Lead Product Security and Compliance Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in India
Remote
Senior level
AdTech • Digital Media • Marketing Tech • Mobile
The Role
Own product security end to end, including vulnerability identification and remediation, secure SDLC practices, SOC 2 compliance, incident response, access controls, data protection, security tooling, vendor assessments, and audit readiness. Partner directly with engineering teams, review production code, strengthen security culture, communicate risk to leadership and external stakeholders, and support evolving compliance requirements such as ISO 27001.
Summary Generated by Built In

BigHappy is looking for a Senior/Lead Product Security & Compliance Engineer to be the org's go-to authority on product security. Someone who can own the problem end-to-end rather than hand off findings and move on. This is a senior, largely independent role: you'll set the security standards our engineering teams work to, contribute to and maintain our SOC 2 compliance from control implementation through audit readiness, and build the tooling and culture that catches vulnerabilities before they ship.
You'll work hands-on with the Chandigarh Tri-city engineering teams (Go, Node.js, React, AWS) — not just filing tickets, but sitting with engineers to help them understand and fix what you find. As we scale, this role is also expected to credibly respond to customers, auditors, and vendors on security posture.

NOTE: 
  • Candidates must be open to work within USA time zones EST/EDT and PST/PDT hours.

Key Responsibilities
Office IT & network operations (steady state)
Own product security end-to-end. Identify vulnerabilities across the full stack: application code, third-party dependencies, APIs, and cloud/infrastructure configuration.
  • Work directly with engineering teams to assist with fixing what you find
    • Pairing on remediation, explaining root cause, and building their ability to catch similar issues themselves, not just filing reports over the wall.
  • Contribute and maintain SOC 2 compliance : control implementation, evidence collection, audit readiness, and ongoing maintenance as controls evolve.
  • Champion secure development practices org-wide.
    • Secure SDLC, code review guidelines, threat modeling for new features, and security training/enablement for engineers.
  • Select, set up, and manage the security tooling stack.
    • SAST/DAST scanning, dependency and vulnerability scanning, secrets detection, and coordination of periodic penetration tests.
  • Own security incident response
    • Detection, triage, remediation, and blameless post-incident review, including the process itself, not just individual incidents.
  • Own access control and data protection practices.
    • Least-privilege access reviews, data classification, and encryption standards across systems.
  • Track and report on security posture and compliance status to leadership, in terms non-security stakeholders can act on.
  • Stay current on emerging threats, relevant CVEs, and evolving compliance requirements (SOC 2 today, maybe ISO 27001 as we scale) and translate that into concrete changes to our practices.
  • Run vendor security assessments, maintain security policy documentation, and act as the primary point of contact for external auditors.
  • Build a security-first culture across engineering. The goal is a trusted advisor teams want to loop in early, not a gatekeeper they route around.

Skills, Knowledge and Expertise

Must-Have Skills
  • 6+ years of experience in product/application security, including demonstrated ownership of a SOC 2 (or comparable) compliance.
  • Either built from scratch or carried through multiple audit cycles.
  • Strong understanding of common vulnerability classes (OWASP Top 10 and beyond), with hands-on experience finding and fixing them, not just reading scanner output.
  • Experience embedding security into the SDLC and shifting developer behavior.
    • Able to influence practices across teams without formal authority and without becoming a blocker to shipping.
  • Familiarity with cloud security, AWS preferred to align with our infrastructure, and working knowledge of modern security tooling (SAST/DAST, SCA, secrets scanning).
  • Hands-on ability to read, review and suggest fixes in production code in at least one backend language (Go, Node.js, Python or Java).
  • Strong communication skills. This role works cross-functionally with engineering, operations, and leadership, and needs to translate technical risk into business terms auditors, customers, and executives can act on.
Nice-to-Have Skills
  • Relevant certifications - CISSP, OSCP, CCSK, or similar.
  • Experience with Go language, including Go-specific security tooling.
  • Prior experience in a startup or scale-up environment, balancing security rigor against shipping speed.
  • Experience with ad-tech, martech, or another high-throughput, latency-sensitive domain.
  • Experience taking a company through ISO 27001 or a similar framework beyond SOC 2.
  • Experience running or coordinating penetration testing engagements with external vendors.

Benefits
Flexible Time-Off : At BIG Happy, we believe that great work comes from a well balanced life. Our flexible time-off policy empower employees to manage their schedules effectively, recharge when needed, and maintain a healthy work-life balance without compromising productivity.
Comprehensive Health & Family Support: We prioritize the well-being of our team and their families. Our plans provide health support policies, including maternity benefits, ensure that employees feel supported during important life stages.

Performance-Driven Rewards & Growth: We recognize and reward impact. Through performance bonuses and incentive programs, employees are acknowledged for their contributions and achievements, fostering a motivating environment that supports both personal and professional growth.

Relocation & Seamless Transition Support: Joining us from a different location? We’ve got you covered. Our relocation support and reimbursement policies are designed to make your transition smooth and stress-free, allowing you to focus on settling into your role and new environment.

Inclusive Culture & Collaborative Environment: Our workplace thrives on collaboration, inclusivity, and engagement. From cross-functional 1:1s to team building activities like movie outings, events, and office get-togethers, we ensure every team member feels connected, valued, and empowered to contribute meaningfully.

About
We specialize in delivering innovative solutions and exceptional services to meet the diverse needs of our clients. With a strong commitment to quality and customer satisfaction, we strive to exceed expectations and drive success in every project we undertake.

Skills Required

  • 6+ years of experience in product or application security
  • Demonstrated ownership of SOC 2 or comparable compliance, including control implementation, audit readiness, and multiple audit cycles or building the program from scratch
  • Hands-on knowledge of OWASP Top 10 and other vulnerability classes, including finding and fixing vulnerabilities
  • Experience embedding security into the software development lifecycle and influencing developer behavior across teams
  • Familiarity with cloud security, preferably AWS
  • Working knowledge of SAST, DAST, software composition analysis, secrets scanning, and related security tooling
  • Ability to read, review, and recommend fixes in production code using Go, Node.js, Python, or Java
  • Strong cross-functional communication skills and ability to translate technical risk into business terms
  • Availability to work during USA EST/EDT and PST/PDT hours
  • CISSP, OSCP, CCSK, or similar certification
  • Experience with Go and Go-specific security tooling
  • Startup or scale-up experience
  • Experience in ad-tech, martech, or another high-throughput, latency-sensitive domain
  • Experience with ISO 27001 or a similar framework beyond SOC 2
  • Experience running or coordinating external penetration testing engagements
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
Year Founded: 2019

What We Do

Big Happy is a creative-first, performance-powered adtech platform that transforms everyday screens into unforgettable experiences, specializing in high-impact mobile and DOOH advertising by combining cutting-edge creative with publisher media to drive brand outcomes.

Similar Jobs

Micron Technology Logo Micron Technology

Reliability Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
Remote
Gujarat, IND
45000 Employees

Micron Technology Logo Micron Technology

Facilities - Sr Manager

Artificial Intelligence • Hardware • Information Technology • Machine Learning
Remote
Gujarat, IND
45000 Employees

Hilton Logo Hilton

Kitchen Stewarding Manager

Software • Hospitality
Remote
India
121228 Employees

Atlassian Logo Atlassian

Senior Engineering Manager

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account