Lead Security Engineer - 11807
Coupa Software, Inc. · pune, Maharashtra, India
Software Development · 1,001-5,000 employees
About the role
The Lead Security Engineer will architect and implement multi-cloud security controls and automated guardrails to protect enterprise and customer data. They will also lead vulnerability management, incident response, and mentor the security engineering team on technical standards.
What they look for
Requirements
Candidates must have 10+ years of security engineering experience with deep expertise in AWS and production cloud environments. A bachelor's degree in a related field and proficiency in software engineering fundamentals like Python or Go are required.
Benefits
Full description
Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.
Why join Coupa?
🔹 Pioneering Technology: At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend.
🔹 Collaborative Culture: We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence.
🔹 Global Impact: Join a company where your work has a global, measurable impact on our clients, the business, and each other.
Learn more on Life at Coupa blog and hear from our employees about their experiences working at Coupa.
The Impact of a Lead Security Engineer at Coupa
Coupa's Security Engineering team protects our enterprise, product, platform, and customer data at scale. As Lead Security Engineer, you will be a hands-on technical leader on the Security Engineering team — architecting and building cloud security controls, setting engineering standards, and partnering closely with Engineering, IT, and Compliance to ship durable, automated security tooling rather than one-off fixes. You thrive on ambiguity, sweat the implementation details, and take pride in solutions that scale across hundreds of accounts and services.
\n
What You'll Do:
- Architect and build multi cloud security controls across Coupa's cloud environment. VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
- Build policy-as-code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after the fact reviews.
- Harden containerized workloads - image scanning, admission control, pod security standards, and runtime detection.
- Write auto-remediation for cloud misconfiguration and drift so common findings close without manual ticket routing.
- Own Vulnerability management program, act as the technical escalation point for security incidents and vulnerability findings - leading forensics, containment, and root-cause analysis using cloud-native and EDR tooling, and driving remediation to closure.
- Partner with Risk & Compliance to translate audit framework requirements (SOC 2, ISO 27001, PCI-DSS, FedRAMP) into concrete technical controls, and automate evidence collection by integrating cloud telemetry with GRC tooling.
- Mentor other security engineers through design review, threat modeling, and code/architecture review; raise the technical bar for the whole team.
- Own reference architectures, threat models, and runbooks for the security tooling you build; participate in and help improve the on-call rotation.
What You'll Bring to Coupa:
- 10+ years of security engineering experience, including significant hands-on work securing production cloud environments at scale, plus experience leading projects or mentoring other engineers.
- Deep, hands-on AWS security expertise - IAM, VPC/networking, KMS, GuardDuty, Security Hub, Config, and Organizations/SCPs; working knowledge of GCP or Azure security is a plus.
- Production experience with Terraform (or equivalent IaC) and policy-as-code frameworks, plus container/Kubernetes security tooling.
- Strong software engineering fundamentals - Python and/or Go, Git-based workflows, and building/maintaining CI/CD security integrations (SAST, DAST, SCA).
- Experience with SIEM/SOAR platforms and vulnerability management tooling (e.g., Wiz, Qualys, Tenable) - building detections and workflows, not just consuming dashboards.
- Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP, NIST 800-53) sufficient to translate control requirements into engineering work.
- Excellent written and verbal communication skills - able to write clear technical design docs and explain risk trade-offs to auditors and engineering leadership alike.
- Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
- Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications.
- Some international travel may be required.
\n
At Coupa, we are 100% committed to creating and nurturing an environment that supports your physical, mental, and community well-being . We offer a comprehensive suite of benefits designed to help you and your family thrive:
Global Well-Being Perks (For All Employees Globally)
- Global Wellness Days: Enjoy two designated, company-wide paid wellness days off each year (typically the first Friday in March and the last Friday in September) so the entire global team can unplug, step away, and recharge together .
- Birthday Time-Off: Celebrate your day! Coupa provides a paid day off on your birthday or another day of your choice within your birthday month .
- Volunteer Time Off (VTO): Giving back is in our DNA. We offer 40 hours of paid VTO annually to support the community initiatives and volunteer programs you are passionate about .
- Employee Assistance Program (EAP): Access free, confidential, 24/7/365 counseling and resources for emotional support, work-life solutions, financial advice, legal guidance, and support for new parents .
- Business Travel Protection: Travel with peace of mind. Zurich Travel Assist provides medical, safety, pre-trip planning, and emergency support during any business travel .
- Referral Bonus Program: Share the Coupa experience! Receive generous monetary referral bonuses when you successfully refer talented friends or acquaintances who are hired into open roles .
Please note: In addition to these global well-being perks, Coupa offers highly competitive, location-specific benefits packages (which include comprehensive medical/dental insurance, retirement/pension plans, and life or accident protection) tailored to your primary work location. Your recruiter will walk you through the specific regional benefits package for this role during the interview process.
Coupa complies with relevant laws and regulations regarding equal opportunity and offers a welcoming and inclusive work environment. Decisions related to hiring, compensation, training, or evaluating performance are made fairly, and we provide equal employment opportunities to all qualified candidates and employees.
Please be advised that inquiries or resumes from recruiters will not be accepted.
By submitting your application, you acknowledge that you have read Coupa’s Privacy Policy and understand that Coupa receives/collects your application, including your personal data, for the purposes of managing Coupa's ongoing recruitment and placement activities, including for employment purposes in the event of a successful application and for notification of future job opportunities if you did not succeed the first time. You will find more details about how your application is processed, the purposes of processing, and how long we retain your application in our Privacy Policy.