Skip to content

Security Engineer

Bounteous IndiaChennai, TN, IndiaAugust 12, 2026
On-site
Full-time
Security Engineering
Senior · 5+ yrs

About the Role

We are looking for a Senior Security Engineer to strengthen and operate our security architecture, which is organized around the NIST Cybersecurity Framework (CSF) 2.0.

This is a hands-on engineering role at the center of the security program. You will own day-to-day operation of core security tooling, drive vulnerability and findings remediation across engineering teams, harden identity and access controls, and produce the control evidence supporting HIPAA (and, where applicable, other regulatory frameworks such as SOX) compliance obligations. You will work closely with DevOps/Engineering, IT, the Compliance/GRC function, and any managed security services partner.

What You Will Do

  • Operate and continuously improve the security stack: WAF policy tuning, cloud posture and vulnerability triage, log-source onboarding to the SIEM, and EDR coverage.
  • Own the findings lifecycle: review penetration test, SIEM, and posture-management findings in a central register, assign to accountable owners, and drive remediation within defined severity-based SLAs (e.g., Critical: plan within 1 day, resolve within 3 days).
  • Harden identity and access management: MFA enforcement across critical systems, access provisioning/deprovisioning workflows, privileged access restriction, and periodic access recertification.
  • Support regulatory control remediation (e.g., HIPAA, SOX ITGC): partner with Engineering and IT to close audit findings in user access management, change management, dev/production segregation, and job/interface monitoring.
  • Extend detection coverage: onboard application logs into the SIEM, close monitoring gaps, and partner with the SOC (in-house or managed) on alert triage, escalation, and incident response.
  • Verify and document WAF/CDN placement and consistent edge protection across all hosted applications and service APIs.
  • Contribute to resilience: validate backup monitoring for core databases, support disaster-recovery tiering (RTO/RPO) completion, and help formalize incident and recovery communication plans.
  • Maintain control evidence in the GRC platform and support internal/external audit cycles alongside the Compliance/GRC owner.
  • Coordinate penetration testing scope and remediation with a managed security services provider, if applicable.

What You Bring

  1. 5+ years in security engineering, with at least 3 years securing cloud-native environments (primary cloud platform required; multi-cloud exposure a plus).
  2. Hands-on experience with CSPM/vulnerability management platforms, WAF/CDN platforms, and SIEM operations (log-source onboarding, alert tuning, working with a SOC).
  3. Strong identity and access management background: SSO/IdP administration, MFA enforcement, cloud IAM, and access review/recertification processes.
  4. Experience running a vulnerability or findings remediation program against defined SLAs, including working directly with engineering teams to get fixes shipped.
  5. Working knowledge of HIPAA Security Rule and (where applicable) SOX ITGC domains (access management, change management, computer operations); experience remediating audit findings strongly preferred.
  6. Familiarity with NIST CSF (2.0) and the ability to map technical controls to framework categories and produce audit-ready evidence.
  7. Scripting ability (Python, Bash, or similar) for automation of security operations tasks.
  8. Clear written and verbal communication — able to explain risk to engineers, auditors, and leadership alike.

Nice to Have

  • Experience in healthcare, telehealth, or another regulated PHI/PII environment.
  • Experience with GRC platforms and evidence automation.
  • Familiarity with EDR platforms and managed security service provider (MSSP) relationships.
  • Exposure to cloud-native relational and NoSQL data store security configuration.
  • Relevant certifications: CISSP, CCSP, AWS/cloud-platform Security Specialty, GIAC (GSEC, GCSA, GCIH), or similar.

Job Details

Salary

₹2,500,000 – ₹3,500,000/yr

Experience

Senior · 5+ yrs

Tools & Tech

AWS
Bash
Python

Preferred Certs

CCSP
CISSP
GCIH
GSEC