Skip to content
← Back to job listings

Lead Security Eng

Keka Technologies Pvt. Ltd · Bengaluru, KA, India

Imported listingfull-time8 days ago

About The Role

About Keka

  • Keka HR is one of India's fastest-growing HRTech platforms, trusted by thousands of businesses
  • across India, the GCC, and the United States. Built with an employee-first approach, Keka helps
  • organizations manage HR, Payroll, Performance, and Employee Experience — seamlessly, at
  • scale.
  • As Keka scales rapidly across geographies and customer segments, security is a core engineering
  • priority — not an afterthought. We are looking for a Lead Security Engineer who will define, build,
  • and own Keka's security posture for the next phase of growth.

About the Role

  • This is a high-ownership, high-visibility role for a security engineer who operates both as a strategic
  • leader and a deeply technical individual contributor. You will lead Keka's security engineering
  • function — building and mentoring a team of junior engineers while personally driving critical
  • security initiatives across cloud infrastructure, product, and platform.
  • The security landscape has changed fundamentally with the rise of AI. We are looking for someone
  • who doesn't just understand that shift — but actively builds against it. Whether securing AI-powered
  • product features, defending against AI-augmented attacks, or establishing responsible AI usage
  • policies within engineering, you'll be defining the playbook.
  • The ideal candidate sees security not as a gatekeeping function, but as a force multiplier for
  • engineering velocity and customer trust.

Key Responsibilities

  1. Security Leadership & Strategy

keka · Lead Security Engineer — Job Description

  • Own end-to-end security posture across cloud infrastructure, applications, and engineering

platforms — from strategy to hands-on execution.

  • Define and drive a multi-year security roadmap aligned with Keka's product and engineering

growth trajectory.

  • Act as the primary security advisor to Engineering, Platform, and Product leadership;

influence architecture decisions proactively, not reactively.

  • Build, mentor, and grow a team of junior and mid-level security engineers — establishing a

culture of security ownership across the entire engineering org.

  • Lead threat modeling, security reviews, and risk assessments across new features and

architectural changes.

  1. AI-Era Security Practices
  • Establish AI security governance: define acceptable use policies for LLMs, Copilot tools, and

agentic systems within engineering workflows.

  • Identify and mitigate AI-specific threat vectors — prompt injection, model inversion, training

data poisoning, and adversarial misuse of AI-powered product features.

  • Build detection capabilities for AI-augmented attacks: deepfake social engineering, AIgenerated phishing, and automated vulnerability exploitation.
  • Evaluate and red-team AI/ML integrations within Keka's product to uncover data leakage,

insecure inference endpoints, and supply chain risks.

  • Stay current with the evolving threat landscape driven by AI — proactively update controls,

playbooks, and team readiness accordingly.

  1. Cloud & Platform Security
  • Strengthen and continuously improve cloud security architecture across AWS, GCP, and

Azure environments.

  • Design and enforce security controls for large-scale distributed systems, multi-tenant SaaS

architecture, and high-volume databases.

  • Implement and mature IAM, network segmentation, secrets management, encryption, and

zero-trust principles.

  • Harden container and Kubernetes environments; ensure runtime security, image scanning,

and cluster access controls.

  • Drive adoption of Infrastructure-as-Code (IaC) security practices with automated policy

enforcement (OPA, Sentinel, etc.).

  1. Vulnerability Management & Incident Response
  • Lead end-to-end vulnerability assessment and remediation across applications, APIs,

databases, and infrastructure.

  • Coordinate and conduct penetration testing; partner with external vendors and drive

remediation with engineering teams.

  • Build and own incident response playbooks, runbooks, and post-mortems — ensuring each

incident measurably improves the system.

  • Implement and tune SIEM, logging, and alerting pipelines to reduce MTTD and MTTR across

security events.

  • Conduct regular security drills, tabletop exercises, and red team scenarios to build team
  • muscle memory.
  • keka · Lead Security Engineer — Job Description
  1. DevSecOps & Engineering Partnership
  • Embed security natively into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and

container vulnerability checks as first-class gates.

  • Partner with Engineering and DevOps to establish secure-by-default development practices

— not security as an afterthought.

  • Build developer-facing security tooling, threat model templates, and secure coding playbooks

that scale across squads.

  • Drive adoption of software supply chain security practices (SBOM, dependency auditing, build

provenance).

  • Champion security as an engineering quality metric — not just a compliance checkbox.
  1. Compliance & Governance
  • Lead and support compliance initiatives for SOC2 Type II, ISO 27001, GDPR, and emerging

data privacy regulations.

  • Maintain audit readiness; own security documentation, control mappings, and evidence

collection.

  • Support enterprise customer security questionnaires, audits, and trust assessments — acting

as a credible technical voice.

What We're Looking For

Must Have

  • ✓ 10+ years in Security Engineering, Cloud Security, or Platform Security — with at least 3
  • years in a senior/lead role.
  • ✓ Proven experience building and mentoring security teams in startup or high-growth SaaS
  • environments.
  • ✓ Hands-on depth in IAM, network security, container/Kubernetes security, API security,
  • database security, encryption, and secrets management.
  • ✓ Strong cloud security experience across AWS, GCP, or Azure — ideally multi-cloud.
  • ✓ Experience with security tooling: Nessus, Burp Suite, Qualys, Prisma Cloud, Wiz,
  • CrowdStrike, or equivalents.
  • ✓ Proficiency in scripting/automation: Python, Bash, or Go — for building detections,
  • remediations, and security tooling.
  • ✓ Ability to operate both as a strategic people leader and a deeply hands-on individual
  • contributor.
  • ✓ Strong incident response instincts — you've owned P0 security incidents end-to-end.
  • ✓ Excellent stakeholder management and ability to translate technical risk into business impact.

Good to Have

  • › Hands-on experience with AI/ML security — LLM threat modeling, agentic pipeline security, or
  • adversarial ML.
  • keka · Lead Security Engineer — Job Description
  • › Experience in HRTech, FinTech, or enterprise SaaS with multi-tenancy and PII at scale.
  • › Certifications: CISSP, CCSP, CEH, AWS Security Specialty, or Google Cloud Security.
  • › Exposure to building scalable security programs from scratch in lean team environments.
  • › Experience with Zero Trust architecture implementation.
  • › Familiarity with SOC2 Type II, ISO 27001, GDPR compliance frameworks.

Why Join Keka

  • Scale & Impact — Secure infrastructure powering HR for thousands of companies across India,
  • GCC, and the US. Your work protects real employee data at scale.
  • Build, Don't Just Run — Join early enough to shape security culture, tooling, and team from the
  • ground up — not inherit a legacy compliance checklist.
  • AI-Native Engineering — Keka is actively embedding AI across its product and engineering
  • workflows. You'll be at the frontier of AI security — not catching up to it.
  • Engineering-First Culture — Security here is treated as engineering quality — not an obstacle.
  • You'll have the trust, access, and influence to get things done right.
  • Ready to secure one of India's fastest-growing SaaS

This is an external listing. JobSpring does not represent or verify the employer. Report this listing