InvestCloud, Inc.

Principal Information Security Engineer

InvestCloud, Inc.  •  Bengaluru, IN (Onsite)  •  1 hour ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

SECURITY ENGINEERING AT INVESTCLOUD

At InvestCloud, we are building an intelligent security response capability that determines what to fix first based on the actual risk to our clients and business, not a scanner's native severity.

Traditional vulnerability management produces disconnected findings and long backlogs. It often misses whether vulnerable code is deployed, reachable by an attacker, connected to a critical service, capable of lateral movement, or already being exploited. We are solving that problem by combining threat intelligence, runtime and deployment evidence, configuration management data, attack path analysis, business criticality, and validation results.

The platform will ingest findings from infrastructure, cloud, application, software supply chain, secrets, containers, infrastructure as code, and adversarial testing. It will reconcile them to a canonical asset and service model, deduplicate them into unique exposures, and rank the remediation actions that remove the most risk.

The product is being built in Python on AWS with source-controlled connectors, deterministic policy code, an AI reasoning layer, human approval gates, complete audit evidence, and closed-loop validation. Large language models (LLMs) can correlate evidence, recommend remediation, and explain decisions. They do not calculate the authoritative priority score.

This is not another scanner or dashboard. It is a security decision and remediation platform that must answer one question reliably: what is the single next action that will remove the most material risk, why is it first, who owns it, and how will we verify the risk is gone? Every engineer on this team will build production software, operate what they build, and own the product after the initial consultant implementation.

THE ROLE

As our Infrastructure & Cloud Security Engineer, you will own the data and platform foundation that every prioritization and remediation decision depends on. You will build the source adapters, canonical schema, normalization, reconciliation, and data quality controls that turn disconnected scanner, intelligence, asset, repository, and deployment records into trusted security data.

Jira Assets is the initial configuration management database (CMDB), but the harness must remain independent of Jira, Wiz, Rapid7, Tenable, Snyk, and every other vendor. You will design source contracts and AWS services so you can add new tools or a future data lake or warehouse without rewriting the scoring, reasoning, or remediation layers.

WHAT YOU WILL OWN

  • Security Data Ingestion: Build and operate source adapters for Wiz, Rapid7 or Tenable, Snyk, VVAH, Jira Assets, security testing platforms, SARIF producers, and threat intelligence feeds. Support bulk, incremental, event-based, and artifact-based ingestion with read-only source access.
  • Canonical Model & Reconciliation: Normalize findings, observations, assets, repositories, commits, pipelines, artifacts, deployments, services, clients, and remediation actions. Reconcile records to the correct entities, deduplicate repeated observations, and retain full source provenance and raw history.
  • Asset, Deployment & Coverage Context: Build the links from repository to pipeline, artifact, runtime asset, application service, business service, client, owner, and external route. Surface missing agents, broken mappings, stale data, and other coverage gaps as actionable work.
  • Threat & Vulnerability Intelligence Feeds: Ingest and maintain independent CVE, exploitation, advisory, fixed version, malicious package, and lifecycle data, including CVE or NVD, CISA KEV and Vulnrichment, EPSS, GitHub Security Advisories, OSV, vendor advisories, and equivalent sources.
  • AWS Data Platform Reliability: Own Lambda- or container-based connectors, SQS and dead letter queues, S3 raw history, Aurora PostgreSQL, secrets, identity, infrastructure as code, monitoring, and recovery. Define service-level expectations for freshness, completeness, reconciliation, and schema compatibility.
  • Production Engineering & Handover: Keep connectors, transformations, tests, schemas, and infrastructure under source control. Build automated tests and observability, participate in architecture and code reviews, document operating procedures, and take permanent ownership from Electric Mind.

WHAT WE ARE LOOKING FOR

  • 7+ years in infrastructure security, cloud security, DevSecOps, security data engineering, or a closely related discipline, with clear evidence of lead-level technical ownership. Advisory-only experience is not sufficient.
  • Production Python and SQL. You can design maintainable APIs, data pipelines, schemas, asynchronous processing, error handling, tests, and migrations, not just scripts.
  • Hands-on AWS engineering with services such as Lambda, SQS, S3, ECS or Fargate, Aurora or PostgreSQL, IAM, Secrets Manager, CloudWatch, and Terraform or CloudFormation.
  • Security data depth across cloud and infrastructure findings, application and dependency findings, SBOMs, SARIF, vulnerability intelligence, and scanner APIs. You understand the security meaning of the data you are transforming.
  • Entity resolution and data quality experience. You can model relationships across assets, services, software, deployments, and clients, preserve unknown values, and diagnose conflicting or incomplete source data.
  • CMDB and data platform experience, ideally Jira Assets plus Snowflake, Fabric, or another warehouse. You can design an abstraction that supports today's source of truth and tomorrow's platform without a rewrite.
  • A builder's mindset with evidence of self-directed work, responsible use of AI to improve engineering quality and speed, concise communication, strong ownership, and the ability to collaborate without ego.

CORE TOOLING & TECHNOLOGIES

Python · SQL · PostgreSQL / Aurora · AWS Lambda · SQS / DLQ · S3 · ECS / Fargate · Terraform / CloudFormation · FastAPI · REST / GraphQL · Jira Assets · Wiz · Rapid7 / Tenable · Snyk · SARIF · CVE / KEV / EPSS · GitLab CI · Datadog

WHY JOIN THIS TEAM

You will own the foundation that determines whether every downstream decision is trustworthy. When the data layer is correct, the harness can identify the same exposure across multiple tools, understand where vulnerable code is actually running, and detect where the organization is blind.

Your work will also determine whether InvestCloud can replace tools, add new evidence sources, and move from Jira Assets to a mature data platform without rebuilding the product. This is permanent product ownership, not connector maintenance.

InvestCloud, Inc.

About InvestCloud, Inc.

InvestCloud, a global leader in wealth technology, aspires to enable a smarter financial future. Driving the digital transformation of the wealth management industry, the company serves a broad array of clients globally, including Wealth and Asset Managers, Wirehouses, Banks, RIAs, and Insurers. In terms of scale, the company’s clients represent more than 40 percent of the $132 trillion of total assets globally. As a leader in delivering personalization and scale across advisory programs, including unified managed accounts (UMA) and separately managed accounts (SMA), the company is committed to the success of its clients. By equipping and enabling advisors and their clients with connected technology, enhanced intelligence, and inspired experiences, InvestCloud delivers leading digital wealth management and financial planning solutions, complemented by a dynamic data warehouse, which scale across the complete wealth continuum. In 2024, InvestCloud was named a CNBC World’s Top Fintech Company, a proof point of the company’s commitment to innovation and client success. Headquartered in the United States, InvestCloud serves clients around the world.

Industry
Finance & Insurance
Company Size
1,001-5,000 employees
Headquarters
West Hollywood, CA
Year Founded
Unknown
Social Media