Senior Security Engineer
- ₹35,000 – ₹50,000 • No equity
- |
- |5 years of exp
- |Full Time
In office
Not Available
About the job
About RADIUS
RADIUS is an AI-powered Omnichannel Interaction System (OIS) that unifies customer touchpoints into a single intelligent platform. It enables enterprises to manage conversations seamlessly across channels while ensuring context continuity, faster resolutions, and superior customer experiences.
Developed by VIS Networks, a technology-driven company committed to transforming customer engagement, RADIUS combines innovation, scalability, and automation to help businesses deliver connected, data-driven, and future-ready CX.
Role Overview
We are seeking a Senior Security Engineer to lead cloud security implementation and compliance initiatives for our CCaaS platform. In this role, you will architect, implement, and maintain security controls across AWS / Azure / GCP infrastructure while ensuring adherence to industry compliance frameworks. You will work closely with engineering, product, legal, and operations teams to embed security into every layer of the platform. This role is critical to our organizational mission, directly impacting our ability to serve enterprise clients and expand into heavily regulated verticals such as financial services, healthcare, and payment processing.
Key Responsibilities
Cloud Security Architecture & Implementation
- Design and implement security controls across multi-cloud infrastructure (AWS / Azure / GCP).
- Establish Infrastructure-as-Code (IaC) security practices using Terraform or CloudFormation.
- Implement IAM policies, role-based access control (RBAC), and privilege escalation prevention.
- Deploy and configure cloud-native security tools (CloudTrail, VPC Flow Logs, GuardDuty, Security Hub, etc.).
- Establish network segmentation, encryption standards (data-at-rest and in-transit), and secret management solutions.
- Lead security assessments and penetration testing of cloud infrastructure.
Compliance Framework Leadership
- PCI-DSS 3.2 / 4.0: Implement and maintain payment processing controls, lead audit readiness, and manage vulnerability scanning and patch management.
- SOC 2 Type II: Design control matrices, establish evidence collection and documentation processes, and coordinate with auditors during certification cycles.
- HIPAA: Implement technical safeguards for PHI, design encryption, access controls, and audit logging, and ensure BAA compliance.
- GDPR: Implement data processing controls, consent management, and data subject rights fulfillment, and coordinate with legal for DPAs.
- Develop and maintain compliance roadmaps for additional certifications as business needs evolve.
- Prepare for and support third-party audits and customer security assessments.
Security Operations & Monitoring
- Establish security monitoring, logging, and alerting infrastructure (SIEM / log aggregation).
- Implement a vulnerability management program covering scanning, remediation, and tracking.
- Develop security incident response procedures and lead incident post-mortems.
- Create and maintain security runbooks and playbooks.
Secure Development & CI/CD
- Integrate security scanning into CI/CD pipelines (SAST, DAST, SCA, container scanning).
- Define secure coding standards and security-focused code review practices.
- Establish dependency management and third-party library audit processes.
Security Documentation & Risk Management
- Maintain security architecture documentation and threat models.
- Develop security policies, standards, and procedures.
- Conduct risk assessments and maintain a risk register.
- Create security metrics dashboards for executive visibility.
Requirements
- 5–10 years of experience in information security, with at least 3+ years focused on cloud security.
- Demonstrated experience implementing and maintaining at least two of the following compliance frameworks: PCI-DSS, SOC 2, HIPAA, GDPR.
- Proven track record via previous audit certifications, compliance project deliverables, or audit support documentation.
- Hands-on experience with infrastructure-as-code security (Terraform, CloudFormation, or Ansible).
- Working knowledge of cloud-native security services (IAM, KMS, CloudTrail, Security Hub), log aggregation and SIEM, vulnerability scanners, container security, and secrets management solutions.
- Deep understanding of cloud architecture security principles: defense-in-depth, zero trust, and principle of least privilege.
- Strong grasp of network security fundamentals (VPCs, firewalls, VPNs, DDoS mitigation).
- Knowledge of encryption technologies and certificate management.
- Proficiency in API security and secure authentication protocols (OAuth 2.0, SAML, mTLS).
- Familiarity with secure coding practices and the OWASP Top 10.
- Understanding of audit processes, evidence collection, and compliance assessment methodologies.
- Ability to translate compliance requirements into technical controls.
- Strong communication skills with the ability to translate complex security concepts for non-technical stakeholders.
- Excellent cross-functional collaboration with engineering, product, legal, and operations teams.
- Ownership mentality with end-to-end responsibility for security outcomes.
- Attention to detail and meticulous in documentation, compliance evidence, and control implementation.
- Strong problem-solving skills, balancing security requirements with business agility.
- Continuous learning mindset to stay current with the evolving threat landscape.
- Preferred Qualifications
- Industry certifications such as CISSP, CCSP, CISM, or AWS Security Specialty are a plus.
- Experience supporting enterprise customers in regulated industries (financial services, healthcare, payment processing).
- Exposure to DPDP and other emerging data protection regulations.
- Strong communication skills to convey complex security concepts to non-technical stakeholders.
- Ownership mindset and strong cross-functional collaboration with engineering, product, legal, and operations teams.
- Continuous learning approach to stay ahead of the evolving threat landscape.
What You’ll Deliver
- A robust multi-cloud security architecture aligned with industry best practices.
- Audit-ready compliance programs for SOC 2, PCI-DSS, HIPAA, GDPR, and DPDP.
- Mature security operations, monitoring, and incident response capabilities.
- Secure CI/CD pipelines and embedded security in the software development lifecycle.
- Comprehensive security documentation, policies, and executive risk dashboards.
Application Requirements
- Updated resume.
- References demonstrating compliance and audit support experience.
Why Join Us?
Work on cutting-edge CX and AI-driven platforms serving enterprise customers.
Play a foundational role in enabling Fortune 500 readiness and expansion into regulated verticals.
Collaborate with a dynamic and innovative team.
Mentor engineers on secure development practices and shape long-term security strategy.
Opportunity to grow in a fast-paced product environment.
Ready to architect security at enterprise scale and shape the compliance foundation of a fast-growing SaaS platform? Apply now!
