VuNet is a pioneer in Business Journey Observability, leveraging Big Data and Machine Learning to transform digital experiences across the financial services. Our deep-tech platform provides end-to-end visibility into customer journeys — empowering proactive issue resolution, operational resilience, and superior user satisfaction.
If you’ve ever used instant payment systems like UPI, chances are you’ve already experienced the power of our platform — we monitor over 28 billion digital transactions monthly (that’s equal to watching 3 years of tik-tok videos), touching 300 million users with leading banks and financial institutions.
VuNet is Series B funded, part of NASSCOM DeepTech Club, awarded NASSCOM’s AI Gamechanger, recognized in Forbes DGEMS 200 and by several global analysts including Gartner, Omdia.
We’re building a new category of observability purpose-built for complex digital journeys — across payments, lending, core banking and more — already powering some of the largest banks in India and MEA.
As a Senior Information Security Engineer, you will be responsible for driving security initiatives across cloud-native, hybrid, and on-premise deployments of VuNet’s platform.
You will lead security assessments, compliance programs, DevSecOps initiatives, customer security reviews, vulnerability management programs, and security architecture reviews while partnering closely with Engineering, Product, DevOps, and Customer Success teams.
Platform Security & Hardening:
- Own and continuously strengthen the information security posture of VuNet's Business Observability platform across SaaS, cloud-native, hybrid, and on-premise deployment models
- Lead comprehensive security assessments including application security testing, API security testing, infrastructure security reviews, penetration testing, and CIS benchmark validation
- Define, implement, and govern security controls across cloud environments, Kubernetes platforms, containerized workloads, and enterprise deployments
- Establish and maintain secure deployment standards, hardening guidelines, and security architecture recommendations for both customer-managed and cloud-hosted environments
- Manage endpoint security and EDR platforms, including endpoint hardening, malware protection, detection engineering, and security monitoring across enterprise assets
- Support enterprise security initiatives including VPN security, identity and access management, infrastructure hardening, and privileged access controls
DevSecOps & Vulnerability Management
- Drive DevSecOps initiatives by integrating vulnerability management, SAST, DAST, container scanning, dependency scanning, compliance validation, and security gates into CI/CD pipelines.
- Own the end-to-end vulnerability management lifecycle including CVE analysis, CVSS-based risk assessment, prioritization, remediation tracking, validation, and reporting.
- Develop and maintain security automation using Python, Bash, and scripting for vulnerability assessments, reporting, and security operations.
- Maintain Software Bill of Materials (SBOMs), open-source software inventory, license compliance, and software supply chain security controls.
- Evaluate, implement, and optimize security technologies for application security, cloud security, vulnerability management, compliance automation, and security monitoring.
Security Architecture & Risk
- Lead threat modeling exercises, security design reviews, and risk assessments for new products, features, and architectural changes.
- Maintain security policies, standards, procedures, audit evidence repositories, and risk management frameworks.
- Stay ahead of emerging threats, evolving regulations, and industry best practices to continuously improve VuNet's security posture.
Compliance & Governance
- Drive compliance and governance programs including ISO 27001, SOC 2 Type II, GDPR, customer audits, and regulatory security requirements.
- Act as the primary security stakeholder during customer security reviews, vendor assessments, compliance evaluations, and technical due diligence engagements.
- Maintain audit evidence repositories, risk registers, and compliance documentation to ensure audit readiness at all times.
Stakeholder Engagement & Leadership
- Partner with Engineering, Product Management, Customer Success, and Leadership teams to define security requirements and ensure timely closure of security risks and compliance gaps.
- Mentor junior security engineers and promote a security-first culture across engineering and operational teams.
4–6 years of hands-on experience in Information Security, Product Security, Application Security, or Cybersecurity Engineering.
Application & Infrastructure Security
- Strong expertise in Web, API, Infrastructure, Cloud, and Kubernetes security.
- Experience performing penetration testing, vulnerability assessments, security audits, and platform hardening.
- Strong understanding of OWASP Top 10, Secure SDLC, Threat Modeling, and Risk Assessment methodologies.
- Hands-on experience with at least one major cloud platform (AWS, GCP, or Azure) including cloud-native security controls.
DevSecOps & Vulnerability Management
- Experience integrating security controls within CI/CD pipelines — including SAST, DAST, container scanning, and dependency scanning.
- Strong understanding of CVE analysis, CVSS scoring, vulnerability prioritization, and risk-based remediation.
- Experience with SBOM generation, OSS inventory management, software supply chain security, and open-source license compliance.
Kubernetes & Container Security
- Hands-on experience with Kubernetes security assessments, RBAC reviews, CIS benchmark validation, container image scanning, and secrets management.
Security Tools
Hands-on experience with tools across the following categories - specific tools may vary:
- Pen Testing / Scanning: Burp Suite, OWASP ZAP, Nmap, Nessus, or equivalent
- Container / K8s Security: Trivy, Kubescape, Dockle, or equivalent
- SAST / Code Scanning: SonarQube, Semgrep, Snyk, or equivalent
- Vulnerability Management: Qualys or equivalent
- SIEM / Monitoring: Any enterprise SIEM platform
Compliance & Governance
- Experience managing ISO 27001, SOC 2 Type II, GDPR, and customer compliance requirements.
- Ability to independently drive audit preparation, customer security reviews, and remediation programs.
Scripting & Automation
- Hands-on experience with Python, Bash, or similar scripting languages for security automation, reporting, and workflow orchestration
Certifications
- OSCP, OSWE, CCSP, CKS, CISSP - certifications that demonstrate hands-on, practitioner-level security expertise.
Domain Familiarity
- Experience with observability, monitoring, AIOps, or platform engineering products
- Familiarity with Big Data and cloud-native technologies such as Elasticsearch, Kafka, Redis, Cassandra, Hadoop, and Spark, particularly in the context of securing data pipelines and distributed systems.
Security Operations
- Experience in security monitoring, incident response, threat detection, and security event triage within a SOC or equivalent function.
- Security risks are proactively identified, prioritized, and remediated within defined SLAs - with zero critical CVEs left unaddressed beyond the remediation window.
- Security controls are embedded throughout the SDLC, with SAST, DAST, and container scanning operational across CI/CD pipelines.
- ISO 27001 / SOC 2 Type II audits completed with zero major observations attributable to security control gaps.
- Customer security reviews are handled independently and contribute to customer trust, with no escalations due to security gaps.
- SBOM and OSS inventory are maintained and current across all active product releases.
- Engineering teams demonstrably adopt security-first development practices, reflected in reduced vulnerability reopen rates and fewer late-stage security findings.
- Junior security engineers grow in capability and take ownership of independent workstreams under mentorship
At VuNet, we’re building a world-class observability platform, proudly Made in India — and we're just getting started.
We’re a team of passionate problem-solvers who love tackling complex challenges. We learn fast, adapt quickly, and stay curious — especially when it comes to exploring and staying ahead of the curve with emerging technologies like Gen AI.
More than just a tech company, VuNet is a place where collaboration, learning, and innovation are part of everyday life. We believe in working together, taking ownership, and growing as a team.
If you’re looking to work on cutting-edge technology, make a real impact, and grow with a supportive team — you’ll feel right at home at VuNet.
- Health insurance coverage for you, your parents, and dependents.
- Mental wellness and 1:1 counselling support.
- A learning culture that promotes growth, innovation, and ownership.
- Transparent, Inclusive, and high-trust workplace culture.
- New Gen AI and integrated Technology workspace.
- Supportive career development programs to expand your skills and enhance expertise with various training programs.