825,970open jobs
53,207companies
135,769added this week
Browse all
Salary
≈ $51k – $105k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Architect · 14+ years exp

First seen by Alion on Aug 21, 2026.

Overview
Company
Impact
Profile match

About the job:

About Aurigo:

Aurigo is an AI-native capital program management platform trusted by over 300 customers managing more than $450 billion in capital programs across North America.

With over 40,000 projects delivered, Aurigo helps organisations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence.

Recognised as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes.

At Aurigo, we don't just build software we help shape the future of infrastructure.

Why this role, and why now:

You report to the Chief Information & Security Officer (CI&SO), and you own the build and run of our security program company wide.

Aurigo builds mission critical AI native SaaS for capital infrastructure and government.

Masterworks, Primus, Essentials and our AI product Lumina are trusted with highly regulated public sector and private sector data across four geographies.

We hold SOC 1 and SOC 2 Type II, FedRAMP, GovRAMP and ISO 22301, with ISO 42001 close behind.

Bangalore is a Global Capability Centre where global functions are owned and held accountable, and this role is one of them.

Aurigo runs a mature, advanced defense in depth posture.

This role takes it further: operating it with greater precision, governing an identity and agent population growing faster than any human one, and using AI to defend at the speed our adversaries now attack.

What you own:

Vulnerability operations:

- Own vulnerability management as one operational discipline across product code, dependencies, containers, cloud, endpoints and SaaS.

- One view, one queue, one owner, with remediation driven through engineering rather than tickets handed across a wall.

- Prioritize on real risk rather than raw CVSS: exploitability, reachability in our code paths, asset criticality and threat intelligence.

- Hold published SLAs by severity and measure recurrence as well as closure.

- Own the technical execution of continuous monitoring under FedRAMP and GovRAMP: authenticated scanning, POA&M delivery, deviation requests and significant change security review.

AI and agent security governance:

- Own security governance for AI company wide: an enterprise LLM assistant for all staff, a low code automation platform, and team built agents.

- Mandatory agent registry and security intake, every agent carrying a named owner, risk tier and approved scope.

- Nothing reaches production unreviewed.

- Treat agents as first class identities: least privilege credentials under privileged access management, full audit trail, tested kill switches, human in the loop on privileged actions.

- Vet third party AI services for data residency, sub processors and training data handling.

- Extend adversarial AI testing across the portfolio for prompt injection, data exfiltration and agent abuse, aligned to the OWASP Top 10 for LLMs, MITRE ATLAS, ISO 42001 and the NIST AI RMF.

- Put AI to work on defense too, through agentic triage and automated evidence collection, so the function scales on output per engineer rather than headcount.

Identity, endpoint and threat defense:

- Own identity security across both populations, with non human identity the larger and faster growing: service accounts, machine identities, keys, tokens, certificates, workload identities and agents, each with a named human owner, vaulted and automatically rotated credentials, and least privilege scope enforced through the full lifecycle including deprovisioning.

- Own identity threat detection and response, phishing resistant multi factor authentication, endpoint security across a mixed Windows and macOS fleet, detection engineering and the virtual SOC partnership, measured on coverage mapped to ATT&CK and on response time rather than ticket volume.

Product security, cloud and data:

- Own product security across Masterworks, Primus, Essentials and Lumina, supporting roughly 250 engineers: threat modelling, SAST, DAST and SCA gated in CI, secrets scanning, SBOM, code signing, guardrails on AI coding assistants, penetration test and bug bounty remediation as a tracked programme, and a security champions model so security moves at the pace of engineering.

- Own runtime cloud posture across AWS and Azure, SaaS posture across the corporate estate, and data security engineering: classification, data loss prevention, encryption and key management, control over how regulated data moves into and out of AI systems, and the engineering controls behind Indias DPDP Act and US state privacy obligations.

Incident response, platform and team:

- Serve as Incident Commander for Sev1.

- Own the severity model, escalation, on call structure and forensics retainer, our ability to meet the FedRAMP one hour window, the CERT-In six hour directive and customer contractual clocks, and an exercise program of tabletops across all four geographies plus a full scope live test each year.

- Lead consolidation onto fewer platforms and own vendor strategy and commercial negotiation.

- Lead and grow the security engineering organization covering SOC, detection, application security, cloud and offensive testing, with funded headcount growth.

- Report posture, risk and roadmap to the CI&SO and the executive leadership team, with defined escalation to the Audit Committee.

Certifications: where your accountability sits:

- GRC owns the certification.

- You own the controls it rests on.

- GRC owns authorization packages, the System Security Plan, 3PAO and agency relationships, the audit calendar, policy, privacy and third party risk.

- You own what every certification rests on: that technical controls are implemented, effective, continuously monitored and evidenced as a byproduct of how we operate.

- If a certification is ever at risk because a control failed or evidence was missing, that is yours.

- If it is because a policy or authorization artefact was wrong, that is GRCs.

What you bring:

Required:

- 14+ years in information and cyber security, including 6+ years leading security teams and at least 2 leading managers or principal level engineers.

- You have owned security for a SaaS product company at scale, building and running it rather than only governing it.

- You have run vulnerability management as an operational discipline at scale, with published SLAs, risk based prioritisation and remediation delivered through engineering.

- You can talk about aging curves and recurrence rates from memory.

- Direct experience governing machine and non-human identity, and practical command of AI and LLM security risk with real experience applying AI to security operations rather than only defending against it.

- Hands on depth in at least four of: identity and privileged access; endpoint detection and response and detection engineering; cloud security across AWS and Azure; application and product security; secure access service edge and CASB; data protection.

- You have operated inside a live authorization regime such as FedRAMP, GovRAMP, DoD IL4 or IL5, PCI DSS or HITRUST.

- You have been incident commander for a material security incident, including the executive and customer communication that came with it.

- You can brief a board or audit committee and hold a technical argument with a staff engineer on the same day, and you have led a global function from an India GCC with genuine accountability rather than delivery support.

Preferred:

- Security leadership for SaaS in government or otherwise regulated markets.

- CISSP, CISM, CCSP or senior cloud provider credentials.

- Experience building agentic security workflows.

- Vendor consolidation and negotiation at seven figure scale.

Aurigo Software Technologies is an Equal Opportunity Employer.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable law.

Skills

Information Security, IT Security, IT Risk Management, IT Controls, Chief Information Security Officer

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
825,970 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Leadership
Similar stack
Same company
Bengaluru
≈ $41k – $85k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • India
Frontend
WebAssembly
DevOps
Cloudflare
Fastly
Akamai
Apply
≈ $35k – $87k per year (Estimated) • In office • Full-Time • Bangkok
DevOps
SLI/SLO/SLA
Apply
IT Project Manager 3 months ago
In office • Full-Time • 3+ years exp • Bachelor's Degree • Bangkok
Management
Agile
Apply
IT Infra Team Lead 5 days ago
≈ $34k – $83k per year (Estimated) • In office • Full-Time • Samut Sakhon
DevOps
VMWare
Azure
AWS
Hyper-V
Linux
Windows
VPN
Cybersecurity
ISO 27001
Apply
IT Project Manager 23 days ago
In office • Full-Time • 2+ years exp • Bachelor's Degree • Tczew
Management
Agile
ITIL
Apply
In office • 5+ years exp • Bengaluru
Databases
Weaviate
Pinecone
FAISS
OpenSearch
AI/ML
LangGraph
AutoGen
LangChain
Claude
Stable Diffusion
LoRA
Fine-tuning
Embeddings
Prompt Engineering
Multimodal AI
AI Agents
Midjourney
PEFT
Semantic Kernel
Veo
Llama
Mistral
CrewAI
Gemini
LLM
RAG
Runway
Pika
Google ADK
Hallucination
Text-to-Speech
DevOps
GCP
Azure
AWS
Apply
In office • 10+ years exp • Bachelor's Degree • Cambridge
AI/ML
Copilot
AI Agents
LLM
OpenAI Codex
DevOps
GCP
CI/CD
AWS
Platform Engineering
Apply
≈ $67k – $168k per year (Estimated) • In office • Full-Time • Dubai
Python
Python
FastAPI
Databases
PostgreSQL
Redis
Milvus
Qdrant
AI/ML
LangGraph
LangChain
vLLM
Embeddings
AI Agents
SGLang
Langfuse
LangSmith
Ollama
LLM
RAG
Hugging Face
LLMOps
KV Cache
DevOps
Helm
GitHub Actions
OpenTelemetry
Prometheus
CI/CD
AWS
Docker
Kubernetes
Grafana
Platform Engineering
Amazon EKS
Apply
Solutions Architect 2 days ago
In office • 5+ years exp • Bachelor's Degree • Bengaluru
AI/ML
AI Agents
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Apply
In office • 8+ years exp • Bengaluru
Python
JavaScript
Node JS
Frontend
Webpack
Three.JS
React.js
DevOps
GCP
Datadog
Azure
CI/CD
AWS
Docker
Grafana
QA
Cypress
Jest
Sentry
Apply
≈ $37k – $88k per year (Estimated) • In office • 12+ years exp • Bengaluru
Apply
≈ $51k – $105k per year (Estimated) • In office • 12+ years exp • Master's Degree • Bengaluru
Databases
Snowflake
Databricks
AI/ML
AI Agents
DevOps
Terraform
Azure
CI/CD
AWS
Analytics
Informatica
Apply
≈ $168k – $313k per year (Estimated) • In office • Bachelor's Degree • Bengaluru
Python
DevOps
Linux
Game Dev
Houdini
Design
Maya
Apply
≈ $28k – $79k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru
DevOps
Azure
AWS
Cloudflare
SLI/SLO/SLA
DNS
DHCP
VPN
BGP
OSPF
Cybersecurity
Zero Trust
Management
ITIL
Apply
In office • Full-Time • Bengaluru
Databases
SAP HANA
Management
ITIL
Apply
≈ $30k – $80k per year (Estimated) • In office • Bengaluru
Apply
See all jobs
This is one of many
825,970 more open roles from verified company boards, updated every day.