Security Operations Engineer
Full-time · Remote / Hybrid · 3–5 years experience
About the Role
Grey Chain is an AI product studio building cloud-native tools for enterprise clients. We're looking for a hands-on SecOps engineer to own our security tooling across both our internal work environment and our client-facing cloud deployments — and help us mature our practices as we scale toward SOC2 compliance.
You'll assess our current security posture across two distinct surfaces — the Greychain team environment and our deployed cloud products — recommend the right tooling for each, and then actually implement it. We don't need a consultant who hands off a slide deck; we need someone who gets things done. You'll work closely with our dev and DevOps teams to embed security into our SDLC, not bolt it on after the fact.
Securing the Work Environment
- MDM/EDR rollout across Greychain devices
- DLP policies to prevent sensitive client data from leaving controlled channels (email, SaaS tools, AI assistants)
- Phishing-resistant passkey/MFA rollout for admin and internal accounts
- Cloudflare client cert authentication to lock down internal-facing services
- Identity and access governance across internal tools and cloud consoles
Securing Deployed Cloud Environments (AWS & Azure)
- Container scanning across AWS ECR and Azure Container Registry — with a clear triage and fix process
- GitHub security hygiene — branch protection, Dependabot, SCA across all repos
- Network security posture — reducing public attack surface (e.g. publicly exposed UIs, external traffic routing)
- Pentest remediation tracking and retest coordination
- DLP controls at the cloud layer — ensuring client data doesn't leak across environments or tenants
- OWASP SAMM assessment and end-to-end SDLC documentation
What We’re Looking For
- 3–5 years in a SecOps, AppSec, or DevSecOps role
- Hands-on experience with both AWS and Azure security services — we deploy on both depending on client
- Experience implementing DLP across endpoint and cloud layers
- Familiarity with GitHub Advanced Security, SCA tooling, and container security
- SOC2 experience — ideally taken a team through it before
- Someone who can advise and implement — we don’t need a consultant, we need someone who gets things done
Nice to Have
- Experience with AI-assisted code scanning (Claude Security, GHAS, GitHub Copilot)
- Familiarity with OWASP SAMM and SDLC governance frameworks
- Experience in a client-delivery environment where cloud choices are client-driven
- Knowledge of Microsoft Purview or equivalent DLP tooling for Azure-heavy clients
Pay: ₹1,200,000.00 - ₹2,000,000.00 per year
Benefits:
- Paid time off
- Provident Fund
- Work from home
Work Location: Remote