Principal Security Manager (India)
Job description
About the role
Truveta is seeking a highly experienced Principal Security Manager to oversee and lead security initiatives across its entire technology platform, including applications, cloud infrastructure, and platform operations. This role requires a strategic thinker with strong technical expertise who can develop, implement, and maintain comprehensive security protocols to protect sensitive health data and ensure compliance with industry standards. The successful candidate will work closely with engineering, product, and platform teams to embed security best practices into all aspects of development and deployment, fostering a security-first culture within the organization. This position offers an exciting opportunity to shape the security posture of a rapidly growing health data company committed to innovation and data privacy.
Key facts
What you'll do
- Lead the design, development, and implementation of security policies, standards, and procedures across all technology domains, including applications, cloud infrastructure, and platform services.
- Collaborate with engineering teams to integrate security controls into the software development lifecycle, including secure coding practices, vulnerability management, and automated security testing within CI/CD pipelines.
- Develop and enforce data protection strategies, including encryption standards, access controls, and data handling policies, to safeguard sensitive health information.
- Conduct comprehensive security assessments and risk analyses of internal systems, cloud environments, and third-party vendors, ensuring compliance with relevant standards and regulations.
- Manage vulnerability management processes, including regular scanning, patching, and remediation efforts to reduce attack surface and mitigate potential threats.
- Strengthen identity and access management (IAM) systems, implementing least privilege principles, multi-factor authentication, and role-based access controls to ensure secure user and system access.
- Enhance security monitoring and incident detection capabilities by deploying and managing SIEM solutions, intrusion detection systems, and other security tools.
- Lead incident response efforts, coordinating investigations, containment, eradication, and recovery activities in the event of security breaches or threats.
- Design and implement secure cloud architecture, including network segmentation, traffic filtering, and edge security measures to protect against external and internal threats.
- Promote the adoption of modern security frameworks such as zero trust architecture, defense-in-depth strategies, and compliance standards relevant to healthcare data.
- Work with engineering teams to incorporate security considerations into system and application design, ensuring security is a foundational aspect of product development.
- Contribute hands-on expertise by participating in security reviews, code audits, and automation efforts to improve security processes.
- Mentor and support engineering and security teams, fostering a culture of continuous improvement and security awareness across the organization.
- Stay current with emerging security threats, industry trends, and best practices, and proactively recommend enhancements to security posture and policies.
- Collaborate with legal, compliance, and privacy teams to ensure adherence to healthcare regulations and data privacy laws.
- Support the development of security training programs and awareness initiatives for technical and non-technical staff.
Requirements
- Bachelor's or Master's degree in Computer Science, Information Technology, or a related field.
- A minimum of 10 years of experience in software engineering, security, or related disciplines, with proven leadership in security management roles.
- Extensive knowledge of cloud security, application security, and security best practices, particularly in cloud-native environments.
- Strong understanding of security frameworks, standards, and compliance requirements relevant to healthcare and data privacy.
- Hands-on experience with CI/CD tools and integrating security controls into automated pipelines.
- Proficiency in programming languages such as Python, Java, or Go, with the ability to contribute to security automation and tooling.
- Familiarity with security technologies including firewalls, intrusion detection/prevention systems, vulnerability scanners, and encryption tools.
- Experience conducting security assessments, penetration testing, and vulnerability management.
- Excellent problem-solving skills, with the ability to analyze complex security issues and develop effective solutions.
- Strong communication skills to articulate security risks and strategies to technical and non-technical stakeholders.
- Ability to work collaboratively in a fast-paced, dynamic environment with cross-functional teams.
- Experience working with healthcare data or in healthcare technology is a plus.
Nice to have
- Relevant security certifications such as CISSP, CISM, or AWS Certified Security Specialty.
- Prior experience working with health data, healthcare systems, or in a regulated environment.
- Knowledge of data privacy laws and compliance standards such as HIPAA, GDPR, or HITRUST.
- Experience with automation, scripting, and DevSecOps practices to streamline security operations.
Skills & tools
- Cloud platforms (AWS, Azure, GCP)
- Security tools (SIEM, IDS/IPS, DLP)
- Programming languages (Python, Java, Go)
- CI/CD tools (Jenkins, GitLab, CircleCI)
- Infrastructure as code (Terraform, CloudFormation)
- Security frameworks (zero trust, defense-in-depth)
- Vulnerability management tools and processes
- Identity and access management systems
Practical notes
This position is based on-site in Hyderabad, India, and is open to candidates who require visa sponsorship. The role offers comprehensive benefits, including health insurance, paid time off, and opportunities for professional growth and development. The company values diversity and encourages qualified candidates from all backgrounds to apply. Applications will be accepted until the position is filled, and candidates are encouraged to submit their applications promptly. The role involves working closely with cross-functional teams, and candidates should be prepared for a collaborative, fast-paced environment focused on building secure, scalable health data solutions.