
Job Description
Ovii's Interpretation of the Role
The Senior Security and Compliance Engineer will own Hevo's compliance certifications and embed security controls across its cloud platform. You’ll partner with engineering, product, legal, and sales to turn regulatory requirements into scalable engineering solutions.
Role Snapshot
- Senior security‑compliance engineer
- Onsite – Bangalore, India
- Full‑time
- Individual contributor
- 5‑8 years experience
Must-Have Requirements
- SOC 2 Type II audit ownership
- Cloud security fundamentals (AWS/GCP/Azure)
- GRC platform experience
- Secure SDLC / DevSecOps practices
- Vulnerability management
- security engineering
- information security
- compliance engineering
- Onsite location in Bangalore, India
Nice-to-Have Signals
- ISO 27001 experience
- Familiarity with GDPR and CCPA
Work Setup
- Location: Bangalore, India
- Work mode: ONSITE
- Employment type: Full-Time
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Certifications
- Relocation
- Notice period
- Travel
- Security clearance
- Coding test
- Portfolio
- GitHub
- Writing sample
- Cover letter
What You'll Likely Work On
- Own end‑to‑end compliance certifications and manage audit cycles
- Design, implement, and continuously improve security controls across cloud infrastructure, access management, data handling, and the SDLC
- Embed security and compliance requirements into CI/CD pipelines and infrastructure‑as‑code
- Conduct risk assessments, vulnerability reviews, and internal audits, driving remediation of findings
- Develop, maintain, and operationalize security policies, standards, training, and continuous compliance monitoring using GRC tooling
- Partner with product, engineering, legal, finance, and sales to address compliance implications of new features and support security‑sensitive deals
Good Fit If You Have
- Treats compliance as a product with high ownership
- Detail‑oriented, process‑driven, and structured
- Influences cross‑functional teams without direct authority
- Strong written communication for policies and audit documentation
- Comfortable operating independently with no direct peers
Skills
- Compliance program ownership (SOC 2, ISO 27001, GDPR, CCPA)
- Cloud security (AWS/GCP/Azure)
- GRC platforms (e.g., Sprinto, Tugboat Logic)
- Secure SDLC & DevSecOps
- Vulnerability management
- Policy & procedure authoring
- Risk assessment & remediation
- Cross‑functional collaboration