About Aurigo
Aurigo is an AI-native capital program management platform trusted by over 300 customers managing more than $450 billion in capital programs across North America. With over 40,000 projects delivered, Aurigo helps organisations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence. Recognised as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes. At Aurigo, we don't just build software — we help shape the future of infrastructure.
Why this role, and why now
You report to the Chief Information & Security Officer (CI&SO), and you own the build and run of our security program company wide.
Aurigo builds mission critical AI native SaaS for capital infrastructure and government. Masterworks, Primus, Essentials and our AI product Lumina are trusted with highly regulated public sector and private sector data across four geographies. We hold SOC 1 and SOC 2 Type II, FedRAMP, GovRAMP and ISO 22301, with ISO 42001 close behind. Bangalore is a Global Capability Centre where global functions are owned and held accountable, and this role is one of them.
Aurigo runs a mature, advanced defense in depth posture. This role takes it further: operating it with greater precision, governing an identity and agent population growing faster than any human one, and using AI to defend at the speed our adversaries now attack.
What you own
Vulnerability operations
- Own vulnerability management as one operational discipline across product code, dependencies, containers, cloud, endpoints and SaaS. One view, one queue, one owner, with remediation driven through engineering rather than tickets handed across a wall.
- Prioritize on real risk rather than raw CVSS: exploitability, reachability in our code paths, asset criticality and threat intelligence. Hold published SLAs by severity and measure recurrence as well as closure.
- Own the technical execution of continuous monitoring under FedRAMP and GovRAMP: authenticated scanning, POA&M delivery, deviation requests and significant change security review.
AI and agent security governance
- Own security governance for AI company wide: an enterprise LLM assistant for all staff, a low code automation platform, and team built agents. Mandatory agent registry and security intake, every agent carrying a named owner, risk tier and approved scope. Nothing reaches production unreviewed.
- Treat agents as first class identities: least privilege credentials under privileged access management, full audit trail, tested kill switches, human in the loop on privileged actions. Vet third party AI services for data residency, sub processors and training data handling.
- Extend adversarial AI testing across the portfolio for prompt injection, data exfiltration and agent abuse, aligned to the OWASP Top 10 for LLMs, MITRE ATLAS, ISO 42001 and the NIST AI RMF. Put AI to work on defense too, through agentic triage and automated evidence collection, so the function scales on output per engineer rather than headcount.
Identity, endpoint and threat defense
- Own identity security across both populations, with non human identity the larger and faster growing: service accounts, machine identities, keys, tokens, certificates, workload identities and agents, each with a named human owner, vaulted and automatically rotated credentials, and least privilege scope enforced through the full lifecycle including deprovisioning.
- Own identity threat detection and response, phishing resistant multi factor authentication, endpoint security across a mixed Windows and macOS fleet, detection engineering and the virtual SOC partnership, measured on coverage mapped to ATT&CK and on response time rather than ticket volume.
Product security, cloud and data
- Own product security across Masterworks, Primus, Essentials and Lumina, supporting roughly 250 engineers: threat modelling, SAST, DAST and SCA gated in CI, secrets scanning, SBOM, code signing, guardrails on AI coding assistants, penetration test and bug bounty remediation as a tracked programme, and a security champions model so security moves at the pace of engineering.
- Own runtime cloud posture across AWS and Azure, SaaS posture across the corporate estate, and data security engineering: classification, data loss prevention, encryption and key management, control over how regulated data moves into and out of AI systems, and the engineering controls behind India's DPDP Act and US state privacy obligations.
Incident response, platform and team
- Serve as Incident Commander for Sev1. Own the severity model, escalation, on call structure and forensics retainer, our ability to meet the FedRAMP one hour window, the CERT-In six hour directive and customer contractual clocks, and an exercise program of tabletops across all four geographies plus a full scope live test each year.
- Lead consolidation onto fewer platforms and own vendor strategy and commercial negotiation. Lead and grow the security engineering organization covering SOC, detection, application security, cloud and offensive testing, with funded headcount growth. Report posture, risk and roadmap to the CI&SO and the executive leadership team, with defined escalation to the Audit Committee.
Certifications: where your accountability sits
GRC owns the certification. You own the controls it rests on.
GRC owns authorization packages, the System Security Plan, 3PAO and agency relationships, the audit calendar, policy, privacy and third party risk. You own what every certification rests on: that technical controls are implemented, effective, continuously monitored and evidenced as a byproduct of how we operate. If a certification is ever at risk because a control failed or evidence was missing, that is yours. If it is because a policy or authorization artefact was wrong, that is GRC's.
What you bring
Required
- 14+ years in information and cyber security, including 6+ years leading security teams and at least 2 leading managers or principal level engineers. You have owned security for a SaaS product company at scale, building and running it rather than only governing it.
- You have run vulnerability management as an operational discipline at scale, with published SLAs, risk based prioritisation and remediation delivered through engineering. You can talk about aging curves and recurrence rates from memory.
- Direct experience governing machine and non-human identity, and practical command of AI and LLM security risk with real experience applying AI to security operations rather than only defending against it.
- Hands on depth in at least four of: identity and privileged access; endpoint detection and response and detection engineering; cloud security across AWS and Azure; application and product security; secure access service edge and CASB; data protection. You have operated inside a live authorization regime such as FedRAMP, GovRAMP, DoD IL4 or IL5, PCI DSS or HITRUST.
- You have been incident commander for a material security incident, including the executive and customer communication that came with it. You can brief a board or audit committee and hold a technical argument with a staff engineer on the same day, and you have led a global function from an India GCC with genuine accountability rather than delivery support.
Preferred
- Security leadership for SaaS in government or otherwise regulated markets. CISSP, CISM, CCSP or senior cloud provider credentials. Experience building agentic security workflows. Vendor consolidation and negotiation at seven figure scale.
Aurigo Software Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable law