- Sector
- AI
- City
- Bengaluru
- Area
- Koramangala and Outer Ring Road
- Experience
- 5 years and above
- Role family
- Other
- Employment type
- FullTime
- Salary
- Not disclosed
- Posted
- 16 Jun 2026 · 2 months ago
- Last checked
- 7 Sept 2026
About the role
About Sarvam
Sarvam is building the bedrock of Sovereign AI for India. The company is developing India’s full-stack sovereign AI platform, building across research, models, infrastructure and applications with a singular focus on making AI genuinely work for India. Sarvam works with leading enterprises and public institutions and is backed by Lightspeed, Peak XV, and Khosla Ventures. Sarvam partners with India’s leading brands, including Tata Capital, SBI Life, CRED, IDFC, and LIC.
About the Role
We work with regulated and financial institutions, which means our internal IT and security posture is held to the same bar as our products. We're hiring an IT Lead to own and build Sarvam's internal IT and IT-security function from the ground up - identity, endpoints, network, data protection, and the audit/compliance evidence machinery that lets us pass SOC 2, ISO 27001, and customer and regulatory audits without scrambling.
This is a hands-on, 0→1 role. You will set up the tooling, write the runbooks, and operate the controls yourself in the early days, then scale a lean team as the company grows. You'll partner closely with Security/CISO, People, and Finance, and you'll be the person auditors talk to.
What You’ll Do
Identity, Tools & Access
IdP administration (Okta / Entra / Google) - SSO, SCIM, conditional access
MFA / passkey enforcement - phishing-resistant auth for privileged accounts
Manage all internal tools, services for productive/efficient use
Joiner-Mover-Leaver automation - provisioning and offboarding to defined SLAs
Quarterly access reviews - User Access Review (UAR) evidence ready for auditors
Endpoint
MDM across Mac, Windows and Linux - fleet enrollment, compliance baselines
EDR operations - deploy, triage, quarantine workflows
Disk encryption with key escrow - enforced and verifiable
Privilege management - no standing local admin, elevation-on-demand
Network, Cloud & Remote Access
ZTNA administration - per-app access with device-posture checks
VPN management - always-on, no split-tunnel for production
DNS filtering - endpoint-level, network-independent
Cloud and SaaS administration - tenant security configuration, identity and access governance across our cloud and SaaS estate
Data Protection
DLP across endpoint and SaaS - USB, clipboard, email, off-network coverage
SASE / SWG - web filtering and shadow-IT discovery
Audit & Compliance
ISO 27001 / SOC 2 evidence operations - logs, inventories and reports on demand
Asset lifecycle - procurement to certified disposal, with an auditable trail
SaaS / vendor register - inventory ownership and security reviews
Vendor management - selection, contracts, security reviews, and ongoing accountability
Operations
SIEM log forwarding - endpoint and IdP events queryable
ITSM discipline - ticket trails that stand up as audit evidence
Incident response - device isolation, forensics pull, timeline writing
Remote-wipe / lost-device runbook - tested and SLA-bound
BCP / DR for IT systems - annual test evidence
The rest of this description is on the employer’s own page.