HamburgerMenu
hirist

E-List Technologies - Information Security Associate - Vulnerability Management

EquityList
2 - 3 Years
Multiple Locations

Posted on: 11/09/2026

Job Description

About EquityList:

EquityList is trusted by 600+ companies to manage their cap table and stock option workflows and compliance. Our comprehensive platform allows customers to manage and administer equity grants - ESOPs, SARs, RSUs, RSAs seamlessly and at scale.

Our customers span APAC, MENA, and the US, including Tata Consumer Products, Taco Bell, Blackbuck, Livspace, Slice, smallcase, Tabby.ai, and Shiprocket - managing equity for 50,000+ stakeholders and stock options worth $3Bn+. We're backed by AngelList India, Hustle Fund, Republic, Unpopular Ventures, Mana Ventures, and a stellar group of angels.

About the Role:

As we deepen our enterprise footprint across regulated markets - onboarding listed companies, fintechs, and compliance-driven clients across three geographies, security has moved from a checkbox to a core trust signal. Clients managing billions in equity on our platform expect us to meet enterprise-grade security standards, and we take that seriously. We're looking for an Information Security Associate who is hands-on, ownership-oriented, and equally comfortable hardening infrastructure and walking a client's CISO through our controls framework. You'll be our first dedicated security hire - which means you own the function, set the baseline, and ensure every enterprise prospect can trust EquityList with their most sensitive equity data.

Ideal Candidate Mindset:

You've been the only security person in a room full of engineers. You've written the first acceptable use policy and found a critical IDOR on the same day. You care about building systems and processes that outlast you, not just passing audits.

Key Responsibilities:

1. Security Operations:

- Own our day-to-day security posture, access controls, endpoint hardening, secrets management, and cloud security hygiene on GCP. Monitor SIEM alerts, investigate incidents, and lead post-incident reviews with written closure reports.

2. Vulnerability Management:

- Conduct periodic internal assessments and coordinate third-party VAPT engagements. Own the remediation tracker and ensure findings don't die in a spreadsheet.

3. Compliance & ISMS:

- Build and maintain our Information Security Management System - policies, risk registers, vendor assessments, and runbooks. Be the person who actually keeps these updated.

4. Certification Readiness:

- Support readiness for ISO 27001, SOC 2 Type II, and GDPR (EU) - maintaining evidence artefacts, coordinating with auditors, and closing gaps proactively.

5. Client-Facing Trust Building:

- Own our Infosec response library for enterprise RFPs, DDQs, and security annexures. Represent EquityList on client InfoSec calls with clarity and confidence.

6. Product and Application Security:

- Work with the engineering team on secure design reviews, threat modelling, and pre-release security checks - bringing security into the SDLC, not just after the fact.

7. Bug Bounty/Responsible disclosure programs:

- Take ownership of initiating and managing bug bounty programs.

8. Cross-functional Collaboration:

- Partner with Product, Compliance, and Business teams to translate security requirements into practical, executable controls without becoming a blocker.

Requirements:

Technical:

- 2 - 3 years in an InfoSec, security engineering, or GRC + technical hybrid role. Ideally, at a SaaS or fintech company.

- Working knowledge of GCP security - IAM, VPC service controls, Cloud Armor, Security Command Center, Cloud Logging, and alerting.

- Familiarity with OWASP Top 10, common vulnerability classes, and the ability to triage scanner output.

- Experience writing security policies, ISMS documentation, and risk registers - not just reading templates.

- Scripting ability (Python or Bash) for automating checks or log analysis is a plus.

Soft Skills:

- Strong written communication, you can translate technical risk into plain language for a founder, a CFO, or a client's legal team.

- Documentation-first mindset, you close loops and keep records clean without being reminded.

- Startup-ready, comfortable with ambiguity, proactive about gaps, and able to wear multiple hats.

Education:

- B.E. / B.Tech in Computer Science, IT, or related field - or equivalent practical experience.

- CompTIA Security+, CEH, or Google's Professional Cloud Security Engineer certification is a plus.

Good to Have:

- Hands-on involvement in ISO 27001 implementation or audit support.

- SOC 2 Type II readiness experience.

- VAPT coordination with third-party vendors.

- Awareness of India's DPDP Act and IT Act obligations.

- Prior experience at a B2B SaaS or fintech startup.

- Hands-on experience with DLP, MDM, or SIEM tooling.

- Build from scratch: You're EquityList's first security hire, you write the playbook, choose the tools, and define what security culture looks like here. No bureaucracy, full ownership.

- Work at the intersection of security and growth: At our stage, security directly enables revenue. You'll co-own enterprise onboarding conversations, influence product architecture, and build relationships with CISOs and CFOs at India's fastest-growing companies.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...