Posted on: 11/09/2026
About EquityList:
EquityList is trusted by 600+ companies to manage their cap table and stock option workflows and compliance. Our comprehensive platform allows customers to manage and administer equity grants - ESOPs, SARs, RSUs, RSAs seamlessly and at scale.
Our customers span APAC, MENA, and the US, including Tata Consumer Products, Taco Bell, Blackbuck, Livspace, Slice, smallcase, Tabby.ai, and Shiprocket - managing equity for 50,000+ stakeholders and stock options worth $3Bn+. We're backed by AngelList India, Hustle Fund, Republic, Unpopular Ventures, Mana Ventures, and a stellar group of angels.
About the Role:
As we deepen our enterprise footprint across regulated markets - onboarding listed companies, fintechs, and compliance-driven clients across three geographies, security has moved from a checkbox to a core trust signal. Clients managing billions in equity on our platform expect us to meet enterprise-grade security standards, and we take that seriously. We're looking for an Information Security Associate who is hands-on, ownership-oriented, and equally comfortable hardening infrastructure and walking a client's CISO through our controls framework. You'll be our first dedicated security hire - which means you own the function, set the baseline, and ensure every enterprise prospect can trust EquityList with their most sensitive equity data.
Ideal Candidate Mindset:
You've been the only security person in a room full of engineers. You've written the first acceptable use policy and found a critical IDOR on the same day. You care about building systems and processes that outlast you, not just passing audits.
Key Responsibilities:
1. Security Operations:
- Own our day-to-day security posture, access controls, endpoint hardening, secrets management, and cloud security hygiene on GCP. Monitor SIEM alerts, investigate incidents, and lead post-incident reviews with written closure reports.
2. Vulnerability Management:
- Conduct periodic internal assessments and coordinate third-party VAPT engagements. Own the remediation tracker and ensure findings don't die in a spreadsheet.
3. Compliance & ISMS:
- Build and maintain our Information Security Management System - policies, risk registers, vendor assessments, and runbooks. Be the person who actually keeps these updated.
4. Certification Readiness:
- Support readiness for ISO 27001, SOC 2 Type II, and GDPR (EU) - maintaining evidence artefacts, coordinating with auditors, and closing gaps proactively.
5. Client-Facing Trust Building:
- Own our Infosec response library for enterprise RFPs, DDQs, and security annexures. Represent EquityList on client InfoSec calls with clarity and confidence.
6. Product and Application Security:
- Work with the engineering team on secure design reviews, threat modelling, and pre-release security checks - bringing security into the SDLC, not just after the fact.
7. Bug Bounty/Responsible disclosure programs:
- Take ownership of initiating and managing bug bounty programs.
8. Cross-functional Collaboration:
- Partner with Product, Compliance, and Business teams to translate security requirements into practical, executable controls without becoming a blocker.
Requirements:
Technical:
- 2 - 3 years in an InfoSec, security engineering, or GRC + technical hybrid role. Ideally, at a SaaS or fintech company.
- Working knowledge of GCP security - IAM, VPC service controls, Cloud Armor, Security Command Center, Cloud Logging, and alerting.
- Familiarity with OWASP Top 10, common vulnerability classes, and the ability to triage scanner output.
- Experience writing security policies, ISMS documentation, and risk registers - not just reading templates.
- Scripting ability (Python or Bash) for automating checks or log analysis is a plus.
Soft Skills:
- Strong written communication, you can translate technical risk into plain language for a founder, a CFO, or a client's legal team.
- Documentation-first mindset, you close loops and keep records clean without being reminded.
- Startup-ready, comfortable with ambiguity, proactive about gaps, and able to wear multiple hats.
Education:
- B.E. / B.Tech in Computer Science, IT, or related field - or equivalent practical experience.
- CompTIA Security+, CEH, or Google's Professional Cloud Security Engineer certification is a plus.
Good to Have:
- Hands-on involvement in ISO 27001 implementation or audit support.
- SOC 2 Type II readiness experience.
- VAPT coordination with third-party vendors.
- Awareness of India's DPDP Act and IT Act obligations.
- Prior experience at a B2B SaaS or fintech startup.
- Hands-on experience with DLP, MDM, or SIEM tooling.
- Build from scratch: You're EquityList's first security hire, you write the playbook, choose the tools, and define what security culture looks like here. No bureaucracy, full ownership.
- Work at the intersection of security and growth: At our stage, security directly enables revenue. You'll co-own enterprise onboarding conversations, influence product architecture, and build relationships with CISOs and CFOs at India's fastest-growing companies.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1670810