Head-of-Information-Security Organization
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
You report to the Chief Information & Security Officer (CI&SO), and you own the build and run of our security program company wide.
Requirements
- 14+ years in information and cyber security, including 6+ years leading security teams and at least 2 leading managers or principal level engineers. You have owned security for a SaaS product company at scale, building and running it rather than only governing it.
- You have run vulnerability management as an operational discipline at scale, with published SLAs, risk based prioritisation and remediation delivered through engineering. You can talk about aging curves and recurrence rates from memory.
- Direct experience governing machine and non-human identity, and practical command of AI and LLM security risk with real experience applying AI to security operations rather than only defending against it.
- Hands on depth in at least four of: identity and privileged access; endpoint detection and response and detection engineering; cloud security across AWS and Azure; application and product security; secure access service edge and CASB; data protection. You have operated inside a live authorization regime such as FedRAMP, GovRAMP, DoD IL4 or IL5, PCI DSS or HITRUST.
- You have been incident commander for a material security incident, including the executive and customer communication that came with it. You can brief a board or audit committee and hold a technical argument with a staff engineer on the same day, and you have led a global function from an India GCC with genuine accountability rather than delivery support., Amazon Web Services (AWS), Applications Security, Artificial Intelligence (AI), Cloud Computing, Computer Security, Defense in Depth, Establish Priorities, GNU C Compiler, Government, Healthcare, Higher Education, ISO (International Organization for Standardization), Information/Data Security (InfoSec), Internet Security, Memory Hardware, Microsoft Windows Azure, PCI-DSS, Project/Program Management, Risk, Service Level Agreement (SLA), Software as a Service (SaaS), Spatial Data, Team Lead/Manager, United States Department of Defense (DoD), Water Utility
About the company
About Aurigo
Aurigo is an AI-native capital program management platform trusted by over 300 customers managing more than $450 billion in capital programs across North America.With over 40,000 projects delivered, Aurigo helps organizations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence.Recognized as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes.At Aurigo, we don’‘t just build software - we help shape the future of infrastructure., Aurigo builds mission critical AI native SaaS for capital infrastructure and government. Masterworks, Primus, Essentials and our AI product Lumina are trusted with highly regulated public sector and private sector data across four geographies. We hold SOC 1 and SOC 2 Type II, FedRAMP, GovRAMP and ISO 22301, with ISO 42001 close behind. Bangalore is a Global Capability Centre where global functions are owned and held accountable, and this role is one of them.
Aurigo runs a mature, advanced defense in depth posture. This role takes it further: operating it with greater precision, governing an identity and agent population growing faster than any human one, and using AI to defend at the speed our adversaries now attack.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
The Overflow: Security and Privacy
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.