{"id":1226023,"url":"https://alion.io/job/aura-cloud-ab-information-security-architect","title":"Information Security Architect","company":{"id":2656349,"name":"Aura Cloud","domain":"auracloud.com","url":"https://alion.io/company/aura-cloud-ab","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Keka","truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":25000,"max_usd":59000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":415},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon CloudWatch","optional":false},{"name":"AWS","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"Commander.js","optional":false},{"name":"CVE","optional":false},{"name":"GDPR","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Rest API","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"Splunk","optional":false},{"name":"Wazuh","optional":false},{"name":"JavaScript","optional":true},{"name":"Node JS","optional":true}],"status":"live","first_seen_at":"2026-09-20T11:08:36Z","employer_posted_date":"2026-09-20","last_verified_at":"2026-10-04T00:32:04Z","board_verified":true,"closed_at":null,"days_open":13,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":13},"description":"About Aura Cloud\nAura Cloud is a Nordic SaaS core banking platform provider. Our Aura platform powers banks and financial institutions across the Nordics and Baltics - processing deposits, loans, payments, and cards for regulated customers.\nThe Role\nYou will own information security across the Aura platform, infrastructure, and organization - from security architecture and compliance certifications to customer-facing security assurance and incident response.\nWe are ISO 27001 certified and continuously strengthening our compliance posture across SOC 2, DORA, and other regulatory frameworks. We need someone who can drive certifications, strengthen our security architecture, and be the trusted security voice to our regulated customers.\nWhat You Will Own\nSecurity Architecture & Engineering\nDefine and maintain the platform's security architecture - network segmentation, encryption, access control, API security, and key management\nReview and approve infrastructure changes, new integrations, and API exposure decisions\nOwn the vulnerability management program - dependency scanning, CVE triage, patching, and remediation tracking\nOversee security monitoring tooling (Wazuh SIEM, EWACS, CloudWatch) - detection rules, alert triage, and tuning\nHands-On Security Engineering\nDesign and implement AWS security controls directly - IAM policies, security groups, KMS key policies, WAF rulesets, GuardDuty tuning\nLead remediation of penetration test and vulnerability assessment findings across infrastructure and application layers, working hands-on with engineering teams to close gaps\nConfigure and tune SIEM detection rules and alerting logic (Wazuh or equivalent) - build use cases, not just monitor dashboards\nOwn certificate lifecycle management and encryption implementation (at-rest and in-transit) across environments\nReview and harden infrastructure configurations against CIS benchmarks and similar standards\nWork with engineering on secure coding practices and help embed security checks into the development pipeline\nCompliance & Certifications\nMaintain and evolve the existing ISO 27001 ISMS through annual surveillance audits and continuous improvement\nDrive SOC 2 Type II compliance - scope, control implementation, evidence collection, and auditor engagement\nOwn DORA compliance - ICT risk management, incident classification/reporting, resilience testing, and third-party risk management\nEnsure GDPR compliance for platform data processing; work alongside the DPO\nCustomer Security Assurance\nHandle customer security questionnaires, due diligence requests, and audit evidence packages\nProduce regular security reports for customers and present at governance meetings\nSupport RFP responses with security content\nIncident Response\nOwn the incident response plan - severity levels, escalation, communication, and post-incident review\nAct as incident commander for security-related P1/P2 incidents; deliver RCA within SLA\nCommission and manage annual third-party penetration testing\nPolicy & Governance\nReview and evolve the existing security policy suite to align with ISO 27001, SOC 2, and DORA\nConduct annual security risk assessments and maintain the risk register\nOversee security awareness training and secure coding practices\nWhat We Are Looking For\nMust Have\n8+ years in information security - architecture, engineering, or hands-on security lead roles\nExperience maintaining an ISO 27001 ISMS through certification and surveillance cycles\nWorking knowledge of DORA or similar financial sector ICT risk frameworks\nHands-on AWS security experience - IAM, VPC, KMS, WAF, GuardDuty, or equivalent\nExperience with SIEM tools (Wazuh, Splunk, Sentinel, or similar)\nUnderstanding of application security - OWASP Top 10, API security, OAuth/JWT/SAML\nAbility to communicate security posture to customer executives, auditors, and regulators\nFluent English\nNice to Have\nExperience with SOC 2 Type II audits\nBackground in SaaS companies serving regulated financial institutions\nGDPR practitioner experience\nCertifications: CISSP, CISM, ISO 27001 Lead Auditor, AWS Security Specialty","description_format":"text","description_chars":4094,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services","Financial Software & Embedded Finance"],"lifecycle":[{"event":"open","at":"2026-09-25T13:21:50Z"}],"visa":[],"liveness":{"score":61,"band":"ok","label":"Likely open","p_open":1,"p_active":0.673,"p_room":0.9,"age_days":12,"expected_fill_days":30,"reasons":["conf:12","velocity","win:mid"],"computed_at":"2026-10-03T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/aura-cloud-ab-information-security-architect","json_url":"https://alion.io/job/aura-cloud-ab-information-security-architect.json","meta":{"generated_at":"2026-10-04T01:29:39Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1943,"day_limit":5000,"remaining_today":3057,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}