
Lead Product Security and Compliance Engineer
Real job — pulled straight from Big Happy’s careers page · Verified October 10, 2026 · No reposts.
Job description
Big Happy is hiring a Lead Product Security and Compliance Engineer — a full-time, based in Panchkula, India role. Apply directly on Big Happy's careers page below.
Lead Product Security and Compliance Engineer
Department: Tech Dev
Employment Type: Full Time
Location: Panchkula, Sector 11, India
BigHappy is looking for a Senior/Lead Product Security & Compliance Engineer to be the org's go-to authority on product security. Someone who can own the problem end-to-end rather than hand off findings and move on. This is a senior, largely independent role: you'll set the security standards our engineering teams work to, contribute to and maintain our SOC 2 compliance from control implementation through audit readiness, and build the tooling and culture that catches vulnerabilities before they ship.
- Candidates must be open to work within USA time zones EST/EDT and PST/PDT hours.
Key Responsibilities
Own product security end-to-end. Identify vulnerabilities across the full stack: application code, third-party dependencies, APIs, and cloud/infrastructure configuration.
- Work directly with engineering teams to assist with fixing what you find
- Pairing on remediation, explaining root cause, and building their ability to catch similar issues themselves, not just filing reports over the wall.
- Contribute and maintain SOC 2 compliance : control implementation, evidence collection, audit readiness, and ongoing maintenance as controls evolve.
- Champion secure development practices org-wide.
- Secure SDLC, code review guidelines, threat modeling for new features, and security training/enablement for engineers.
- Select, set up, and manage the security tooling stack.
- SAST/DAST scanning, dependency and vulnerability scanning, secrets detection, and coordination of periodic penetration tests.
- Own security incident response
- Detection, triage, remediation, and blameless post-incident review, including the process itself, not just individual incidents.
- Own access control and data protection practices.
- Least-privilege access reviews, data classification, and encryption standards across systems.
- Track and report on security posture and compliance status to leadership, in terms non-security stakeholders can act on.
- Stay current on emerging threats, relevant CVEs, and evolving compliance requirements (SOC 2 today, maybe ISO 27001 as we scale) and translate that into concrete changes to our practices.
- Run vendor security assessments, maintain security policy documentation, and act as the primary point of contact for external auditors.
- Build a security-first culture across engineering. The goal is a trusted advisor teams want to loop in early, not a gatekeeper they route around.
Skills, Knowledge and Expertise
Must-Have Skills
- 6+ years of experience in product/application security, including demonstrated ownership of a SOC 2 (or comparable) compliance.
- Either built from scratch or carried through multiple audit cycles.
- Strong understanding of common vulnerability classes (OWASP Top 10 and beyond), with hands-on experience finding and fixing them, not just reading scanner output.
- Experience embedding security into the SDLC and shifting developer behavior.
- Able to influence practices across teams without formal authority and without becoming a blocker to shipping.
- Familiarity with cloud security, AWS preferred to align with our infrastructure, and working knowledge of modern security tooling (SAST/DAST, SCA, secrets scanning).
- Hands-on ability to read, review and suggest fixes in production code in at least one backend language (Go, Node.js, Python or Java).
- Strong communication skills. This role works cross-functionally with engineering, operations, and leadership, and needs to translate technical risk into business terms auditors, customers, and executives can act on.
- Relevant certifications - CISSP, OSCP, CCSK, or similar.
- Experience with Go language, including Go-specific security tooling.
- Prior experience in a startup or scale-up environment, balancing security rigor against shipping speed.
- Experience with ad-tech, martech, or another high-throughput, latency-sensitive domain.
- Experience taking a company through ISO 27001 or a similar framework beyond SOC 2.
- Experience running or coordinating penetration testing engagements with external vendors.
Benefits
Inclusive Culture & Collaborative Environment: Our workplace thrives on collaboration, inclusivity, and engagement. From cross-functional 1:1s to team building activities like movie outings, events, and office get-togethers, we ensure every team member feels connected, valued, and empowered to contribute meaningfully.
Get Lead Product Security and Compliance Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for Lead Product Security and Compliance Engineer at Big Happy?
The required skills for Lead Product Security and Compliance Engineer at Big Happy include: SOC 2, AWS, Go, Node.js, Python, Java, CISSP, ISO 27001.
What is the seniority level for Lead Product Security and Compliance Engineer at Big Happy?
Lead Product Security and Compliance Engineer at Big Happy is a Senior / Lead level position.
How do I apply for Lead Product Security and Compliance Engineer at Big Happy?
You can view the full description and apply for Lead Product Security and Compliance Engineer at Big Happy on EchoJobs: https://echojobs.io/job/big-happy-lead-product-security-and-compliance-engineer-tech-dev-87h62.