Snabbit
Website:
snabbit.com
Job details:
We’re looking for a Information Security Manager
Snabbit is India’s first Quick-Service App delivering home services in just 10 minutes through a hyperlocal network of trained and verified professionals. Backed by top VCs in the country, Snabbit is redefining the home services space by combining speed, quality, and trust.
Founded by Aayush Agarwal, Snabbit is on a mission to make home services as seamless and instant as ordering groceries. We’ve already completed lakhs of jobs with exceptional customer satisfaction - and we’re just getting started.
The Opportunity
We’re looking for an Information Security professional to help build and strengthen Snabbit’s security foundation as we scale.
This role sits at the intersection of Application Security, Information Security, and Security Governance. You’ll work closely with engineering and product teams to make security a part of how we build, while also owning policies, controls, risk management, and compliance. The mandate is to ensure our systems, applications, and processes remain secure as Snabbit grows 10x.
What You’ll Do
- Own Application Security → Build and strengthen application security across our backend, APIs, mobile and web applications.
- Secure the SDLC → Embed security into the development lifecycle through threat modelling, security reviews, secure coding practices, and vulnerability management.
- Find & Fix Risks → Drive application security testing including VAPT, SAST, DAST, SCA, and API security, and work with engineering teams to ensure timely remediation.
- Build the Security Framework → Define and implement information security policies, standards, processes, and controls as Snabbit scales.
- Drive Governance → Own security risk assessments, security controls, audits, compliance requirements, and security documentation.
- Partner with Engineering → Work closely with engineering, product, cloud, and infrastructure teams to identify security risks and build practical solutions.
- Raise the Security Bar → Establish security best practices across applications, infrastructure, access management, data protection, incident response, and third-party risk.
What We’re Looking For
- Strong experience in Application Security / Product Security / Information Security, with hands-on experience securing applications and APIs.
- Deep understanding of OWASP, API security, vulnerability management, threat modelling, secure SDLC, and DevSecOps.
- Experience with application security testing such as SAST, DAST, SCA, VAPT, and penetration testing.
- Strong understanding of Information Security policies, controls, risk management, and governance.
- Familiarity with security frameworks such as ISO 27001, SOC 2, NIST, or equivalent.
- A builder at heart - comfortable creating security processes and policies from the ground up rather than simply maintaining existing ones.
- Strong technical judgement: able to distinguish between theoretical risks and real business impact, and translate security requirements into practical solutions.
- Strong stakeholder management skills, with the ability to influence engineering and product teams without slowing down execution.
Why Snabbit?
- Build security from the ground up: Help shape the security foundation of a rapidly scaling consumer technology company.
- Company-wide impact: Influence how engineering and product teams build secure systems, not just how one application is secured.
- Technical + strategic: Stay close to technology while also owning security governance, policies, and risk.
- Hard problems, early enough: Many of the security challenges required for our next 10x are still ahead of us.
- High ownership: Move quickly, make consequential decisions, and see your work directly translate into a more secure Snabbit.
You’ll Thrive Here If You
You think about security as an enabler, not a blocker. You enjoy getting deep into applications and APIs, but can also step back and build the policies, controls, and processes needed to scale security across an organisation. You’re comfortable working with engineers, challenging assumptions, simplifying complexity, and taking ownership of security from risk identification through remediation.
Click on Apply to know more.