Senior Cloud Security Engineer
Delta Exchange
IndiaPosted 24 days ago
Skill Required
Cloud EngineerSecurity EngineerCloud SecuritysecurityCloudDevOpsAWSandFulltime
Key highlights
- Daily traded volume of ~$0.5 billion
- 50-100 person dev team
- Founded by IIT and ISB graduates
- Frequent hands-on Terraform review for security gaps
- AWS-native infrastructure
- Role includes building evidence dashboards for non-security leadership
Role overview
Delta is a rapidly growing cryptocurrency derivatives exchange (founded 2018) with ~$0.5 billion daily traded volume, backed by top crypto funds and crypto projects. The company is re-imagining and re-building the financial system as an innovative, mission-driven fintech. The founding team includes IIT and ISB graduates with prior experience at major financial institutions (Citibank, UBS, GIC) and notable tech ventures (TinyOwl). With approximately 250 employees and a 50-100 person development team, all infrastructure runs on AWS.
Responsibilities
- Verify that infra implementations match the security model — continuously, not quarterly.
- Build automated compliance checks and drift detection (AWS Config, Steampipe, custom tooling, whatever works)
- Review Terraform PRs for IAM, SCP, and network security gaps before they hit production.
- Own credential lifecycle: rotation, PAM, JIT access, session recording.
- Write and tune detection rules in OpenSearch SIEM.
- Build evidence dashboards that prove security posture to non-security leadership.
- Evaluate security tooling (build vs buy) and own the recommendation with documented tradeoffs.
Requirements
- 5+ years in infrastructure or security engineering, with at least 2 years focused on AWS security
- IAM beyond basic roles — you understand policy evaluation logic, permission boundaries, cross-account access patterns
- Have built automated security checks that run in production (any tooling)
- Can read and critically review Terraform for security posture
- Have operated PAM tooling or credential rotation in production (any tool)
- Comfortable owning a security domain end-to-end without constant direction
Nice to have
- Worked at an org < 500 people where you were one of the very few (or the only) security engineers
- Multi-account AWS Organizations / SCP experience.
- Wrote SIEM detection rules in production (any platform — OpenSearch, Splunk, Elastic, etc.)
- Regulated fintech, exchange, or payments background.
- Built security evidence/reporting that non-security people actually used.
Additional details
- Most innovative cryptocurrency derivatives exchange
- Daily traded volume of ~$0.5 billion, increasing
- Bigger than all Indian crypto exchanges combined
- Offer the widest range of derivative products
- Serving traders all over the globe since 2018
- Founding team comprised of IIT and ISB graduates
- Business co-founders previously worked with Citibank, UBS and GIC
- Tech co-founder previously co-founded TinyOwl and
- Funded by top crypto funds (Sino Global Capital, CoinFund, Gumi Cryptos) and crypto projects (Aave and Kyber Network)
- Dedicated security engineer role
- Company size: ~250 people, 50-100 person dev team
- All infra is AWS
- DevOps builds infrastructure; security engineer makes sure it's secure and can prove it
- hands-on role
- When the CTO asks, "Are we secure?" you pull up a dashboard, not a slide deck
- Own the security posture of the infrastructure from shaping how access and controls are modelled, to verifying they hold in practice