About Aurigo
Aurigo is an AI-native capital program management platform trusted by over 300 customers managing more than $450 billion in capital programs across North America.With over 40,000 projects delivered, Aurigo helps organizations in transportation, water and utilities, healthcare, higher education, and government plan, build, and manage infrastructure with confidence.Recognized as one of the Top 25 AI Companies of 2024 and a Great Place to Work for three consecutive years, we leverage artificial intelligence to create smarter, more connected outcomes.At Aurigo, we don't just build software — we help shape the future of infrastructure.
Description:
You report to the Chief Information & Security Officer (CI&SO), and you own the build and run of our security program company wide.
Aurigo builds mission critical AI native SaaS for capital infrastructure and government. Masterworks, Primus, Essentials and our AI product Lumina are trusted with highly regulated public sector and private sector data across four geographies. We hold SOC 1 and SOC 2 Type II, FedRAMP, GovRAMP and ISO 22301, with ISO 42001 close behind. Bangalore is a Global Capability Centre where global functions are owned and held accountable, and this role is one of them.
Aurigo runs a mature, advanced defense in depth posture. This role takes it further: operating it with greater precision, governing an identity and agent population growing faster than any human one, and using AI to defend at the speed our adversaries now attack.
Requirements:
- 14+ years in information and cyber security, including 6+ years leading security teams and at least 2 leading managers or principal level engineers. You have owned security for a SaaS product company at scale, building and running it rather than only governing it.
- You have run vulnerability management as an operational discipline at scale, with published SLAs, risk based prioritisation and remediation delivered through engineering. You can talk about aging curves and recurrence rates from memory.
- Direct experience governing machine and non-human identity, and practical command of AI and LLM security risk with real experience applying AI to security operations rather than only defending against it.
- Hands on depth in at least four of: identity and privileged access; endpoint detection and response and detection engineering; cloud security across AWS and Azure; application and product security; secure access service edge and CASB; data protection. You have operated inside a live authorization regime such as FedRAMP, GovRAMP, DoD IL4 or IL5, PCI DSS or HITRUST.
- You have been incident commander for a material security incident, including the executive and customer communication that came with it. You can brief a board or audit committee and hold a technical argument with a staff engineer on the same day, and you have led a global function from an India GCC with genuine accountability rather than delivery support.