Careers at Nuvena

Security & Compliance Lead

Own security and compliance for every Nuvena product and client deployment: VAPT, audits, ISO 27001 and the DPDP Act.

Barakhamba Road, New Delhi4–5 yearsFull-time · in officeTechnical

About Nuvena. Nuvena builds Navio, the Execution Operating System: every promise a company makes or is owed — in a contract or to a team — gets an owner, a follow-up and proof.

Role Summary

You own security and compliance for everything Nuvena builds and runs: Navio OS, Navio On It, our internal systems and the deployments at our clients. You keep our products secure, our policies current and our audits clean, in line with India's Digital Personal Data Protection Act and global security standards.

Key Responsibilities

  • Secure all our products and infrastructure (AWS, Azure, Linux, Docker): hardening, access control, secrets, logging, monitoring and backups.
  • Run VAPT on our web apps, mobile apps and APIs every release, and manage external audits by CERT-In empanelled auditors; track every finding to closure.
  • Keep a complete audit log of findings, fixes, evidence and sign-offs, ready for any client or regulator.
  • Own compliance with the DPDP Act 2023 and the DPDP Rules: data map, consent and notices, retention and deletion, data-principal requests and breach handling; act as our privacy and grievance contact.
  • Lead ISO/IEC 27001 (and 27701) from gap assessment to certification, and SOC 2 when clients need it.
  • Write and maintain our security policies: access, incident response, BCP/DR, vendor risk and secure development.
  • Meet the CERT-In Directions: incident reporting within 6 hours, 180-day log retention and clock synchronisation.
  • Maintain security at client deployments: patching, periodic VAPT, client security questionnaires and audits.
  • Track new laws and standards, including RBI, SEBI and IRDAI guidelines for our banking and insurance clients, and keep our controls current.
  • Train the team on secure coding, and review code and architecture for security.

Must Have

  • 4–5 years in cybersecurity, with hands-on VAPT of web apps, APIs and mobile apps (Burp Suite, OWASP ZAP, Nmap, OWASP Top 10, MASVS).
  • Has implemented ISO 27001 controls or a SOC 2 programme end to end.
  • Working knowledge of the DPDP Act and the CERT-In Directions.
  • Cloud and Linux security on AWS or Azure; containers and CI/CD.
  • Clear writing: policies, audit reports and client security responses.

Good To Have

  • OSCP, CEH, ISO 27001 Lead Auditor or Implementer, CISA, CISM or CompTIA Security+.
  • BFSI security frameworks (RBI, SEBI CSCRF, IRDAI) or government audits (CERT-In empanelled, STQC, MeitY).
  • GDPR, or the UAE or Saudi personal data protection laws, for international clients.
  • SIEM and EDR tools, threat modelling and a secure SDLC.

What We Expect From Everyone

  • Go-getter
  • Problem-solver
  • Open-minded
  • Takes decisions
  • Owns the outcome
  • Works as one team
See How We Work