Website:
dreamcast.in
Job details:
What We're Looking For
- AI Engineering: Hands-on experience with modern AI/ML frameworks and LLMs. Proficient in building AI-powered solutions, writing production-quality code, developing automation pipelines, and leveraging AI to improve security operations and engineering productivity.
- Compliance & Governance: Strong understanding of ISO 27001, SOC 2, and the DPDP Act, with practical experience implementing security controls, maintaining compliance evidence, supporting audits, and translating compliance requirements into operational processes.
- Security Engineering: Solid experience securing cloud environments (AWS, Azure, or GCP), identity and access management (IAM), application security, infrastructure security, and DevSecOps practices. Able to design and implement security controls rather than only recommend them.
- Offensive Security: Hands-on experience with Vulnerability Assessment and Penetration Testing (VAPT), red teaming, reconnaissance, exploitation, and post-exploitation techniques. Ability to identify security weaknesses and provide practical remediation recommendations.
- Security Automation: Proficient in automating security operations using Python, Bash, PowerShell, Infrastructure as Code (Terraform), CI/CD pipelines, or AI-powered security tooling.
- Ownership & Problem Solving: Self-driven professional who thrives in fast-paced startup environments, takes end-to-end ownership of security initiatives, and can execute effectively with minimal supervision.
- Communication: Excellent verbal and written communication skills with the ability to collaborate with engineering, product, legal, and leadership teams while clearly communicating technical concepts to non-technical stakeholders.
Nice to Have
- Professional certifications such as OSCP, CISSP, CEH, ISO 27001 Lead Implementer/Lead Auditor, AWS Security Specialty, or Azure Security Engineer (AZ-500).
- Experience leading or supporting an organization's first SOC 2 Type I/II or ISO 27001 certification journey.
- Experience working in an early-stage startup or building a security function from the ground up.
- Hands-on experience securing AI/LLM applications, agentic AI systems, and implementing controls against LLM-specific threats such as prompt injection, data leakage, and model abuse.
- Familiarity with security monitoring, SIEM solutions, incident response, threat modeling, and cloud-native security tools.
Why This Role
- Real ownership — you build and run the security function, set the standards, and leave a lasting mark.
- Direct mentorship from an experienced Virtual CISO, with the autonomy to execute your own way.
- A rare blend of building, automating, defending, and attacking — no two weeks look the same.
- High-trust, high-impact, high-visibility work at a company that takes security seriously from day one.
Skills: data privacy & data governance,ai/ml,llm security,cloud security (aws / azure / gcp),dpdp act compliance,soc 2,soc 2 compliance,penetration testing,iso 27001,security controls implementation,ai engineering,infrastructure security,security automation,ai security,security architecture,application security,devsecops,python,infrastructure as code (terraform)
Click on Apply to know more.