← All verified jobs

Lead Security Engineer - 11807

coupa software Pune, IndiaRemote

See all open roles at coupa software

Ghost-risk verdict

Likely real

  • 115 open roles at this company in 30 days (mass-hiring blitz)
  • no salary disclosed (correlates with ghost postings)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

What You'll Do:

Architect and build multi cloud security controls across Coupa's cloud environment. VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.

Build policy-as-code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after the fact reviews.

Harden containerized workloads - image scanning, admission control, pod security standards, and runtime detection.

Write auto-remediation for cloud misconfiguration and drift so common findings close without manual ticket routing.

Own Vulnerability management program, act as the technical escalation point for security incidents and vulnerability findings - leading forensics, containment, and root-cause analysis using cloud-native and EDR tooling, and driving remediation to closure.

Partner with Risk & Compliance to translate audit framework requirements (SOC 2, ISO 27001, PCI-DSS, FedRAMP) into concrete technical controls, and automate evidence collection by integrating cloud telemetry with GRC tooling.

Mentor other security engineers through design review, threat modeling, and code/architecture review; raise the technical bar for the whole team.

Own reference architectures, threat models, and runbooks for the security tooling you build; participate in and help improve the on-call rotation.

What You'll Bring to Coupa:

10+ years of security engineering experience, including significant hands-on work securing production cloud environments at scale, plus experience leading projects or mentoring other engineers.

Deep, hands-on AWS security expertise - IAM, VPC/networking, KMS, GuardDuty, Security Hub, Config, and Organizations/SCPs; working knowledge of GCP or Azure security is a plus.

Production experience with Terraform (or equivalent IaC) and policy-as-code frameworks, plus container/Kubernetes security tooling.

Strong software engineering fundamentals - Python and/or Go, Git-based workflows, and building/maintaining CI/CD security integrations (SAST, DAST, SCA).

Experience with SIEM/SOAR platforms and vulnerability management tooling (e.g., Wiz, Qualys, Tenable) - building detections and workflows, not just consuming dashboards.

Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP, NIST 800-53) sufficient to translate control requirements into engineering work.

Excellent written and verbal communication skills - able to write clear technical design docs and explain risk trade-offs to auditors and engineering leadership alike.

Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.

Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications.

Some international travel may be required.

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.