More jobs:
Head of Information Security
Job in
560001, Vasanthanagar, Karnataka, India
Listed on 2026-08-30
Listing for:
Aurigo Software Technologies
Full Time
position Listed on 2026-08-30
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
About Aurigo
Aurigo is an AI-native capital program management platform trusted by over 300 customers managing more than $450 billion in capital programs across North America. With over 40,000 projects delivered, Aurigo helps organisations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence. Recognised as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes.
At Aurigo, we don't just build software — we help shape the future of infrastructure.
Location : Bengaluru, Karnataka
Work Mode :
Hybrid
About the Role
You report to the Chief Information & Security Officer (CI&SO), and you own the build and run of our security program company wide.
Aurigo builds mission critical AI native SaaS for capital infrastructure and government. Masterworks, Primus, Essentials and our AI product Lumina are trusted with highly regulated public sector and private sector data across four geographies. We hold SOC 1 and SOC 2 Type II, FedRAMP, GovRAMP and ISO 22301, with ISO 42001 close behind. Bangalore is a Global Capability Centre where global functions are owned and held accountable, and this role is one of them.
Aurigo runs a mature, advanced defense in depth posture. This role takes it further: operating it with greater precision, governing an identity and agent population growing faster than any human one, and using AI to defend at the speed our adversaries now attack.
Key Responsibilities
Vulnerability operations
Own vulnerability management as one operational discipline across product code, dependencies, containers, cloud, endpoints and SaaS. One view, one queue, one owner, with remediation driven through engineering rather than tickets handed across a wall.
Prioritize on real risk rather than raw CVSS: exploitability, reachability in our code paths, asset criticality and threat intelligence. Hold published SLAs by severity and measure recurrence as well as closure.
Own the technical execution of continuous monitoring under FedRAMP and GovRAMP: authenticated scanning, POA&M delivery, deviation requests and significant change security review.
AI and agent security governance
Own security governance for AI company wide: an enterprise LLM assistant for all staff, a low code automation platform, and team built agents. Mandatory agent registry and security intake, every agent carrying a named owner, risk tier and approved scope. Nothing reaches production unreviewed.
Treat agents as first class identities: least privilege credentials under privileged access management, full audit trail, tested kill switches, human in the loop on privileged actions. Vet third party AI services for data residency, sub processors and training data handling.
Extend adversarial AI testing across the portfolio for prompt injection, data exfiltration and agent abuse, aligned to the OWASP Top 10 for LLMs, MITRE ATLAS, ISO 42001 and the NIST AI RMF. Put AI to work on defense too, through agentic triage and automated evidence collection, so the function scales on output per engineer rather than headcount.
Identity, endpoint and threat defense
Own identity security across both populations, with non human identity the larger and faster growing: service accounts, machine identities, keys, tokens, certificates, workload identities and agents, each with a named human owner, vaulted and automatically rotated credentials, and least privilege scope enforced through the full lifecycle including deprovisioning.
Own identity threat detection and response, phishing resistant multi factor authentication, endpoint security across a mixed Windows and macOS fleet, detection engineering and the virtual SOC partnership, measured on coverage mapped to ATT&CK and on response time rather than ticket volume.
Product security, cloud and data
Own product security across Masterworks, Primus, Essentials and Lumina, supporting roughly 250 engineers: threat modelling, SAST, DAST and SCA gated in CI, secrets scanning, SBOM, code signing, guardrails on AI coding assistants,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×