
Security & Policy Engineer
- ₹12L – ₹24L • 2.0% – 5.0%
- |Remote () •
- |2 years of exp
- |Full Time
About the job
Mission
Build the security and policy layer that makes Federis credible for regulated enterprise buyers: fail-closed controls, least privilege access, audit evidence, policy-as-code, secure integrations, and defensible compliance posture.
Key Responsibilities
• Implement policy decision points, policy enforcement points, audit trails, RBAC/ABAC workflows, approvals, and evidence capture.
• Integrate external IAM and policy systems through provider abstractions rather than product-specific tight coupling.
• Own threat models, secure design reviews, abuse cases, data-flow analysis, secrets handling, and security test requirements.
• Build controls for tenant isolation, service authentication, mTLS, certificate lifecycle, key management, and privileged operation review.
• Create secure-by-default engineering patterns and partner with QA on negative tests, access-control tests, and regression suites.
• Support enterprise due diligence, security questionnaires, audit requests, and compliance evidence collection.
Required Experience
• 5+ years in product security, platform security, IAM, policy engineering, compliance engineering, or secure backend development.
• Practical experience with authorization models, identity federation, audit logging, encryption, secrets management, and secure APIs.
• Strong ability to translate policy requirements into enforceable code, tests, and operational controls.
• Comfort reviewing architecture, code, infrastructure, dependencies, and deployment practices for security and licensing risk.
• Clear written communication for security findings, control descriptions, and customer-facing evidence.
Useful Differentiators
• Hands-on experience with OPA, Rego, Keycloak, SPIFFE/SPIRE, service mesh security, SIEM integrations, or cloud KMS/HSM patterns.
• Experience with SOC 2, ISO 27001, financial services security reviews, public sector procurement, or air-gapped deployments.
• Background in AI governance, model risk management, data loss prevention, or privacy engineering.
First 90 Days
• Publish security architecture principles, threat model templates, policy design patterns, and access-control test strategy.
• Implement or harden at least one critical policy/audit workflow end to end.
• Create the first customer security evidence packet with product, platform, and process owners.
Success Scorecard
• High-risk workflows fail closed and produce complete audit evidence.
• Security review is integrated into design and release flow without becoming a late-stage bottleneck.
• Identity and policy integrations remain provider-neutral and replaceable.
• Enterprise security questionnaires become repeatable rather than bespoke engineering projects.
Similar Jobs








