Information Security Architect
Auracloud · Aura Cloud Technologies Private Limited · India · On-site
Posted Sep 20, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Aura Cloud
Aura Cloud is a Nordic SaaS core banking platform provider. Our Aura platform powers banks and financial institutions across the Nordics and Baltics — processing deposits, loans, payments, and cards for regulated customers.
The Role
You will own information security across the Aura platform, infrastructure, and organization — from security architecture and compliance certifications to customer-facing security assurance and incident response.
We are ISO 27001 certified and continuously strengthening our compliance posture across SOC 2, DORA, and other regulatory frameworks. We need someone who can drive certifications, strengthen our security architecture, and be the trusted security voice to our regulated customers.
What You Will Own
Security Architecture & Engineering
Define and maintain the platform's security architecture — network segmentation, encryption, access control, API security, and key management
Review and approve infrastructure changes, new integrations, and API exposure decisions
Own the vulnerability management program — dependency scanning, CVE triage, patching, and remediation tracking
Oversee security monitoring tooling (Wazuh SIEM, EWACS, CloudWatch) — detection rules, alert triage, and tuning
Hands-On Security Engineering
Design and implement AWS security controls directly — IAM policies, security groups, KMS key policies, WAF rulesets, GuardDuty tuning
Lead remediation of penetration test and vulnerability assessment findings across infrastructure and application layers, working hands-on with engineering teams to close gaps
Configure and tune SIEM detection rules and alerting logic (Wazuh or equivalent) — build use cases, not just monitor dashboards
Own certificate lifecycle management and encryption implementation (at-rest and in-transit) across environments
Review and harden infrastructure configurations against CIS benchmarks and similar standards
Work with engineering on secure coding practices and help embed security checks into the development pipeline
Compliance & Certifications
Maintain and evolve the existing ISO 27001 ISMS through annual surveillance audits and continuous improvement
Drive SOC 2 Type II compliance — scope, control implementation, evidence collection, and auditor engagement
Own DORA compliance — ICT risk management, incident classification/reporting, resilience testing, and third-party risk management
Ensure GDPR compliance for platform data processing; work alongside the DPO
Customer Security Assurance
Handle customer security questionnaires, due diligence requests, and audit evidence packages
Produce regular security reports for customers and present at governance meetings
Support RFP responses with security content
Incident Response
Own the incident response plan — severity levels, escalation, communication, and post-incident review
Act as incident commander for security-related P1/P2 incidents; deliver RCA within SLA
Commission and…