Arcana Analytics
Posted 1y ago

Lead Security Engineer

Arcana Analytics
India
HybridFull Time
Responsibilities
  • enforcing policy
  • building guardrails
  • hardening infrastructure
Requirements
  • 5+ years in security/compliance for cloud-native
  • Fintech, and hybrid setups
  • Strong GCP and Kubernetes security
  • IaC (Terraform)
  • GitOps
  • Python
  • Policy-as-code
  • Strong communicator
Technical tools mentioned
TerraformArgoCDFluxPythonOPAGatekeeperGCPKubernetesKMSVPC

Job description

 

As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden infrastructure end-to-end. While your primary focus will be on our GCP resources, you'll also partner with teams across networking, applications, and compliance to ensure we're secure by design and resistant to drift.

Responsibilities:

  • Enterprise Security Architecture - Governance and Compliance, including driving adherence to ISO 27001, SOC 2, GDPR, and enforcing CIS benchmarks on all infrastructure.
  • Policy, Automation, and Guardrails - own the end-to-end security lifecycle by defining policy-as-code, embedding continuous compliance checks into CI/CD, and building automated, drift-resistant guardrails across cloud, containers, and VMs.
  • Infrastructure Hardening and Drift Detection - implement automated drift alerts and self-healing playbooks for VPCs, firewall rules, Kubernetes clusters, and endpoints.
  • Monitoring, Logging, and Incident Response - configure Cloud Audit Logs, SIEM exports, and custom alerts for critical security events; lead root-cause investigations, build detection logic, and develop runbooks for cloud-wide incidents.

Requirements:

  • 5+ years driving security and compliance in dynamic, regulated environments- securing cloud-native platforms and hybrid infrastructures, with deep familiarity in fintech and portfolio-management standards, and best practices for supporting distributed, remote teams.
  • Deep expertise with GCP security (IAM, KMS, VPC Service Controls, Cloud Logging/Audit, WAF, SecOps) and Kubernetes application hardening.
  • Strong Infrastructure-as-Code skills (Terraform or equivalent) and GitOps experience (ArgoCD, Flux).
  • Proficiency in Python scripting and policy-as-code frameworks (OPA, Gatekeeper).
  • Excellent communicator - able to translate technical findings into clear policies and remediation plans.

Helpful Experience:

  • Familiarity with multi-cloud security controls.
  • Security certifications (GCP Professional Security Engineer, CISSP, CKA/CKS).
  • Experience with service mesh (Istio/Anthos) or zero-trust architectures.

 

About Arcana Analytics

Platform for institutional portfolio risk and investment performance analytics.

Year founded
2022
Employees
130
Organization type
Private
Latest investment
Raised $10.40M Series A (2025) — led by Positive Sum, Abstract Ventures
Headquarters
US

Similar jobs

Lead Security Engineer roles
5mo
Save
Mark Applied
Hide
Lead Security Engineer
Bangalore, Karnataka, India
HybridFull Time
Huron
HuronNasdaq: HURN: Professional services firm providing management consulting and digital transformation.
Lead security engineer with expertise in AppSec, vulnerability management, and penetration testing using Tenable; guide secure coding and remediation.
Tenable, Burp Suite, OWASP ZAP, Nmap, Metasploit, Python, Bash, PowerShell
5mo
Save
Mark Applied
Hide
Lead Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
Amtech Software
Amtech Software: Provides integrated enterprise software for packaging and manufacturing industries.
10+ YOE8-12 years in security engineering; 5+ years securing AWS; IAM, encryption, logging; SOC 2/ISO 27001 experience; scripting and IaC.
AWS, SIEM, EDR, Vulnerability Scanners, CSPM, Terraform
7mo
Save
Mark Applied
Hide
Lead Security Engineer - Secure Web Gateway
Mumbai or Hyderabad or Chennai or Bengaluru
OnsiteFull Time
IDFC First Bank
IDFC First BankNational Stock Exchange of India / BSE Limited: IDFCFIRSTB / 539437: Provides universal banking and financial services to individuals and businesses.
10+ YOESenior Network Security Engineer with 10+ years experience in Secure Web Gateway, SWG policies, and banking security standards.
Netskope, SIEM, Secure Web Gateway, HTTP/HTTPS, SSL/TLS inspection, DNS, Web traffic analysis, DLP, SaaS security, IaaS security, PaaS security, ISO 27001, NIST, GDPR, Firewall, ZTNA, SASE, SSE, Identity providers
5mo
Save
Mark Applied
Hide
Lead Cloud Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
InMobi
InMobi: Mobile advertising and AI-powered content discovery platform.
4+ YOE4-6 years in cloud security; hands-on Azure/AWS/GCP; Kubernetes, containers; CSPM; vulnerability and risk management; CI/CD security; infra as code; strong communication.
Terraform, Kubernetes, Docker, Cloud Providers (Azure AWS GCP), CSPM, GKE, EKS, AKS, OpenID, OAuth, TLS, CI/CD, Network security
2y
Save
Mark Applied
Hide
Lead Product Security Engineer
Bangalore, Karnataka, India
OnsiteFull Time
Applause
Applause: Digital quality assurance and crowdtesting for software products.
8+ YOE8+ years in software security; strong C/C++, Linux, networking; SSDLC leadership; vulnerability analysis; threat modeling; root cause analysis.
C, C++, Linux, GDB, Makefile, Networking, TCP/IP, HTTP/S, DNS, OSCP, OSCE, GPEN, CRTP
2y
Save
Mark Applied
Hide
Lead Product Security Engineer
Bangalore, Karnataka, India
OnsiteFull Time
Cloud Software Group
Cloud Software Group: Provides enterprise software for virtualization, networking, and data analytics.
8+ YOE8+ years in software security; expert in Unix systems, networks, cryptography; strong C/C++; Linux; networking; OS vulnerabilities; SSDLC; threat modeling; debugging; exploit writing.
GDB, Core dump analysis, Makefile, AFL, Peach, Coverity
3mo
Save
Mark Applied
Hide
Cyber Security Software Development Lead Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
BorgWarner
BorgWarnerNYSE: BWA: Manufactures propulsion systems and components for combustion and electric vehicles.
7+ YOE7-9 years automotive embedded software with 5+ years in automotive cybersecurity; expertise in automotive cybersecurity architecture; strong C/C++ in embedded systems; AUTOSAR; HSM; ISO/SAE 21434; UN R155/156; ASPICE.
C/C++, AUTOSAR, Vector DaVinci, EB Tresos, Jira, Polarion, ISO/SAE 21434, ASPICE, HSM, Secure Boot, Secure Diagnostics, Secure OTA, Secure Tokens