Skip to content

Lead Security Eng

Keka Technologies Pvt. LtdBengaluru, KA, IndiaSeptember 12, 2026
On-site
Full-time
Security Engineering
Management

About Keka

Keka HR is one of India's fastest-growing HRTech platforms, trusted by thousands of businesses

across India, the GCC, and the United States. Built with an employee-first approach, Keka helps

organizations manage HR, Payroll, Performance, and Employee Experience — seamlessly, at

scale.

As Keka scales rapidly across geographies and customer segments, security is a core engineering

priority — not an afterthought. We are looking for a Lead Security Engineer who will define, build,

and own Keka's security posture for the next phase of growth.

About the Role

This is a high-ownership, high-visibility role for a security engineer who operates both as a strategic

leader and a deeply technical individual contributor. You will lead Keka's security engineering

function — building and mentoring a team of junior engineers while personally driving critical

security initiatives across cloud infrastructure, product, and platform.

The security landscape has changed fundamentally with the rise of AI. We are looking for someone

who doesn't just understand that shift — but actively builds against it. Whether securing AI-powered

product features, defending against AI-augmented attacks, or establishing responsible AI usage

policies within engineering, you'll be defining the playbook.

The ideal candidate sees security not as a gatekeeping function, but as a force multiplier for

engineering velocity and customer trust.

Key Responsibilities

1. Security Leadership & Strategy

keka · Lead Security Engineer — Job Description

• Own end-to-end security posture across cloud infrastructure, applications, and engineering

platforms — from strategy to hands-on execution.

• Define and drive a multi-year security roadmap aligned with Keka's product and engineering

growth trajectory.

• Act as the primary security advisor to Engineering, Platform, and Product leadership;

influence architecture decisions proactively, not reactively.

• Build, mentor, and grow a team of junior and mid-level security engineers — establishing a

culture of security ownership across the entire engineering org.

• Lead threat modeling, security reviews, and risk assessments across new features and

architectural changes.

2. AI-Era Security Practices

• Establish AI security governance: define acceptable use policies for LLMs, Copilot tools, and

agentic systems within engineering workflows.

• Identify and mitigate AI-specific threat vectors — prompt injection, model inversion, training

data poisoning, and adversarial misuse of AI-powered product features.

• Build detection capabilities for AI-augmented attacks: deepfake social engineering, AIgenerated phishing, and automated vulnerability exploitation.

• Evaluate and red-team AI/ML integrations within Keka's product to uncover data leakage,

insecure inference endpoints, and supply chain risks.

• Stay current with the evolving threat landscape driven by AI — proactively update controls,

playbooks, and team readiness accordingly.

3. Cloud & Platform Security

• Strengthen and continuously improve cloud security architecture across AWS, GCP, and

Azure environments.

• Design and enforce security controls for large-scale distributed systems, multi-tenant SaaS

architecture, and high-volume databases.

• Implement and mature IAM, network segmentation, secrets management, encryption, and

zero-trust principles.

• Harden container and Kubernetes environments; ensure runtime security, image scanning,

and cluster access controls.

• Drive adoption of Infrastructure-as-Code (IaC) security practices with automated policy

enforcement (OPA, Sentinel, etc.).

4. Vulnerability Management & Incident Response

• Lead end-to-end vulnerability assessment and remediation across applications, APIs,

databases, and infrastructure.

• Coordinate and conduct penetration testing; partner with external vendors and drive

remediation with engineering teams.

• Build and own incident response playbooks, runbooks, and post-mortems — ensuring each

incident measurably improves the system.

• Implement and tune SIEM, logging, and alerting pipelines to reduce MTTD and MTTR across

security events.

• Conduct regular security drills, tabletop exercises, and red team scenarios to build team

muscle memory.

keka · Lead Security Engineer — Job Description

5. DevSecOps & Engineering Partnership

• Embed security natively into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and

container vulnerability checks as first-class gates.

• Partner with Engineering and DevOps to establish secure-by-default development practices

— not security as an afterthought.

• Build developer-facing security tooling, threat model templates, and secure coding playbooks

that scale across squads.

• Drive adoption of software supply chain security practices (SBOM, dependency auditing, build

provenance).

• Champion security as an engineering quality metric — not just a compliance checkbox.

6. Compliance & Governance

• Lead and support compliance initiatives for SOC2 Type II, ISO 27001, GDPR, and emerging

data privacy regulations.

• Maintain audit readiness; own security documentation, control mappings, and evidence

collection.

• Support enterprise customer security questionnaires, audits, and trust assessments — acting

as a credible technical voice.

What We're Looking For

Must Have

✓ 10+ years in Security Engineering, Cloud Security, or Platform Security — with at least 3

years in a senior/lead role.

✓ Proven experience building and mentoring security teams in startup or high-growth SaaS

environments.

✓ Hands-on depth in IAM, network security, container/Kubernetes security, API security,

database security, encryption, and secrets management.

✓ Strong cloud security experience across AWS, GCP, or Azure — ideally multi-cloud.

✓ Experience with security tooling: Nessus, Burp Suite, Qualys, Prisma Cloud, Wiz,

CrowdStrike, or equivalents.

✓ Proficiency in scripting/automation: Python, Bash, or Go — for building detections,

remediations, and security tooling.

✓ Ability to operate both as a strategic people leader and a deeply hands-on individual

contributor.

✓ Strong incident response instincts — you've owned P0 security incidents end-to-end.

✓ Excellent stakeholder management and ability to translate technical risk into business impact.

Good to Have

› Hands-on experience with AI/ML security — LLM threat modeling, agentic pipeline security, or

adversarial ML.

keka · Lead Security Engineer — Job Description

› Experience in HRTech, FinTech, or enterprise SaaS with multi-tenancy and PII at scale.

› Certifications: CISSP, CCSP, CEH, AWS Security Specialty, or Google Cloud Security.

› Exposure to building scalable security programs from scratch in lean team environments.

› Experience with Zero Trust architecture implementation.

› Familiarity with SOC2 Type II, ISO 27001, GDPR compliance frameworks.

Why Join Keka

Scale & Impact — Secure infrastructure powering HR for thousands of companies across India,

GCC, and the US. Your work protects real employee data at scale.

Build, Don't Just Run — Join early enough to shape security culture, tooling, and team from the

ground up — not inherit a legacy compliance checklist.

AI-Native Engineering — Keka is actively embedding AI across its product and engineering

workflows. You'll be at the frontier of AI security — not catching up to it.

Engineering-First Culture — Security here is treated as engineering quality — not an obstacle.

You'll have the trust, access, and influence to get things done right.

Ready to secure one of India's fastest-growing SaaS

Job Details

Experience

Management

Tools & Tech

AWS
Azure
Bash
Burp Suite
CrowdStrike
GCP
GitHub Copilot
Go
Kubernetes
Microsoft Sentinel
Nessus
OPA
Prisma Cloud
Python
Qualys
Wiz

Preferred Certs

AWS Security Specialty
CCSP
CEH
CISSP