Arcana
Website:
arcana.io
Company:
https://www.linkedin.com/company/arcanaanalytics
Industries: Technology, Information and Internet
Job details:
Head of Security
Location: Bangalore (Hybrid)
As our Head of Security, you'll define and lead Arcana's overall security strategy across infrastructure, applications, cloud, and enterprise systems. You'll build and scale the security function, establish security-by-design principles across engineering, and ensure our platform remains resilient as we grow. While your primary focus will be on securing our GCP infrastructure and production environments, you'll partner closely with Engineering, Product, IT, and Leadership to balance security, compliance, and engineering velocity.
Responsibilities:
- Own Arcana's end-to-end security strategy across cloud, infrastructure, applications, corporate systems, and data.
- Build and lead the company's security roadmap while establishing a strong security culture across engineering and the organization.
- Drive enterprise security governance and compliance, including ISO 27001, SOC 2, GDPR, and customer security requirements.
- Define and enforce security policies, standards, and controls across cloud infrastructure, applications, endpoints, and corporate environments.
- Lead cloud security initiatives across GCP, Kubernetes, networking, IAM, KMS, VPC Service Controls, Cloud Logging/Audit, and WAF.
- Build security guardrails using Infrastructure-as-Code, policy-as-code, and continuous compliance integrated into CI/CD pipelines.
- Oversee infrastructure hardening, vulnerability management, threat detection, incident response, and disaster recovery readiness.
- Establish security checkpoints and threat modeling processes for all new products, services, and architectural changes.
- Lead application security initiatives, including secure SDLC, code security, secrets management, software supply chain security, and penetration testing.
- Build and manage security monitoring, SIEM, detection engineering, incident response playbooks, and post-incident reviews.
- Partner with executive leadership to communicate security risks, investment priorities, and overall security posture.
- Build, mentor, and scale a high-performing security team while fostering a security-first mindset across the company.
Requirements:
- 12+ years of experience leading security programs for cloud-native platforms in high-growth or regulated environments.
- Proven experience building and scaling security teams and driving organization-wide security initiatives.
- Deep expertise in GCP security (IAM, KMS, VPC Service Controls, Cloud Logging/Audit, WAF, SecOps) and Kubernetes security.
- Strong knowledge of application security, DevSecOps, infrastructure security, and secure software development practices.
- Hands-on experience with Infrastructure-as-Code (Terraform or equivalent), GitOps (ArgoCD, Flux), and policy-as-code frameworks (OPA, Gatekeeper).
- Strong understanding of security operations, incident response, vulnerability management, SIEM platforms, and threat detection.
- Experience implementing and maintaining ISO 27001, SOC 2, GDPR, and other security compliance frameworks.
- Proficiency in Python or Go for automation and security tooling.
- Excellent communication and leadership skills with the ability to influence engineering teams and executive stakeholders.
Helpful Experience:
- Experience leading security in fintech, financial infrastructure, or highly regulated industries.
- Familiarity with multi-cloud security architectures and Zero Trust principles.
- Experience with service mesh technologies (Istio/Anthos) and confidential computing.
- Security certifications such as CISSP, GCP Professional Cloud Security Engineer, CISM, or CKA/CKS.
Click on Apply to know more.