- Technical Leadership: Lead a team of 4 senior security engineers — setting technical direction, reviewing code, owning architecture decisions, and ensuring every engineer grows in both traditional InfoSec depth and agentic AI engineering capability.
- Automated Security Platform: Own the design, deployment, and ongoing evolution of our intelligent security response platform — a Python-based, AI-driven pipeline that automates vulnerability discovery, contextual triage, reasoning, and graduated remediation across our full product estate.
- Autonomy Policy & Governance: Define and own the graduated automation policy — what the platform may execute automatically, what requires human approval, and what constitutes a break-glass escalation. You hold the senior technical authority for automated remediation decisions.
- Global InfoSec Interlock: Operate as the primary technical representative of the Bengaluru security engineering team in global InfoSec forums — owning the security posture reporting, KPI tracking (MTTA, SAST coverage, remediation velocity), and executive-level updates.
- InfoSec Transformation: Lead the progressive transition from reactive, manual vulnerability management to a proactive, automated, evidence-driven security practice — retiring manual triage queues, spreadsheet tracking, and ad hoc patching in favour of platform-driven workflows.
- Team Development: Hire, develop, and retain security engineers who are genuinely dual-track — capable of operating traditional security tooling and building and maintaining the agentic layer that reasons over it.
WHAT WE ARE LOOKING FOR
- 15+ years in information security engineering, with at least 8 years in a technical leadership or senior engineering management role — you must be credible as an engineer to the team you lead.
- Hands-on Python development experience — you write production-quality Python, not just review it. Security automation, API integration, and pipeline development are your native territory.
- Proven experience delivering a security engineering programme at scale — SAST/SCA/DAST across a multi-product estate, CI/CD security gate enforcement, vulnerability lifecycle management end-to-end.
- Direct experience with agentic AI or LLM-based automation in a production security context — confidence-scored decision pipelines, human-in-the-loop gate design, automated evidence generation.
- Experience designing and governing automated remediation policies — graduated autonomy models, kill-switch protocols, audit trail requirements, and SOC 2 or equivalent compliance mapping.
- Track record of building and developing dual-track security engineering teams — engineers who are both InfoSec practitioners and automation/AI builders.
- Background in FinTech, enterprise SaaS, or a regulated technology environment — practical understanding of how compliance obligations shape security architecture decisions.
CORE TOOLING & TECHNOLOGIES
Python (production-level) · Snyk · SonarQube · Tenable · Wiz · LangChain / LangGraph · Claude / GPT-4o APIs · Jira / JSM · CI/CD (GitLab CI) · Datadog · OWASP ASVS · SOC 2 · CVSS
Skills Required
- 15+ years in information security engineering with at least 8 years in technical leadership or senior engineering management
- Production-quality hands-on Python development experience
- Proven delivery of security engineering programs at scale (SAST/SCA/DAST, CI/CD security gates, vulnerability lifecycle)
- Direct experience with agentic AI or LLM-based automation in production security (human-in-the-loop, confidence-scored decision pipelines)
- Experience designing and governing automated remediation policies (graduated autonomy, kill-switch, audit trails, compliance mapping)
- Track record building and developing dual-track security engineering teams (InfoSec + automation/AI skills)
- Background in FinTech, enterprise SaaS, or regulated technology environments
- Experience with Snyk, SonarQube, Tenable, Wiz
- Familiarity with LangChain/LangGraph and LLM APIs (Claude, GPT-4o) in production
- Experience with Jira/JSM, GitLab CI, Datadog
- Knowledge of OWASP ASVS, SOC 2 mapping, and CVSS
What We Do
InvestCloud, a global leader in wealth technology, aspires to enable a smarter financial future. Driving the digital transformation of the wealth management industry, the company serves a broad array of clients globally, including Wealth and Asset Managers, Wirehouses, Banks, RIAs, and Insurers. In terms of scale, the company’s clients represent more than 40 percent of the $132 trillion of total assets globally. As a leader in delivering personalization and scale across advisory programs, including unified managed accounts (UMA) and separately managed accounts (SMA), the company is committed to the success of its clients. By equipping and enabling advisors and their clients with connected technology, enhanced intelligence, and inspired experiences, InvestCloud delivers leading digital wealth management and financial planning solutions, complemented by a dynamic data warehouse, which scale across the complete wealth continuum. In 2024, InvestCloud was named a CNBC World’s Top Fintech Company, a proof point of the company’s commitment to innovation and client success. Headquartered in the United States, InvestCloud serves clients around the world.
Why Work With Us
Our growth is driven by our people as much as by our product. We are a team of operators, designers and artists. We value fresh perspectives as well as seasoned experience. We are connected by a strong sense of fun and family, working with focus to meet and exceed the highest standards.
Gallery








