Vacancy description
EquityList
$3 USD
Gurgaon, भारत
About EquityList:EquityList is trusted by 600+ companies to manage their cap table and stock option workflows and compliance. Our comprehensive platform allows customers to manage and administer equity grants - ESOPs, SARs, RSUs, RSAs seamlessly and at https://jobeax.com/link/0IrWkv4yR6S3C4XS customers span APAC, MENA, and the US, including Tata Consumer Products, Taco Bell, Blackbuck, Livspace, Slice, smallcase, https://jobeax.com/link/PiC8ChXhw5fyKWMa, and Shiprocket - managing equity for 50,000+ stakeholders and stock options worth $3Bn+. We're backed by AngelList India, Hustle Fund, Republic, Unpopular Ventures, Mana Ventures, and a stellar group of https://jobeax.com/link/iDV7eJoJ6ZT8h8Wl the Role:As we deepen our enterprise footprint across regulated markets - onboarding listed companies, fintechs, and compliance-driven clients across three geographies, security has moved from a checkbox to a core trust signal. Clients managing billions in equity on our platform expect us to meet enterprise-grade security standards, and we take that seriously. We're looking for an Information Security Associate who is hands-on, ownership-oriented, and equally comfortable hardening infrastructure and walking a client's CISO through our controls framework. You'll be our first dedicated security hire - which means you own the function, set the baseline, and ensure every enterprise prospect can trust EquityList with their most sensitive equity https://jobeax.com/link/5Kl0LLo7GszuESkK Candidate Mindset:You've been the only security person in a room full of engineers. You've written the first acceptable use policy and found a critical IDOR on the same day. You care about building systems and processes that outlast you, not just passing https://jobeax.com/link/4plMygJeVwc5xE4I Responsibilities:1. Security Operations:- Own our day-to-day security posture, access controls, endpoint hardening, secrets management, and cloud security hygiene on GCP. Monitor SIEM alerts, investigate incidents, and lead post-incident reviews with written closure reports.2. Vulnerability Management:- Conduct periodic internal assessments and coordinate third-party VAPT engagements. Own the remediation tracker and ensure findings don't die in a spreadsheet.3. Compliance & ISMS:- Build and maintain our Information Security Management System - policies, risk registers, vendor assessments, and runbooks. Be the person who actually keeps these updated.4. Certification Readiness:- Support readiness for ISO 27001, SOC 2 Type II, and GDPR (EU) - maintaining evidence artefacts, coordinating with auditors, and closing gaps proactively.5. Client-Facing Trust Building:- Own our Infosec response library for enterprise RFPs, DDQs, and security annexures. Represent EquityList on client InfoSec calls with clarity and confidence.6. Product and Application Security:- Work with the engineering team on secure design reviews, threat modelling, and pre-release security checks - bringing security into the SDLC, not just after the fact.7. Bug Bounty/Responsible disclosure programs:- Take ownership of initiating and managing bug bounty programs.8. Cross-functional Collaboration:- Partner with Product, Compliance, and Business teams to translate security requirements into practical, executable controls without becoming a blocker.Requirements:Technical:- 2 - 3 years in an InfoSec, security engineering, or GRC + technical hybrid role. Ideally, at a SaaS or fintech company.- Working knowledge of GCP security - IAM, VPC service controls, Cloud Armor, Security Command Center, Cloud Logging, and alerting.- Familiarity with OWASP Top 10, common vulnerability classes, and the ability to triage scanner output.- Experience writing security policies, ISMS documentation, and risk registers - not just reading templates.- Scripting ability (Python or Bash) for automating checks or log analysis is a https://jobeax.com/link/Qod6Xl5vE5JajabY Skills:- Strong written communication, you can translate technical risk into plain language for a founder, a CFO, or a client's legal team.- Documentation-first mindset, you close loops and keep records clean without being reminded.- Startup-ready, comfortable with ambiguity, proactive about gaps, and able to wear multiple hats.Education:- B.E. / https://jobeax.com/link/2DENLGgQM7whDhaE in Computer Science, IT, or related field - or equivalent practical experience.- CompTIA Security+, CEH, or Google's Professional Cloud Security Engineer certification is a https://jobeax.com/link/sdmIcjxQwAiTGZY2 to Have:- Hands-on involvement in ISO 27001 implementation or audit support.- SOC 2 Type II readiness experience.- VAPT coordination with third-party vendors.- Awareness of India's DPDP Act and IT Act obligations.- Prior experience at a B2B SaaS or fintech startup.- Hands-on experience with DLP, MDM, or SIEM tooling.- Build from scratch: You're EquityList's first security hire, you write the playbook, choose the tools, and define what security culture looks like here. No bureaucracy, full ownership.- Work at the intersection of security and growth: At our stage, security directly enables revenue. You'll co-own enterprise onboarding conversations, influence product architecture, and build relationships with CISOs and CFOs at India's fastest-growing companies. (ref:hirist.tech)