Ovii Job Board

Security Engineer

Drivetrain

India, India • Remote - India, India • Full-Time • 2+ years

Posted 2026-07-01 Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

The Security Engineer will own and evolve Drivetrain's security posture across product, infrastructure, and internal tooling. The role is hands‑on, collaborating with engineering, IT, and compliance to embed security throughout the development lifecycle.

Role Snapshot

  • Own security posture across product & infrastructure
  • Lead application security and vulnerability management
  • Implement secure SDLC and tooling
  • Respond to incidents and maintain runbooks
  • Manage identity & access controls

Must-Have Requirements

  • cloud security (AWS or GCP)
  • identity and access management (IAM, SSO, RBAC)
  • secure SDLC practices (SAST, DAST, code review)
  • vulnerability management
  • incident response
  • Python or Go scripting
  • security engineering
  • application security
  • cloud security

Nice-to-Have Signals

  • experience securing SaaS products handling sensitive financial data
  • leading SOC 2 or ISO 27001 audits
  • container security (Docker/Kubernetes)
  • IaC scanning (Terraform)
  • familiarity with OWASP Top 10, SOC 2, ISO 27001, GDPR
  • SaaS product security
  • SOC 2 audit leadership
  • container security
  • financial services
  • SaaS

Work Setup

  • Location: India, India
  • Work mode: REMOTE
  • Remote scope: COUNTRY_RESTRICTED
  • Remote countries: India
  • Employment type: Full-Time

Eligibility Gates

  • Visa sponsorship: unknown

Not Specified in JD

  • Salary range
  • Visa sponsorship
  • Relocation
  • Notice period
  • Travel
  • Security clearance
  • Coding test
  • Portfolio

What You'll Likely Work On

  • Design, implement, and maintain security controls for cloud platforms, CI/CD pipelines, and internal systems
  • Lead threat modeling, secure code reviews, and integrate SAST/DAST tools into the development workflow
  • Own vulnerability management: triage, prioritize, and drive remediation of scan, pen‑test, and bug‑bounty findings
  • Monitor for security incidents, respond, and maintain incident‑response runbooks
  • Manage identity and access controls (SSO, RBAC, least‑privilege) for internal and customer‑facing services
  • Support customer security questionnaires, audits, and certifications such as SOC 2 and ISO 27001
  • Partner with engineering teams to embed secure‑by‑design practices into new features
  • Evaluate and roll out security tooling like secrets management, endpoint protection, and cloud security posture management

Good Fit If You Have

  • Clear communicator who can translate security risk to non‑technical stakeholders
  • Proactive attitude toward building security processes, not just policies
  • Interest in fostering a security‑first culture across the organization

Skills

  • Cloud security (AWS/GCP)
  • Identity & Access Management (IAM, SSO, RBAC)
  • Secure SDLC (SAST/DAST, code review)
  • Vulnerability management
  • Incident response
  • Python/Go scripting
  • Security tooling (secrets management, CSPM)
  • Container security (Docker/Kubernetes) – preferred
  • IaC scanning (Terraform) – preferred
  • OSCP/CISSP/CCSP certifications – optional

Remote Eligibility

  • India