Senior Security Manager
Bangalore, India
About the role -
- Stand up and run governance for AI used across the company — Claude Enterprise (all staff), n8n agent platform, and the growing number of team-built agents.
- Own a mandatory agent registry and security intake: every agent inventoried with an owner and risk tier; nothing reaches production unreviewed.
- Treat agents as identities — least-privilege scoped credentials (vaulted in CyberArk), audit trails, and kill switches; harden n8n (SSO/RBAC, dev-prod separation, human-in-the-loop for privileged actions).
- Vet third-party AI tools and services (data residency, DPAs, sub-processors) and drive shadow-AI discovery via Netskope.
- Extend AI/LLM security testing (OWASP Top 10 for LLMs, MITRE ATLAS, red-teaming) already in place for Lumina; align to ISO 42001 and the NIST AI RMF.
- Extend our live CyberArk PAM from privileged human accounts to service, machine, and agent identities; drive ITDR and phishing-resistant MFA.
- Own endpoint security across a mixed Windows + Mac fleet (Microsoft Defender ATP + CrowdStrike Falcon Complete), closing Mac coverage parity gaps.
- Mature the SOC: alert triage (800/month today), threat hunting, and AI-augmented detection to match adversary speed (current 1h / 4h MTTD / MTTR).
- Strengthen the human layer — vishing and social-engineering resilience, tabletop and red/blue exercises across all four geographies.
- Lead consolidation of point tools onto the CrowdStrike Falcon platform (SCA, Exposure Management, FileVantage, Next-Gen SIEM), targeting material cost savings and eliminating cross-domain blind spots.
- Own runtime cloud security for AWS + Azure.
- Own SaaS security posture management (SSPM) across Salesforce, SuccessFactors, NetSuite, and Microsoft 365; protect the public-facing website (WAF/CDN, integrity monitoring).
- Secure the software supply chain and developer workflows: dependency and package scanning, code signing, and guardrails for AI coding tools.
What you bring
Required
- 10+ years : years of experience in information/cyber security, including 3+ years in a people-management role.
- Hands-on depth across several of: identity & PAM (CyberArk or equivalent), EDR/XDR (CrowdStrike/Defender), SIEM, cloud security (AWS/Azure), SASE/ZTNA (Netskope or equivalent).
Preferred
- Experience securing SaaS products in regulated/government contexts.
- Certifications such as CISSP, CISM, CCSP, or cloud-provider security credentials.
- Experience governing enterprise AI adoption or agent/automation platforms (e.g., n8n) and SSPM tooling.
- Vendor consolidation and commercial negotiation experience.
What success looks like in the first year
- Every AI agent and automation in the company is inventoried, owned, least-privileged, and monitored — with governance the whole company follows.
- Identity controls extended from human admins to agent and machine identities; ITDR and phishing-resistant MFA in place.
- Security stack consolidated onto fewer platforms with measurable cost savings and unified cross-domain visibility.
- Cloud and SaaS posture continuously monitored; compliance certifications maintained with zero customer-impacting security incidents.
About Aurigo
Aurigo is an AI‑native capital program management platform trusted by over 300 customers managing more than $300 billion in capital programs across North America. With over 40,000 projects delivered, Aurigo helps organizations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence. Recognized as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes. At Aurigo, we don't just build software—we help shape the future of infrastructure.