Build implemented security & compliance,
with us
Kaitara Security delivers implemented security & compliance for businesses — not shelf reports — across DPDP, CERT-In, the IT Act and medical-device cybersecurity, on our own scanning and monitoring platforms. You'll work directly with the founder, own real client outcomes early, and grow fast.
Who we're looking for (both roles)
- M.Tech in Cybersecurity / Information Security (or CSE with a security specialisation, or an equivalent strong security background). 0–3 years' experience; sharp freshers with a solid security thesis are encouraged.
- Fundamentals — networking, OS, web security (OWASP Top 10), basic cryptography, Linux, scripting (Python preferred).
- Clear written English — we ship documents clients act on; writing is core, not optional.
- Intellectual honesty — “let me verify against the source” over guessing. For anything regulatory, we work from the primary text, never from memory.
- Builder temperament — comfortable with broad ownership, direct mentorship and fast feedback in a small, founder-led team.
Security Analyst
VAPT & Scanning · grows into Medical-Device Cybersecurity
Primary — You do the security testing and turn it into evidence clients act on.
- Perform vulnerability assessments and penetration tests using a modern security-testing toolchain and our in-house scanning platform.
- Manual web-application testing: IDOR, authentication and session handling, API security, sensitive-data exposure, rate limiting.
- Write findings reports rated for business impact; run the clean re-test after the client remediates.
- Help extend our scanning platform with new checks; track CERT-In and regulatory changes that affect what we test for.
Growth track — Medical-Device Cybersecurity
Assist on device cybersecurity technical files — SBOM, threat models, security risk assessments — and learn the standards (IEC 81001-5-1, EU-MDR / MDCG 2019-16, FDA §524B, AAMI TIR57 ↔ ISO 14971), working closely with the founder.
Must-have: Hands-on web-application penetration testing, vulnerability triage and CVSS scoring, scripting (Python). (1–3 yrs: independent VAPT engagements, a report portfolio.)
Good-to-have: OSCP / CEH progress, CI/CD or cloud (AWS/GCP) security, embedded/IoT exposure, CTF experience.
Apply for Security Analyst →Compliance & Privacy Analyst
DPDP / CERT-In · grows into Security Monitoring & Client Success
Primary — You assess what applies to a client and help implement it — the core of what Kaitara sells.
- Run regulatory-profile assessments and gap analyses against DPDP Act 2023 + Rules 2025, CERT-In Directions 2022, and the IT Act.
- Help implement obligations: privacy notices, consent, grievance mechanism, breach response (72-hour timeline), vendor data-processing agreements.
- Draft and review compliance documents; keep our regulatory references current and cited to the primary source; support clients through our compliance platform.
- Support clients through live incidents — the CERT-In six-hour report and the DPDP Rule 7 notifications — using our incident tooling, and run the follow-up so the same gap does not recur.
Growth track — Security Monitoring & Client Success
Help stand up and run our monitoring stack for clients — currently in pilot, so you would be there from the first tenant — tuning detections, mapping alerts to their CERT-In / DPDP obligations, and owning the day-to-day client relationship. (Full product training provided.)
Must-have: Security fundamentals + real interest in law / privacy / GRC; disciplined, precise writing; client-ready communication. (1–3 yrs: hands-on experience implementing a compliance framework — DPDP, ISO 27001 or similar.)
Good-to-have: DPDP / GDPR / ISO 27001 coursework or certifications; exposure to GRC or privacy tooling; familiarity with security-monitoring concepts.
Apply for Compliance & Privacy Analyst →