As Xoxoday continues to scale globally, security is foundational not an afterthought. we're looking for a Senior Information Security Engineer who can help protect our cloud infrastructure, applications, and data while enabling teams to move fast and build securely.
This role sits deep within our engineering ecosystem. you'll embed security into how we'design, build, deploy, and operate systems working closely with Cloud, Platform, and Application Engineering teams. you'll balance proactive security design with hands-on incident response, and help shape a strong, security-first culture across the organization.
If you enjoy solving real-world security problems, working close to systems and code, and influencing how teams build securely at scale, this role is for you.
What you'll Do Cloud & Infrastructure Security
- Design, implement, and operate cloud-native security controls across AWS, Azure, GCP, and Oracle.
- Strengthen IAM, network security, and cloud posture using services like GuardDuty, Azure Security Center and others.
- Partner with platform teams to secure VPCs, security groups, and cloud access patterns.
Application & DevSecOps Security
- Embed security into the SDLC through threat modeling, secure code reviews, and security-by-design practices.
- Integrate SAST, DAST, and SCA tools into CI/CD pipelines.
- Secure infrastructure-as-code and containerized workloads using Terraform, CloudFormation, ARM, Docker, and Kubernetes.
Security Monitoring & Incident Response
- Monitor security alerts and investigate potential threats across cloud and application layers.
- Lead or support incident response efforts, root-cause analysis, and corrective actions.
- Plan and execute
VAPT and penetration testing
engagements (internal and external), track remediation, and validate fixes. - Conduct
red teaming activities and tabletop exercises
to test detection, response readiness, and cross-team coordination. - Continuously improve detection, response, and testing maturity.
Security Tools & Platforms
- Manage and optimize security tooling including firewalls, SIEM, EDR, DLP, IDS/IPS, CSPM, and vulnerability management platforms.
- Ensure tools are we'll-integrated, actionable, and aligned with operational needs.
Compliance, Governance & Awareness
- Support compliance with industry standards and frameworks such as SOC2, HIPAA, ISO 27001, NIST, CIS, and GDPR.
- Promote secure engineering practices through training, documentation, and ongoing awareness programs.
- Act as a trusted security advisor to engineering and product teams.
Continuous Improvement
- Stay ahead of emerging threats, cloud vulnerabilities, and evolving security best practices.
- Continuously raise the bar on Xoxoday s security posture through automation and process improvement.
Endpoint Security (Secondary Scope)
- Provide guidance on endpoint security tooling such as SentinelOne and Microsoft Defender when required.
What we're Looking For
- Strong hands-on experience in
cloud security across AWS and Azure
. - Practical exposure to CSPM tools (eg, Prisma Cloud, Wiz, Orca) and SIEM / IDS / IPS platforms.
- Experience securing containerized and Kubernetes-based environments.
- Familiarity with CI/CD security integrations (eg, Snyk, GitHub Advanced Security, or similar).
- Solid understanding of network security, encryption, identity, and access management.
- Experience with application security testing tools (SAST, DAST, SCA).
- Working knowledge of security frameworks and standards such as ISO 27001, NIST, and CIS.
- Strong analytical, troubleshooting, and problem-solving skills.
Nice to Have:
- Experience with DevSecOps automation and security-as-code practices.
- Exposure to threat intelligence and cloud security monitoring solutions.
- Familiarity with incident response frameworks and forensic analysis.
- Security certifications such as CISSP, CISM, CCSP, or CompTIA Security+.
What Makes You a Strong Fit
- High ownership and a security-first mindset.
- Clear communicator who can translate risk into practical guidance.
- Comfortable working in fast-paced, evolving environments.
- Curious, proactive, and committed to continuous learning.
Why This Role Matters
Security enables scale. In this role, you'll directly influence how securely our products are built and operated, how teams think about risk, and how we protect customer trust as we grow globally.
Why Join Us
- Work with modern, cloud-native security technologies at scale.
- Collaborate closely with strong engineering and platform teams.
- Flexible work policies, comprehensive health benefits, and modern tooling.
- Clear growth path toward
Security Architect
or Security Engineering Lead
roles.