Posted on: 27/04/2026
Description :
4-6 years in Information Security/AppSec/Data Security with expertise in cloud security (AWS/GCP/Azure), Python scripting, and compliance frameworks (ISO 27001, SOC 2, HIPAA, GDPR)
Own and scale data and application security, build SecDevOps pipelines, manage vulnerability remediation, conduct audits and compliance, enforce secure coding, perform code audits, monitor security events, and handle incident response
Job description :
Want to lead Information Security for a leader in biometrics company which is profitable, growing 4X YoY and with offices in US, EU, ME and SE Asia? Want to learn how to secure super-critical systems at scale? Then this is the job for you.
Ultrahuman | Information Security Engineer
Location : Remote / Bangalore
About the Role :
Ultrahuman is looking for an Information Security Engineer to own and scale our security posture end-to-end. This critical role is responsible for the overall security of our systems, with a core focus on data and application security.
We seek a hands-on engineer who can architect robust security defenses, manage risk, and drive security-focused initiatives across product and engineering teams. This role requires excellent problem-solving ability, a strong ownership mindset, and expertise in creating a secure-by-design environment.
What You will Do :
- Be in charge of data and app security, ensuring comprehensive protection for sensitive user data, intellectual property, and production applications.
- Design, build, and maintain continuous security monitoring and automation pipelines (SecDevOps) to run periodic security scans against infrastructure and application code.
- Review, analyze, and triage the outcomes of security scans, vulnerability assessments, and penetration tests, and manage the remediation lifecycle, especially for critical and high-severity findings.
- Actively help in various audits and compliances (e.g., ISO 27001, GDPR, HIPAA, SOC 2, or other industry standards), ensuring all security controls meet regulatory and contractual protections.
- Introduce and enforce security best practices across all engineering functions, including secure coding standards, data encryption (in transit and at rest), and secure configuration management.
- Perform internal code audits from time to time and security design reviews on core systems to proactively discover hidden vulnerabilities and verify that key security controls are implemented correctly.
- Develop and integrate security controls into the software development lifecycle (SDLC) to prevent security issues from reaching production environments.
- Configure and monitor security log events data, usage anomaly detection, and other telemetry to quickly identify suspicious or unauthorized activity.
- Participate in the security incident response program, contributing to the proactive detection, containment, and analysis of security incidents.
- Evaluate and manage security risks associated with third-party vendors and applications, including conducting security questionnaires and reviewing third-party penetration testing reports.
What Were Looking For :
- 4-6 years of experience in an Information Security, Application Security (AppSec), or Data Security role.
- Proven hands-on experience in implementing security controls for cloud platforms (e.g., AWS, GCP, Azure).
- Strong practical knowledge of at least one scripting language (e.g., Python) for building security tooling and automation.
- Deep expertise in web application security, mobile application security, and common vulnerability frameworks (e.g., OWASP Top 10).
- Experience with compliance frameworks (e.g., ISO 27001, SOC 2, HIPAA, GDPR) and managing audit processes.
- Hands-on experience configuring and analyzing output from security testing tools (SAST, DAST, vulnerability scanners).
- Familiarity with security information and event management (SIEM) systems and leveraging log data for security monitoring.
- Strong ownership mindset and ability to work independently in a fast-paced environment.
Core Skills :
- Information Security, Application Security (AppSec), Cloud Security, Data Security, Security Automation (SecDevOps), Compliance & Auditing, Vulnerability Management, Python, Penetration Testing, IAM/Access Control
Did you find something suspicious?
Posted by
ORANGEMINT TECHNOLOGIES PRIVATE LIMITED
Recruiter at ORANGEMINT TECHNOLOGIES PRIVATE LIMITED
Last Active: 30 Apr 2026
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1631588