
- Early StageStartup in initial stages
- Growing fastShowed strong hiring growth in the past month
Founding Security Engineer
- ₹12L – ₹20L • 0.01% – 0.5%
- |
- |3 years of exp
- |Full Time
About the job
Location: Gurgaon (In-Office) / Bangalore (Remote at first then in-office)
Type: Full-time
Experience: 3+ Years
About EquityList
EquityList is trusted by 600+ companies to manage their cap table and stock option workflows and compliance. Our comprehensive platform allows customers to manage and administer equity grants - ESOPs, SARs, RSUs, RSAs seamlessly and at scale.
Our customers span APAC, MENA, and the US, including Tata Consumer Products, Taco Bell, Blackbuck, Livspace, Slice, smallcase, Tabby.ai, and Shiprocket - managing equity for 50,000+ stakeholders and stock options worth $3Bn+. We're backed by AngelList India, Hustle Fund, Republic, Unpopular Ventures, Mana Ventures, and a stellar group of angels.
About the Role
As we deepen our enterprise footprint across regulated markets - onboarding listed companies, fintechs, and compliance-driven clients across three geographies, security has moved from a checkbox to a core trust signal. Clients managing billions in equity on our platform expect us to meet enterprise-grade security standards, and we take that seriously.
We're looking for an Information Security Associate who is hands-on, ownership-oriented, and equally comfortable hardening infrastructure and walking a client's CISO through our controls framework. You'll be our first dedicated security hire - which means you own the function, set the baseline, and ensure every enterprise prospect can trust EquityList with their most sensitive equity data.
Ideal Candidate Mindset
You've been the only security person in a room full of engineers. You've written the first acceptable use policy and found a critical IDOR on the same day. You care about building systems and processes that outlast you, not just passing audits.
Key Responsibilities
1. Security Operations: Own our day-to-day security posture, access controls, endpoint hardening, secrets management, and cloud security hygiene on GCP. Monitor SIEM alerts, investigate incidents, and lead post-incident reviews with written closure reports.
2. Vulnerability Management: Conduct periodic internal assessments and coordinate third-party VAPT engagements. Own the remediation tracker and ensure findings don't die in a spreadsheet.
3. Compliance & ISMS: Build and maintain our Information Security Management System - policies, risk registers, vendor assessments, and runbooks. Be the person who actually keeps these updated.
4. Certification Readiness: Support readiness for ISO 27001, SOC 2 Type II, and GDPR (EU) - maintaining evidence artefacts, coordinating with auditors, and closing gaps proactively.
5. Client-Facing Trust Building: Own our Infosec response library for enterprise RFPs, DDQs, and security annexures. Represent EquityList on client InfoSec calls with clarity and confidence.
6. Product and Application Security: Work with the engineering team on secure design reviews, threat modelling, and pre-release security checks - bringing security into the SDLC, not just after the fact.
7. Bug Bounty/Responsible disclosure programs: Take ownership of initiating and managing bug bounty programs
8. Cross-functional Collaboration: Partner with Product, Compliance, and Business teams to translate security requirements into practical, executable controls without becoming a blocker.
Requirements
Technical:
- 2–3 years in an InfoSec, security engineering, or GRC + technical hybrid role. Ideally, at a SaaS or fintech company
- Working knowledge of GCP security - IAM, VPC service controls, Cloud Armor, Security Command Center, Cloud Logging, and alerting
- Familiarity with OWASP Top 10, common vulnerability classes, and the ability to triage scanner output
- Experience writing security policies, ISMS documentation, and risk registers - not just reading templates
- Scripting ability (Python or Bash) for automating checks or log analysis is a plus
- Soft Skills:
- Strong written communication, you can translate technical risk into plain language for a founder, a CFO, or a client's legal team
- Documentation-first mindset, you close loops and keep records clean without being reminded
- Startup-ready, comfortable with ambiguity, proactive about gaps, and able to wear multiple hats
- Education:
- B.E. / B.Tech in Computer Science, IT, or related field — or equivalent practical experience
- CompTIA Security+, CEH, or Google's Professional Cloud Security Engineer certification is a plus.
Good to Have
- Hands-on involvement in ISO 27001 implementation or audit support
- SOC 2 Type II readiness experience
- VAPT coordination with third-party vendors
- Awareness of India's DPDP Act and IT Act obligations
- Prior experience at a B2B SaaS or fintech startup
- Hands-on experience with DLP, MDM, or SIEM tooling
Growth Opportunity
Build from scratch: You're EquityList's first security hire, you write the playbook, choose the tools, and define what security culture looks like here. No bureaucracy, full ownership.
Work at the intersection of security and growth: At our stage, security directly enables revenue. You'll co-own enterprise onboarding conversations, influence product architecture, and build relationships with CISOs and CFOs at India's fastest-growing companies.
About the company
- Early StageStartup in initial stages
- Growing fastShowed strong hiring growth in the past month
Employees joined from
Perks
Similar Jobs





