solutions to mid-market enterprise customers. The flagship product, Hire2Retire, focuses on automating the employee identity lifecycle, integrating HR systems with Identity Management and other applications to ensure seamless onboarding, off-boarding, compliance, and security with a zero-trust and least-privilege security posture. Key Responsibilities: - Application Security (AppSec): - Drive and secure the SDLC practices across product lines. - Oversee threat modeling, secure code reviews, and integrate robust Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) into the deployment pipeline. - Vulnerability & Risk Governance: - Own the end-to-end vulnerability management lifecycle. - Architect risk assessment methodologies, run remediation tracking, and ensure systematic patching of application and infrastructure weak points. - Security Assessments: - Conduct hands-on technical scanning and security assessments utilizing industry-standard tools, network scanners, and assessment utilities such as Nmap, OWASP ZAP, or commercial equivalents. - Network & Cloud Architecture: - Secure cloud-native infrastructure hosted on AWS. - Oversee network security architectures including firewalls, micro-segmentation, IDS/IPS, and Web Application Firewalls (WAFs) to actively manage the company's external attack surface. - Compliance & Frameworks: - Implement, scale, and maintain critical organizational security controls aligned tightly with industry frameworks such as SOC 2, HIPAA, and c

One address, no account. We’ll tell you when matching roles go live.

More at RoboMQ

Related open roles

View all roles