
Lead Security Eng
Keka Technologies Pvt. Ltd · Bengaluru, KA, India
About The Role
About Keka
- Keka HR is one of India's fastest-growing HRTech platforms, trusted by thousands of businesses
- across India, the GCC, and the United States. Built with an employee-first approach, Keka helps
- organizations manage HR, Payroll, Performance, and Employee Experience — seamlessly, at
- scale.
- As Keka scales rapidly across geographies and customer segments, security is a core engineering
- priority — not an afterthought. We are looking for a Lead Security Engineer who will define, build,
- and own Keka's security posture for the next phase of growth.
About the Role
- This is a high-ownership, high-visibility role for a security engineer who operates both as a strategic
- leader and a deeply technical individual contributor. You will lead Keka's security engineering
- function — building and mentoring a team of junior engineers while personally driving critical
- security initiatives across cloud infrastructure, product, and platform.
- The security landscape has changed fundamentally with the rise of AI. We are looking for someone
- who doesn't just understand that shift — but actively builds against it. Whether securing AI-powered
- product features, defending against AI-augmented attacks, or establishing responsible AI usage
- policies within engineering, you'll be defining the playbook.
- The ideal candidate sees security not as a gatekeeping function, but as a force multiplier for
- engineering velocity and customer trust.
Key Responsibilities
- Security Leadership & Strategy
keka · Lead Security Engineer — Job Description
- Own end-to-end security posture across cloud infrastructure, applications, and engineering
platforms — from strategy to hands-on execution.
- Define and drive a multi-year security roadmap aligned with Keka's product and engineering
growth trajectory.
- Act as the primary security advisor to Engineering, Platform, and Product leadership;
influence architecture decisions proactively, not reactively.
- Build, mentor, and grow a team of junior and mid-level security engineers — establishing a
culture of security ownership across the entire engineering org.
- Lead threat modeling, security reviews, and risk assessments across new features and
architectural changes.
- AI-Era Security Practices
- Establish AI security governance: define acceptable use policies for LLMs, Copilot tools, and
agentic systems within engineering workflows.
- Identify and mitigate AI-specific threat vectors — prompt injection, model inversion, training
data poisoning, and adversarial misuse of AI-powered product features.
- Build detection capabilities for AI-augmented attacks: deepfake social engineering, AIgenerated phishing, and automated vulnerability exploitation.
- Evaluate and red-team AI/ML integrations within Keka's product to uncover data leakage,
insecure inference endpoints, and supply chain risks.
- Stay current with the evolving threat landscape driven by AI — proactively update controls,
playbooks, and team readiness accordingly.
- Cloud & Platform Security
- Strengthen and continuously improve cloud security architecture across AWS, GCP, and
Azure environments.
- Design and enforce security controls for large-scale distributed systems, multi-tenant SaaS
architecture, and high-volume databases.
- Implement and mature IAM, network segmentation, secrets management, encryption, and
zero-trust principles.
- Harden container and Kubernetes environments; ensure runtime security, image scanning,
and cluster access controls.
- Drive adoption of Infrastructure-as-Code (IaC) security practices with automated policy
enforcement (OPA, Sentinel, etc.).
- Vulnerability Management & Incident Response
- Lead end-to-end vulnerability assessment and remediation across applications, APIs,
databases, and infrastructure.
- Coordinate and conduct penetration testing; partner with external vendors and drive
remediation with engineering teams.
- Build and own incident response playbooks, runbooks, and post-mortems — ensuring each
incident measurably improves the system.
- Implement and tune SIEM, logging, and alerting pipelines to reduce MTTD and MTTR across
security events.
- Conduct regular security drills, tabletop exercises, and red team scenarios to build team
- muscle memory.
- keka · Lead Security Engineer — Job Description
- DevSecOps & Engineering Partnership
- Embed security natively into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and
container vulnerability checks as first-class gates.
- Partner with Engineering and DevOps to establish secure-by-default development practices
— not security as an afterthought.
- Build developer-facing security tooling, threat model templates, and secure coding playbooks
that scale across squads.
- Drive adoption of software supply chain security practices (SBOM, dependency auditing, build
provenance).
- Champion security as an engineering quality metric — not just a compliance checkbox.
- Compliance & Governance
- Lead and support compliance initiatives for SOC2 Type II, ISO 27001, GDPR, and emerging
data privacy regulations.
- Maintain audit readiness; own security documentation, control mappings, and evidence
collection.
- Support enterprise customer security questionnaires, audits, and trust assessments — acting
as a credible technical voice.
What We're Looking For
Must Have
- ✓ 10+ years in Security Engineering, Cloud Security, or Platform Security — with at least 3
- years in a senior/lead role.
- ✓ Proven experience building and mentoring security teams in startup or high-growth SaaS
- environments.
- ✓ Hands-on depth in IAM, network security, container/Kubernetes security, API security,
- database security, encryption, and secrets management.
- ✓ Strong cloud security experience across AWS, GCP, or Azure — ideally multi-cloud.
- ✓ Experience with security tooling: Nessus, Burp Suite, Qualys, Prisma Cloud, Wiz,
- CrowdStrike, or equivalents.
- ✓ Proficiency in scripting/automation: Python, Bash, or Go — for building detections,
- remediations, and security tooling.
- ✓ Ability to operate both as a strategic people leader and a deeply hands-on individual
- contributor.
- ✓ Strong incident response instincts — you've owned P0 security incidents end-to-end.
- ✓ Excellent stakeholder management and ability to translate technical risk into business impact.
Good to Have
- › Hands-on experience with AI/ML security — LLM threat modeling, agentic pipeline security, or
- adversarial ML.
- keka · Lead Security Engineer — Job Description
- › Experience in HRTech, FinTech, or enterprise SaaS with multi-tenancy and PII at scale.
- › Certifications: CISSP, CCSP, CEH, AWS Security Specialty, or Google Cloud Security.
- › Exposure to building scalable security programs from scratch in lean team environments.
- › Experience with Zero Trust architecture implementation.
- › Familiarity with SOC2 Type II, ISO 27001, GDPR compliance frameworks.
Why Join Keka
- Scale & Impact — Secure infrastructure powering HR for thousands of companies across India,
- GCC, and the US. Your work protects real employee data at scale.
- Build, Don't Just Run — Join early enough to shape security culture, tooling, and team from the
- ground up — not inherit a legacy compliance checklist.
- AI-Native Engineering — Keka is actively embedding AI across its product and engineering
- workflows. You'll be at the frontier of AI security — not catching up to it.
- Engineering-First Culture — Security here is treated as engineering quality — not an obstacle.
- You'll have the trust, access, and influence to get things done right.
- Ready to secure one of India's fastest-growing SaaS
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
