Pune, भारत
Vacancy description
EquityList
$3 USD
Gurgaon, भारत
About EquityList:EquityList is trusted by 600+ companies to manage their cap table and stock option workflows and compliance. Our comprehensive platform allows customers to manage and administer equity grants - ESOPs, SARs, RSUs, RSAs seamlessly and at https://jobeax.com/link/0IrWkv4yR6S3C4XS customers span APAC, MENA, and the US, including Tata Consumer Products, Taco Bell, Blackbuck, Livspace, Slice, smallcase, https://jobeax.com/link/PiC8ChXhw5fyKWMa, and Shiprocket - managing equity for 50,000+ stakeholders and stock options worth $3Bn+. We're backed by AngelList India, Hustle Fund, Republic, Unpopular Ventures, Mana Ventures, and a stellar group of https://jobeax.com/link/iDV7eJoJ6ZT8h8Wl the Role:As we deepen our enterprise footprint across regulated markets - onboarding listed companies, fintechs, and compliance-driven clients across three geographies, security has moved from a checkbox to a core trust signal. Clients managing billions in equity on our platform expect us to meet enterprise-grade security standards, and we take that seriously. We're looking for an Information Security Associate who is hands-on, ownership-oriented, and equally comfortable hardening infrastructure and walking a client's CISO through our controls framework. You'll be our first dedicated security hire - which means you own the function, set the baseline, and ensure every enterprise prospect can trust EquityList with their most sensitive equity https://jobeax.com/link/5Kl0LLo7GszuESkK Candidate Mindset:You've been the only security person in a room full of engineers. You've written the first acceptable use policy and found a critical IDOR on the same day. You care about building systems and processes that outlast you, not just passing https://jobeax.com/link/4plMygJeVwc5xE4I Responsibilities:1. Security Operations:- Own our day-to-day security posture, access controls, endpoint hardening, secrets management, and cloud security hygiene on GCP. Monitor SIEM alerts, investigate incidents, and lead post-incident reviews with written closure reports.2. Vulnerability Management:- Conduct periodic internal assessments and coordinate third-party VAPT engagements. Own the remediation tracker and ensure findings don't die in a spreadsheet.3. Compliance & ISMS:- Build and maintain our Information Security Management System - policies, risk registers, vendor assessments, and runbooks. Be the person who actually keeps these updated.4. Certification Readiness:- Support readiness for ISO 27001, SOC 2 Type II, and GDPR (EU) - maintaining evidence artefacts, coordinating with auditors, and closing gaps proactively.5. Client-Facing Trust Building:- Own our Infosec response library for enterprise RFPs, DDQs, and security annexures. Represent EquityList on client InfoSec calls with clarity and confidence.6. Product and Application Security:- Work with the engineering team on secure design reviews, threat modelling, and pre-release security checks - bringing security into the SDLC, not just after the fact.7. Bug Bounty/Responsible disclosure programs:- Take ownership of initiating and managing bug bounty programs.8. Cross-functional Collaboration:- Partner with Product, Compliance, and Business teams to translate security requirements into practical, executable controls without becoming a blocker.Requirements:Technical:- 2 - 3 years in an InfoSec, security engineering, or GRC + technical hybrid role. Ideally, at a SaaS or fintech company.- Working knowledge of GCP security - IAM, VPC service controls, Cloud Armor, Security Command Center, Cloud Logging, and alerting.- Familiarity with OWASP Top 10, common vulnerability classes, and the ability to triage scanner output.- Experience writing security policies, ISMS documentation, and risk registers - not just reading templates.- Scripting ability (Python or Bash) for automating checks or log analysis is a https://jobeax.com/link/Qod6Xl5vE5JajabY Skills:- Strong written communication, you can translate technical risk into plain language for a founder, a CFO, or a client's legal team.- Documentation-first mindset, you close loops and keep records clean without being reminded.- Startup-ready, comfortable with ambiguity, proactive about gaps, and able to wear multiple hats.Education:- B.E. / https://jobeax.com/link/2DENLGgQM7whDhaE in Computer Science, IT, or related field - or equivalent practical experience.- CompTIA Security+, CEH, or Google's Professional Cloud Security Engineer certification is a https://jobeax.com/link/sdmIcjxQwAiTGZY2 to Have:- Hands-on involvement in ISO 27001 implementation or audit support.- SOC 2 Type II readiness experience.- VAPT coordination with third-party vendors.- Awareness of India's DPDP Act and IT Act obligations.- Prior experience at a B2B SaaS or fintech startup.- Hands-on experience with DLP, MDM, or SIEM tooling.- Build from scratch: You're EquityList's first security hire, you write the playbook, choose the tools, and define what security culture looks like here. No bureaucracy, full ownership.- Work at the intersection of security and growth: At our stage, security directly enables revenue. You'll co-own enterprise onboarding conversations, influence product architecture, and build relationships with CISOs and CFOs at India's fastest-growing companies. (ref:hirist.tech)
Similar vacancies
Pune, भारत
Barracuda Networks
Bangalore, भारत
Bangalore, भारत
Energy Exemplar
Pune, भारत
Hyderabad, भारत
Contentstack
Bangalore, भारत
Bengaluru, भारत
Capgemini
Hyderabad, भारत
Maganti IT Resources, LLC
Hyderabad, भारत
IT, Compliance / Regulatory
$300 USD
Delhi, भारत