Lead Product Security Engineer - Cloud Security
Product
Bengaluru, Karnataka, India
About Tekion:
Positively disrupting an industry that has not seen any innovation in over 50 years, Tekion has challenged the paradigm with the first and fastest cloud-native automotive platform that includes the revolutionary Automotive Retail Cloud (ARC) for retailers, Automotive Enterprise Cloud (AEC) for manufacturers and other large automotive enterprises and Automotive Partner Cloud (APC) for technology and industry partners. Tekion connects the entire spectrum of the automotive retail ecosystem through one seamless platform. The transformative platform uses cutting-edge technology, big data, machine learning, and AI to seamlessly bring together OEMs, retailers/dealers and consumers. With its highly configurable integration and greater customer engagement capabilities, Tekion is enabling the best automotive retail experiences ever. Tekion employs close to 3,000 people across North America, Asia and Europe.
Summary
We are seeking a Lead Product Security Engineer – Cloud Security to lead the operational and engineering execution of Tekion’s cloud security program across cloud-native products, infrastructure, platforms, and data services. This role combines hands-on technical depth with program ownership, stakeholder leadership, and people-management exposure.
You will partner with CloudOps, Platform Engineering, Product Engineering, Data, IT, and Security Operations to improve cloud preparedness for new products, operate CSPM and DSPM capabilities, drive vulnerability closure within strict SLAs, and coordinate cloud-security support throughout incident detection, response, recovery, and continuous improvement.
Duties & Responsibilities
Cloud Security Operations Management
Lead day-to-day cloud security across AWS and Azure, including intake, triage, prioritization, assignment, escalation, validation, exception handling, and closure.
Define operating rhythms, runbooks, ownership models, dashboards, and executive metrics for cloud risks, incidents, control health, and remediation progress.
Manage operational backlogs and balance planned improvements, urgent exposures, product launches, audit needs, and incident-driven work.
Incident Management & SOC Partnership
Act as the cloud security lead during cloud-related incidents, working with the SOC and incident response teams on scoping, containment, eradication, recovery, and stakeholder communication.
Provide cloud context, identity analysis (preferrably), configuration evidence, and technical guidance to accelerate investigation and decision-making.
Maintain cloud incident playbooks, escalation paths, forensic readiness, and post-incident action tracking; ensure lessons learned become durable control and detection improvements.
Vulnerability Closure & SLA Governance
Facilitate end-to-end closure of cloud vulnerabilities, misconfigurations, identity risks, data exposures, and control gaps with infrastructure and product owners.
Enforce stricter risk-based remediation SLAs, monitor aging and overdue findings, conduct regular reviews, and escalate material non-compliance through defined governance channels.
Validate remediation evidence, govern exceptions and compensating controls, identify repeat root causes, and sponsor systemic fixes that reduce recurrence.
New Product Cloud Preparedness & Infrastructure Alignment
Engage early with new product and platform initiatives to assess cloud preparedness, shared-responsibility boundaries, infrastructure dependencies, data flows, identity models, logging, resilience, and security support requirements.
Lead cloud security design reviews and launch-readiness assessments; define minimum launch criteria, required guardrails, residual risks, and accountable owners.
Partner with CloudOps and Infrastructure teams to deliver secure landing zones, IAM patterns, network controls, encryption, secrets management, monitoring, backup, and operational support readiness.
CSPM & DSPM Operations
Own hands-on operation and optimization of CSPM/CNAPP/DSPM capabilities, including account onboarding, policy tuning, integrations, risk correlation, workflow automation, and posture reporting.
Improve signal quality through suppression governance, ownership enrichment, risk-based prioritization, baselining, and measurable reduction of false positives and stale findings.
People Leadership & Stakeholder Management
Provide technical direction, work allocation, coaching, feedback, and development support to cloud security engineers; contribute to hiring and capability planning.
Build accountability and a high-ownership culture while maintaining psychological safety, clear expectations, and constructive cross-functional relationships.
Communicate cloud risk, operational health, incident impact, SLA performance, and investment needs clearly to engineering and security leadership.
Qualifications
Required
Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Engineering, or a related field; equivalent experience considered.
10–15 years of experience in cloud security, product security, infrastructure security, security operations, or related engineering roles, including technical leadership responsibilities.
Deep hands-on experience with AWS and/or Azure security, including IAM, networking, containers/Kubernetes, encryption, secrets, logging, monitoring, and infrastructure-as-code.
Demonstrated operational experience with CSPM/CNAPP and practical exposure to DSPM operations, data discovery, classification, access analysis, and exposure remediation.
Experience leading cloud incident response support with SOC teams and coordinating incident actions across engineering, infrastructure, and business stakeholders.
Strong vulnerability-management, SLA-governance, exception-management, escalation, and remediation-closure experience.
Experience assessing cloud readiness for new products and translating security requirements into actionable infrastructure and engineering plans.
People-management exposure or demonstrated experience mentoring engineers, coordinating team delivery, and influencing without authority.
Strong scripting or automation capability using Python, Bash, Terraform, policy-as-code, or equivalent technologies.
Preferred
Experience in high-scale SaaS, multi-cloud, or cloud-native product environments.
Familiarity with NIST CSF, NIST incident response guidance, CIS benchmarks, ISO 27001, and SOC 2.
Exposure to CIEM, CWPP, cloud detection engineering, SIEM/SOAR integrations, and data-loss prevention controls.
Industry-recognized cloud security or security leadership certifications are a plus.
Effective 4 Aug 2026, Current Tekion Employees should apply via the Internal Job Board in Ashby
Tekion is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, victim of violence or having a family member who is a victim of violence, the intersectionality of two or more protected categories, or other applicable legally protected characteristics.
For more information on our privacy practices, please refer to our Applicant Privacy Notice here.