Lead Security Eng
Keka
Full Time10+ yearsPosted about 5 hours ago
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
10+ years
Job Description
About the Role
This is a high-ownership, high-visibility role for a security engineer who operates both as a strategic leader and a deeply technical individual contributor. You will lead Keka's security engineering function — building and mentoring a team of junior engineers while personally driving critical security initiatives across cloud infrastructure, product, and platform.
Key Responsibilities
Security Leadership & Strategy
- Own end-to-end security posture across cloud infrastructure, applications, and engineering platforms — from strategy to hands-on execution.
- Define and drive a multi-year security roadmap aligned with Keka's product and engineering growth trajectory.
- Act as the primary security advisor to Engineering, Platform, and Product leadership; influence architecture decisions proactively, not reactively.
- Build, mentor, and grow a team of junior and mid-level security engineers — establishing a culture of security ownership across the entire engineering org.
- Lead threat modeling, security reviews, and risk assessments across new features and architectural changes.
AI-Era Security Practices
- Establish AI security governance: define acceptable use policies for LLMs, Copilot tools, and agentic systems within engineering workflows.
- Identify and mitigate AI-specific threat vectors — prompt injection, model inversion, training data poisoning, and adversarial misuse of AI-powered product features.
- Build detection capabilities for AI-augmented attacks: deepfake social engineering, AI-generated phishing, and automated vulnerability exploitation.
- Evaluate and red-team AI/ML integrations within Keka's product to uncover data leakage, insecure inference endpoints, and supply chain risks.
- Stay current with the evolving threat landscape driven by AI — proactively update controls, playbooks, and team readiness accordingly.
Cloud & Platform Security
- Strengthen and continuously improve cloud security architecture across AWS, GCP, and Azure environments.
- Design and enforce security controls for large-scale distributed systems, multi-tenant SaaS architecture, and high-volume databases.
- Implement and mature IAM, network segmentation, secrets management, encryption, and zero-trust principles.
- Harden container and Kubernetes environments; ensure runtime security, image scanning, and cluster access controls.
- Drive adoption of Infrastructure-as-Code (IaC) security practices with automated policy enforcement (OPA, Sentinel, etc.).
Vulnerability Management & Incident Response
- Lead end-to-end vulnerability assessment and remediation across applications, APIs, databases, and infrastructure.
- Coordinate and conduct penetration testing; partner with external vendors and drive remediation with engineering teams.
- Build and own incident response playbooks, runbooks, and post-mortems — ensuring each incident measurably improves the system.
- Implement and tune SIEM, logging, and alerting pipelines to reduce MTTD and MTTR across security events.
- Conduct regular security drills, tabletop exercises, and red team scenarios to build team muscle memory.
DevSecOps & Engineering Partnership
- Embed security natively into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and container vulnerability checks as first-class gates.
- Partner with Engineering and DevOps to establish secure-by-default development practices — not security as an afterthought.
- Build developer-facing security tooling, threat model templates, and secure coding playbooks that scale across squads.
- Drive adoption of software supply chain security practices (SBOM, dependency auditing, build provenance).
- Champion security as an engineering quality metric — not just a compliance checkbox.
Compliance & Governance
- Lead and support compliance initiatives for SOC2 Type II, ISO 27001, GDPR, and emerging data privacy regulations.
- Maintain audit readiness; own security documentation, control mappings, and evidence collection.
- Support enterprise customer security questionnaires, audits, and trust assessments — acting as a credible technical voice.