CISO | Scrabble
Job Description
Scope and Responsibilities: Security Leadership & Strategy • Define and lead MoEngage’s enterprise security strategy, architecture, and roadmap • Elevate security as a core engineering imperative — not a checkbox • Build a high-skill, lean and impact-driven security organization, optimizing structure without immediate team expansion. Cloud Security (Primary Focus) • Secure a fully AWS-hosted product environment operating across 7 global regions and ~15,000 active production EC2 instances at scale • Strengthen multi-account cloud governance and controls (3 major accounts today) • Drive identity & access hardening, IAM governance, vaulting & federation best practices • Continuous monitoring and automated remediation through Cloud SecOps best practices Application & API Security • Ensure secure engineering by embedding threat modeling, code security, automation in CI/CD • Enhance security of microservices, large API surfaces, SDK integrations, and customer facing components • Implement mature vulnerability lifecycle management with measurable MTTR improvements • Build bot defense, abuse prevention and runtime protection capabilities Developer Security Enablement • Ensure developers are security fluent through training, tooling and guardrails • Strong working knowledge of GitHub and software supply chain security required Network Architecture & Infrastructure Security • Review internal and perimeter security designs for evolving global scale • Implement modern zero trust and continuous verification models • Drive secure containerization, orchestration, and cross-region resiliency Governance, Risk & Compliance • GRC and privacy oversight secondary; operational execution supported by existing team members • Ensure compliance success emerges naturally from strong foundational controls Incident Response & Risk Monitoring • Ownership of detection and response frameworks across cloud & data assets • Lead post-incident root cause analysis and containment strategy Ideal Candidate Profile: Core Requirements • 15–18 years of security leadership experience with hands-on cloud engineering background • Former developer with working depth in securing complex production environments • Solid grasp of AWS internal services, networking, identity, encryption, and distributed systems security • Proven ability to drive change and influence senior engineering leaders • Experience leading high-performance security teams in hyper-growth environments Preferred Experience • Experience in SaaS or high-traffic B2C companies (sector flexibility — capability is primary)