967 Compliance Engineer jobs in India

Senior Compliance Engineer

Bangalore, Karnataka Trellix

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**_Job Title:_**
Senior Compliance Engineer
**About Skyhigh Security:**
Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.
Since 2011, organizations have trusted us to provide them with a complete, market-leading security platform built on a modern cloud stack. Our industry-leading suite of products radically simplifies data security through easy-to-use, cloud-based, Zero Trust solutions that are managed in a single dashboard, powered by hundreds of employees across the world. With offices in Santa Clara, Aylesbury, Paderborn, Bengaluru, Sydney, Tokyo and more, our employees are the heart and soul of our company.
Skyhigh Security Is more than a company; here, when you invest your career with us, we commit to investing in you. We embrace a hybrid work model, creating the flexibility and freedom you need from your work environment to reach your potential. From our employee recognition program, to our 'Blast Talks' learning series, and team celebrations (we love to have fun!), we strive to be an interactive and engaging place where you can be your authentic self.
We are on these too! Follow us on LinkedIn ( and ( .
**_Role Overview:_**
You will be responsible for secure design, development and operation of Skyhigh's products and services. Responsibilities may include threat assessment, design of security components, vulnerability assessment. Ensures products conform to standards and specifications. Develops plans and cost estimates and assesses projects to analyze risks. Responds to customer/client requests or events as they occur. Develops solutions to problems utilizing formal education, judgment and formal process. Maintains substantial knowledge of state-of-the-art security principles, theories, attacks and contributes to literate and conferences. Require thorough knowledge of security practices, procedures and capabilities in order to perform non-repetitive, analytical work.
**About the Role:**
+ You will serve as a critical member of the team who expertly blends technical security knowledge with strategic compliance management.
+ You will be the primary driver of our corporate compliance program. This involves independently managing the full lifecycle of internal and external audits for key certifications like ISO 27001, SOC 2, FedRAMP, and PCI-DSS.
+ You will handle audit preparation, coordinate with auditors, and meticulously gather all required evidence and documentation.
+ You will take direct ownership of developing, maintaining, and communicating our Information Security Management System (ISMS) documentation and policies.
+ You will ensure compliance is not an afterthought by actively reviewing operational controls and participating in IT change management. You will work directly with technical teams to integrate compliance requirements into their workflows and CI/CD pipelines.
+ While compliance is the focus, you will leverage your security engineering knowledge to provide valuable insights. You will personally guide the secure design of systems and translate vulnerability findings into actionable, risk-based remediation plans that align with our compliance framework.
**Qualifications:**
+ 5-10 years of combined experience IT Audit, IT Compliance, or a related Security Engineering role with a strong compliance focus. You are a seasoned professional with deep knowledge of industry-leading security principles and frameworks.
+ Hands-on experience managing audits for multiple standards, particularly ISO 27001, SOC 2, or FedRAMP. You are an expert in independently gathering evidence and presenting a compelling case for certification.
+ Ability to perform both analytical, compliance-focused work and technical, hands-on tasks when needed. Your exceptional analytical, documentation, and organizational skills allow you to manage complex projects with meticulous detail.
+ Excellent communicator with a proven ability to convey complex technical and compliance issues to a wide range of audiences. You excel at collaborating with cross-functional teams to drive process maturity and operational efficiency, serving as a subject matter expert and trusted advisor.
+ Familiar with cloud environments (e.g., AWS, Azure, GCP) and understand the role of DevOps tools (e.g., GitLab, Jenkins) in a modern security and compliance program. You are comfortable thriving in a fast-paced, evolving global environment.
**_Company Benefits and Perks:_**
We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees.
+ Retirement Plans
+ Medical, Dental and Vision Coverage
+ Paid Time Off
+ Paid Parental Leave
+ Support for Community Involvement
We're serious about our commitment to a workplace where everyone can thrive and contribute to our industry-leading products and customer support, which is why we prohibit discrimination and harassment based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
This advertiser has chosen not to accept applicants from your region.

Senior Compliance Engineer

Bengaluru, Karnataka Skyhigh Security

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

About Skyhigh Security:

Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world’s data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.


Since 2011, organizations have trusted us to provide them with a complete, market-leading security platform built on a modern cloud stack. Our industry-leading suite of products radically simplifies data security through easy-to-use, cloud-based, Zero Trust solutions that are managed in a single dashboard, powered by hundreds of employees across the world. With offices in Santa Clara, Aylesbury, Paderborn, Bengaluru, Sydney, Tokyo and more, our employees are the heart and soul of our company.


Skyhigh Security Is more than a company; here, when you invest your career with us, we commit to investing in you. We embrace a hybrid work model, creating the flexibility and freedom you need from your work environment to reach your potential. From our employee recognition program, to our ‘Blast Talks' learning series, and team celebrations (we love to have fun!), we strive to be an interactive and engaging place where you can be your authentic self.


The Role:

  • You will serve as a critical member of the team who expertly blends technical security knowledge with strategic compliance management.
  • You will be the primary driver of our corporate compliance program. This involves independently managing the full lifecycle of internal and external audits for key certifications like ISO 27001, SOC 2, FedRAMP, and PCI-DSS.
  • You will handle audit preparation, coordinate with auditors, and meticulously gather all required evidence and documentation.
  • You will take direct ownership of developing, maintaining, and communicating our Information Security Management System (ISMS) documentation and policies.
  • You will ensure compliance is not an afterthought by actively reviewing operational controls and participating in IT change management. You will work directly with technical teams to integrate compliance requirements into their workflows and CI/CD pipelines.
  • While compliance is the focus, you will leverage your security engineering knowledge to provide valuable insights. You will personally guide the secure design of systems and translate vulnerability findings into actionable, risk-based remediation plans that align with our compliance framework.


Qualifications:

  • 5-10 years of combined experience IT Audit, IT Compliance, or a related Security Engineering role with a strong compliance focus. You are a seasoned professional with deep knowledge of industry-leading security principles and frameworks.
  • Hands-on experience managing audits for multiple standards, particularly ISO 27001, SOC 2, or FedRAMP. You are an expert in independently gathering evidence and presenting a compelling case for certification.
  • Ability to perform both analytical, compliance-focused work and technical, hands-on tasks when needed. Your exceptional analytical, documentation, and organizational skills allow you to manage complex projects with meticulous detail.
  • Excellent communicator with a proven ability to convey complex technical and compliance issues to a wide range of audiences. You excel at collaborating with cross-functional teams to drive process maturity and operational efficiency, serving as a subject matter expert and trusted advisor.
  • Familiar with cloud environments (e.g., AWS, Azure, GCP) and understand the role of DevOps tools (e.g., GitLab, Jenkins) in a modern security and compliance program. You are comfortable thriving in a fast-paced, evolving global environment.
This advertiser has chosen not to accept applicants from your region.

Compliance Engineer - Sustainability Compliance (Remote)

Certivo

Posted today

Job Viewed

Tap Again To Close

Job Description

Certivo turns regulatory evidence into market access. Our AI, CORA, automates supplier outreach, data extraction, and rule checks, then assembles market-ready packets mapped to every product × site × market. We pair automation with deep domain expertise so industrial manufacturers can meet sustainability expectations and regulatory requirements without slowing down launches.


The role

Own sustainability compliance outcomes for industrial customers. You will lead life cycle data collection, model LCAs, produce and maintain EPDs, manage packaging and producer-responsibility obligations, and stand up reporting workflows for enterprise programs. You will also encode your playbooks into CORA so evidence stays current as products, suppliers, and rules change.


Responsibilities

  • Regulatory and program intelligence: track and interpret sustainability frameworks and owner/operator requirements relevant to industrial equipment and components; author applicability rationales and encode thresholds, scopes, and reporting triggers into CORA.
  • CSRD (EU) readiness: lead double materiality pre-work for industrial manufacturers; map ESRS topics (with emphasis on E1 GHG , E2 Pollution , E5 Circular Economy , and relevant social/governance disclosures) to data owners, controls, audit trail, and product‑level links (EPD, packaging, WEEE/batteries touchpoints).
  • CBAM (EU) enablement: define CBAM scope (HS codes), production routes, embedded emissions (direct/indirect), electricity mix, and precursors; collect supplier declarations, build calculation files, and manage transitional reporting and definitive‑phase data flows.
  • EU Batteries Regulation: where in scope (e.g., energy storage, drives/controllers with batteries), build workflows for battery labeling , recycled content , performance/durability , safety , carbon footprint declaration , and battery passport data; coordinate QR/UID strategy and supplier attestations.
  • ESPR / Digital Product Passport (DPP): design attribute sets (UID, material composition, recycled content, repairability/serviceability, software/firmware, documentation) and evidence linkages; pilot payloads and maintenance processes; define how engineering changes trigger DPP updates.
  • Life cycle modeling and EPDs: plan and execute LCAs aligned to ISO 14040/44 and EN 15804+A2; produce EPDs under ISO 14025 and relevant PCRs; coordinate third-party review and program operator verification.
  • Supplier data collection: run multilingual campaigns to collect material specs, process energy, yields and scrap, transport, packaging, CBAM inputs , battery passport attributes , and end‑of‑life assumptions; validate data lineage and quality; commission testing or certificates as needed.
  • Packaging and producer responsibility: gather weights, materials, and labeling data; prepare declarations and filings for packaging EPR where applicable; manage bill of materials and labeling implications for industrial packaging.
  • Product- and portfolio-level carbon: support Scope 3 Category 1 (purchased goods and services) data capture; build emission factor libraries and mapping to parts; maintain auditable calculation files.
  • Reporting and submittals: assemble sustainability evidence packs for buyers, owners, and authorities; prepare materials for contractor submittals and owner/operator documentation.
  • Automation and data quality: define quality gates, curate factor and dataset libraries, and partner with Product and AI to improve extraction accuracy and reduce false positives/negatives.
  • Customer and auditor interface: present models, assumptions, and results; respond to auditor or buyer questions; drive remediation to closure.


Industrial sub-verticals you will support

  • Test and Measurement / Instrumentation: product-level embodied carbon and packaging declarations; EPDs where applicable; VOC/PFAS claims alignment with materials teams.
  • Systems and Controls (HVAC/Automation/Lighting): controller and actuator product families; luminaire component EPD linkages; packaging reporting.
  • Electrical Enclosures, Panels, and Power Distribution: steel and aluminum content tracking, coatings, and packaging; EPDs or embodied-carbon summaries used in projects.
  • PVF / Water and Fire Protection: valves, fittings, polymers and brass content; NSF/ANSI 61/372 coordination with sustainability claims; construction submittal evidence.
  • Drives, Motors, and Motion: motor and drive LCAs and EPDs; efficiency labels linkage to sustainability evidence; packaging data.
  • Utility/Facility Skids and Equipment: multi-product skid LCAs and documentation; owner/operator evidence packs and commissioning documentation.
  • Data Center Infrastructure Components: embodied carbon summaries and EPDs where applicable; packaging reporting for high-volume shipments.
  • On-site Power and Energy Storage: component-level embodied carbon and packaging reporting for gensets, BESS modules, cabinets, and switchgear; commissioning documentation.


Frameworks and programs you will touch (Exposure to all is not required)

  • CSRD / ESRS (EU): double materiality, ESRS topic scoping (E1/E2/E3/E5 plus governance/social where relevant), data controls and audit trail, linkage to product‑level evidence (EPDs, packaging, WEEE/batteries).
  • CBAM (EU): Regulation 2023/956 transitional reporting vs. definitive phase; HS code scoping; embedded‑emissions calculation files (direct/indirect), production routes, electricity mix, precursor accounting; quarterly reporting.
  • EU Batteries Regulation: product labeling, performance/durability, safety documentation, recycled content and carbon‑footprint declarations, and battery passport data capture/maintenance (including QR/UID strategy).
  • ESPR / Digital Product Passport (DPP): attribute design, payload pilots, governance for updates, and links to technical documentation.
  • EPDs and LCA: ISO 14040/44; ISO 14025; EN 15804+A2; PCRs relevant to electrical, mechanical, and construction‑adjacent products; program operators such as UL, ASTM, NSF, EPD International.
  • Carbon accounting: GHG Protocol Scope 1, 2, and 3 with emphasis on Category 1; emission factor sources and data‑quality documentation.
  • Packaging and product stewardship: packaging EPR regimes; WEEE and EU Batteries Regulation where relevant to product lines; labeling and reporting basics.
  • Market and buyer programs: contractor submittals; owner/operator requirements; Buy Clean ‑style requests for embodied carbon where applicable.
  • Trade and market access touchpoints: data capture for mechanisms that require product or material emissions data where applicable (e.g., CBAM‑linked import declarations).


Must-have qualifications

  • 4 to 8+ years in LCA, EPD, or sustainability program management within industrial, electrical, mechanical, or construction-adjacent manufacturing.
  • Hands-on experience building cradle-to-gate LCAs and taking at least one EPD through third-party verification with a program operator.
  • Strong BoM and process understanding; ability to translate engineering and sourcing data into life cycle inventory inputs and auditable models.
  • Proficiency with at least one LCA tool (openLCA, SimaPro, GaBi, One Click LCA) and advanced spreadsheet skills; familiarity with emission factor datasets.
  • Clear written and verbal communication; able to explain assumptions and results to engineers, buyers, and auditors.
  • Process discipline: change control, documentation, and versioning of models and assumptions.


Nice-to-have

  • Experience with packaging EPR reporting and data models for multi-market shipments.
  • Familiarity with sustainability elements of construction product documentation (declarations, contractor submittals, owner/operator requirements).
  • Exposure to organization-level carbon accounting and supplier engagement for Scope 3 data improvement.
  • PLM/ERP experience (Windchill, SAP, Oracle, Arena) and basic SQL or scripting.
  • Multilingual for supplier engagement.


How we work

  • AI plus human: pair with CORA to automate requests, validation, and rule checks while you focus on modeling choices and edge cases.
  • Ownership: measured on readiness, timeliness, and audit performance for named programs.
  • Builder’s mindset: turn playbooks into reusable rule packs and product features.


Interview process

  1. Intro (30 minutes): mutual fit and domain depth.
  2. Technical deep dive (60 minutes): walk us through an LCA and EPD you owned, including data gaps and verification.
  3. Practical exercise (90-minute take-home): given a short BoM and process brief, produce an applicability matrix, a data-collection plan, and a preliminary LCA boundary and assumptions document.
  4. Panel (60 minutes): cross-functional scenario with Customer Success and Product.


Apply

Send your resume or LinkedIn and one or two relevant (redacted) LCA/EPD artifacts you authored to with subject “Compliance Engineer (Sustainability Compliance)

This advertiser has chosen not to accept applicants from your region.

Senior Patch Compliance Engineer

Hyderabad, Andhra Pradesh CirrusLabs

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description

Experience range: 5+ years

Location: Bengaluru and Hyderabad


Position Summary

We are seeking a Senior Patch Compliance Engineer as part of a long-term patch compliance and remediation initiative. This role will be hands-on and technical , while also offering the opportunity to mentor and guide two additional engineers as part of a seven-member global team .

The primary focus is to deploy and validate OS, Office, and third-party patching solutions across enterprise endpoints using SCCM, Intune, Qualys, and PatchMyPC , with additional exposure to tools such as Nexthink, BigFix , and other industry-standard platforms. PowerShell scripting and automation are essential to succeed in this environment.

This role is ideal for a technically skilled professional with strong endpoint patching expertise, excellent scripting capabilities, and a proactive approach to continuous improvement and compliance operations.


  • Key Responsibilities Lead and execute patch deployments across Windows OS, Microsoft Office, and third-party applications using SCCM, Intune, PatchMyPC , and related enterprise tools
  • Create, enhance, and maintain PowerShell scripts to support automation of pre-patch and post-patch processes
  • Validate deployment success, troubleshoot failed installations, and guide junior engineers through remediation efforts
  • Collaborate closely with global team leads, architects, and security teams to align patching activities with compliance goals
  • Monitor patching dashboards, perform queries, and provide real-time status reports on endpoint compliance and system health
  • Help maintain process documentation and contribute to team playbooks for standardized patch workflows
  • Actively support continuous optimization of patching strategies, particularly for third-party application patching , which is a critical focus
  • Coordinate closely with broader platform teams to ensure accurate targeting and risk prioritization of patch cycles


  • Required Qualifications 5+ years of experience in enterprise IT operations, endpoint management, or patch compliance engineering roles
  • Proven expertise in SCCM and Intune , including package deployment, device targeting, and automation
  • Strong hands-on experience with PowerShell scripting and automation for endpoint management
  • Practical understanding of patching lifecycle , remediation best practices, and third-party software support
  • Exposure to Qualys or equivalent vulnerability scanning platforms
  • Strong troubleshooting skills and ability to work independently in a fast-paced enterprise setting
  • Effective written and verbal communication skills in English, with experience in reporting and technical documentation
  • Comfort working across remote, cross-functional teams, including U.S. and LATAM-based resources


  • Preferred Qualifications Experience with PatchMyPC , Nexthink , BigFix , or similar endpoint compliance and analytics platforms
  • Familiarity with Prisma Cloud or other enterprise security posture platforms (contextual understanding only; not day-to-day)
  • Background working in a consultancy or large enterprise client delivery environment
  • Knowledge of industry patching standards and secure configuration frameworks (e.g., CIS Benchmarks)
  • Ability to provide informal mentorship and support to junior or peer-level engineers on the team


  • Why Join Us? Play a central role in a high-impact patch compliance initiative for a Fortune 50 enterprise client
  • Use your automation and scripting skills to help drive efficiency and measurable security outcomes
  • Join a globally distributed team solving real-world compliance challenges across 200K+ endpoints
  • Gain valuable exposure to modern patching and compliance platforms in a collaborative, remote-first setting
This advertiser has chosen not to accept applicants from your region.

Senior Risk Assessment Analyst

520001 Krishna, Andhra Pradesh ₹650000 Annually WhatJobs

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly analytical and detail-oriented Senior Risk Assessment Analyst to join their dynamic team. This fully remote position offers the opportunity to shape risk management strategies within the insurance sector. The successful candidate will be responsible for developing, implementing, and monitoring sophisticated risk models to identify, assess, and mitigate potential financial and operational risks across various insurance products. You will collaborate closely with underwriting, actuarial, and claims departments to ensure robust risk frameworks are in place.

Key responsibilities include conducting in-depth analysis of historical data to predict future risk trends, evaluating the effectiveness of existing risk controls, and recommending improvements. You will also play a crucial role in regulatory compliance, ensuring adherence to industry standards and reporting requirements. The ideal candidate will possess a strong understanding of insurance principles, statistical analysis techniques, and relevant software (e.g., R, Python, SQL). Excellent communication skills are paramount, as you will be presenting complex findings to stakeholders at all levels.

Qualifications:
  • Bachelor's or Master's degree in Statistics, Mathematics, Finance, Economics, or a related quantitative field.
  • Minimum of 5 years of experience in risk assessment, preferably within the insurance industry.
  • Proven expertise in statistical modeling, data analysis, and risk management methodologies.
  • Proficiency in data analysis tools and programming languages such as Python, R, SAS, or SQL.
  • Strong understanding of insurance products, markets, and regulatory environments.
  • Excellent analytical, problem-solving, and critical thinking skills.
  • Exceptional written and verbal communication skills, with the ability to articulate complex concepts clearly.
  • Ability to work independently and as part of a remote team, demonstrating strong organizational and time management skills.
  • Experience with specific insurance risk management software is a plus.
This is a fully remote role, allowing you to contribute from the comfort of your home office. We are looking for an individual who is proactive, self-motivated, and eager to make a significant impact. If you are passionate about data-driven decision-making and have a keen eye for detail, we encourage you to apply and become a vital part of our client's success. The role is based in **Vijayawada, Andhra Pradesh, IN**, but will be conducted entirely remotely.
This advertiser has chosen not to accept applicants from your region.

Actuarial Analyst - Risk Assessment

520001 Krishna, Andhra Pradesh ₹800000 Annually WhatJobs

Posted 7 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a prominent insurance provider, is seeking a diligent and analytical Actuarial Analyst to join their Risk Assessment department. This role is essential for evaluating financial risks, developing pricing models, and ensuring the solvency of the company's insurance products. The successful candidate will work closely with underwriting, claims, and finance teams to provide critical insights and data-driven recommendations. This position requires regular presence at our office in Vijayawada, Andhra Pradesh, IN .

Responsibilities:
  • Perform actuarial valuations and analysis for various insurance products (life, health, general).
  • Develop, test, and implement pricing models and reserving methodologies.
  • Analyze statistical data to assess risk and predict future claim costs.
  • Assist in the development and maintenance of financial projections and solvency requirements.
  • Collaborate with actuaries, underwriters, and product managers to support product development and strategy.
  • Prepare regulatory filings and reports, ensuring compliance with industry standards.
  • Use actuarial software and programming tools (e.g., SQL, Python, R, Prophet) for data analysis and modeling.
  • Stay current with actuarial standards of practice, regulations, and industry trends.
  • Communicate complex actuarial concepts and findings to non-technical stakeholders.
  • Contribute to the continuous improvement of actuarial processes and methodologies.
  • Support internal and external audits related to actuarial data and models.
  • Mentor junior analysts and provide guidance on actuarial techniques.

Qualifications:
  • Bachelor's degree in Actuarial Science, Mathematics, Statistics, or a related quantitative field.
  • Progress towards actuarial exams (e.g., ACET, IFoA, SOA/CAS) is strongly preferred.
  • 2-5 years of experience in the insurance or actuarial field.
  • Proficiency in actuarial modeling software and databases.
  • Strong analytical, quantitative, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Familiarity with insurance products and regulatory requirements.
  • Proficiency in Microsoft Excel and SQL is required. Experience with programming languages like Python or R is a plus.
  • Ability to work effectively both independently and as part of a team.
  • Attention to detail and commitment to accuracy.

This role is a fantastic opportunity for an ambitious Actuarial Analyst to advance their career within a leading insurance firm based in Vijayawada, Andhra Pradesh, IN . You will gain invaluable experience in risk assessment and product pricing, contributing directly to the company's financial health and strategic decisions. The position demands analytical rigor and a dedication to upholding the highest professional standards within the insurance industry. We encourage applications from individuals who are eager to learn, grow, and take on challenging responsibilities. Your contribution will be vital in navigating the complex financial landscape of insurance, ensuring our client remains competitive and secure.
This advertiser has chosen not to accept applicants from your region.

Security & Compliance Engineer - Sovereign Cloud

Kochi, Kerala IBM

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Introduction**
At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, let's talk.
**Your role and responsibilities**
The ideal candidate for this role will become an active member of a globally distributed team responsible for building the Sovereign Cloud offering which is part of IBM's Multi Cloud Platform strategy. This role is focused on working with multiple technology and offering teams to ensure that both corporate and regulatory security & compliance requirements; are built into the solution. We are seeking a self-motivated, experienced security & compliance engineer. This role covers security assessment support, the knowledge/development of appropriate security documentation (i.e., System Security Plan (SSP), policies and procedures), data gathering, vulnerability management and ongoing continuous monitoring activities.
**Required technical and professional expertise**
* Working experience with NIST Security controls and technologies, including vulnerability management capabilities.
* Working experience with using tools such as Tenable, Nessus/Security Center, WebInspect, or Nexpose, etc.
* Participate in recurring ConMon meetings to review, submit required artifacts, assist with annual 3PAO security assessment, generate or facilitate deviation requests as required
* Flexible, self-motivated, and able to work independently in a fast paced environment
* Collaborate with cross-functional teams to ensure security and compliance requirements are integrated into the development lifecycle.
Expected years of experience: 8+ years
**Preferred technical and professional experience**
* Create dashboards and metric reports to ensure Continuous Monitoring program is meeting local compliance obligations
* Excellent communication skills and the proven ability to work effectively with all levels of IT and business management
* Track and oversee the vulnerability remediation efforts in order to advise leadership as required on status, blockers and potential risks
* Experience in filing deviation requests for vulnerabilities on behalf of product teams
* One or more related professional certifications (e.g. CISSP, CISM, CISA, CRISC, etc.)
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Compliance engineer Jobs in India !

Senior Infrastructure Security & Compliance Engineer

People Prime Worldwide

Posted today

Job Viewed

Tap Again To Close

Job Description

About Client:

Our client is a global digital solutions and technology consulting company headquartered in Mumbai, India. The company generates annual revenue of over $4.29 billion (₹35,517 crore), reflecting a 4.4% year-over-year growth in USD terms. It has a workforce of around 86,000 professionals operating in more than 40 countries and serves a global client base of over 700 organizations.


Job Type: C2H


Role: Senior Infrastructure Security & Compliance Engineer

Experience: 8-12y


Work Location:Bangalore


Payroll on : People Prime World Wide


Notice :0-15days


Job Description:

Senior Infrastructure Security & Compliance Engineer (Zero-Touch GPU Cloud – GitOps-Driven Compliance & Resilience)


We are seeking a Senior Infrastructure Security & Compliance Engineer with 10+ years of experience in infrastructure and platform automation to drive the Zero-Touch Build, Upgrade, and Certification pipeline for our on-prem GPU cloud environment. This role is focused on integrating security scanning, policy enforcement, compliance validation, and backup automation into a fully GitOps-managed GPU cloud stack, spanning hardware → OS → Kubernetes → platform layers.


Key Responsibilities

  • Design and implement GitOps-native workflows to automate security, compliance, and backup validation as part of the GPU cloud lifecycle.
  • Integrate Trivy into CI/CD pipelines for container and system image vulnerability scanning.
  • Automate kube-bench execution and remediation workflows to enforce Kubernetes security benchmarks (CIS/STIG).
  • Define and enforce policy-as-code using OPA/Gatekeeper to validate cluster and workload configurations.
  • Deploy and manage Velero to automate backup and disaster recovery operations for Kubernetes workloads.
  • Ensure that all compliance, scanning, and backup logic is declarative and auditable through Git-backed repositories.
  • Collaborate with infrastructure, platform, and security teams to define security baselines, enforce drift detection, and integrate automated guardrails.
  • Drive remediation automation and post-validation gates across build, upgrade, and certification pipelines.
  • Monitor evolving security threats and ensure tooling is regularly updated to detect vulnerabilities, misconfigurations, and compliance drift.


Required Skills & Experience

  • 10+ years of hands-on experience in infrastructure, platform automation, and systems security.
  • Primary key skills required are Python/Go/Bash scripting, OPA Rego policy writing, CI integration for Trivy & kube-bench, GitOps
  • Strong knowledge and practical experience with:
  • Trivy for container, filesystem, and configuration scanning
  • kube-bench for Kubernetes CIS benchmark compliance
  • Velero for Kubernetes-native backup and disaster recovery
  • OPA/Gatekeeper for policy-as-code and admission control
  • Deep understanding of GitOps workflows (e.g., Argo CD, Flux) and how to integrate security tools declaratively.
  • Proven experience automating security, compliance, and backup validation in CI/CD pipelines.
  • Solid foundation in Kubernetes internals, RBAC, pod security, and multi-tenant best practices.
  • Familiarity with vulnerability management lifecycles and security risk remediation strategies.
  • Experience with Linux systems administration, OS hardening, and secure bootstrapping.
  • Proficiency in scripting languages such as Python, Go, or Bash for automation and tooling integration.
  • Bonus:
  • Experience with SBOMs, image signing, or container supply chain security
  • Exposure to regulated environments (e.g., PCI-DSS, HIPAA, FedRAMP)
  • Contributions to open-source security/compliance projects


  • Seniority Level
  • Mid-Senior level
  • Industry
  • IT Services and IT Consulting
  • Software Development
  • Employment Type
  • Contract
  • Job Functions
  • Information Technology
  • Skills
  • Infrastructure Security
  • Compliance Engineering
This advertiser has chosen not to accept applicants from your region.

Risk Assessment & Assurance, Enterprise Risk, Director

Mumbai, Maharashtra BlackRock

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**About this role**
**Role Brief**
We are looking for an experienced team leader to manage the **RQA** **Risk Assessment & Assurance Team** in Mumbai, India.
**Business Overview**
Understanding and managing risk is the cornerstone of BlackRock's approach to responsible investing. The Risk & Quantitative Analysis (RQA) group provides independent oversight of BlackRock's fiduciary and enterprise risks. Our mission is to advance the firm's risk management practices and to deliver independent risk expertise and constructive challenge to drive better business and investment outcomes. RQA promotes BlackRock as a leader in risk management by providing independent top-down and bottom-up oversight to help identify investment, counterparty, operational, regulatory, technology, and third-party risks.
RQA is committed to investing in our people to increase both individual enablement and a strong collaborative environment. As a global group located all around the world, our goal is to create a culture of inclusion which encourages teamwork, innovation, diversity and the development our future leaders. We actively engage in discussions on career growth and work with team members to understand how personal passions and strengths connect with our purpose.
**Who We Are**
As part of the broader Thematic Risk Assessment team (TRA) within the Enterprise Risk Management group (a Second Line of Defense function), the **RQA Risk Assessment & Assurance (RAA) Team** is vital to the "true-up" understanding of our enterprise risk and control landscape, and continued confidence that our risk management processes are effective and reliable. These help provide assurance that the firm's enterprise risk management framework is adept at managing current and emerging risks, protects our clients and firm, and supports the achievement of firm-wide business goals within our risk tolerance. Key stakeholders include, but not limited to, broader RQA Enterprise Risk Management teams and leaders, Enterprise Technology Risk & Control (First Line of Defense risk function), Innovation Office and Information Security, and other risk and control functions.
**What You Will Be Doing** :
Your primary responsibilities include:
+ Lead and support risk assurance plans that evaluate, monitor and report on the design &/or effectiveness of enterprise risk assessment programs and its activities.
+ Perform and support thematic risk assessments that evaluate enterprise risks of interest.
+ Identify, dimension, and propose practical solutions for improving enterprise risk assessment programs, risk management processes, risk and control taxonomies, and risk and control assessment techniques.
+ Manage the RAA Team's and team members' performance.
+ Execute and support continuous improvements to enterprise risk assessment programs.
+ Identify and escalate potentially systemic enterprise risk issues in a timely manner.
+ Ensure risk assessment and assurance exercises are comprehensively documented and reported.
+ Be a risk champion within the wider BlackRock business.
**What We Look For** :
As a **Team Lead** with people management responsibilities, you must have:
+ Strong risk and control assessment expertise (especially in technology &/or information security).
+ Excellent attention to detail, strong work ethics, and able to work as part of a global team and make informed risk management decisions.
+ **17+ years** of practical experience in Enterprise &/or Technology Risk Management, Business Process Engineering, Quality Assurance, or Audit (experience earned in Asset Management or Banking industry is preferred).
+ **7+ years** of experience **leading and performance managing** a team (non-project-based).
+ **5+ years** of experience in **performing** risk and control assessments, quality testing, control testing, &/or IT auditing.
+ Demonstrable ability to identify and analyze process, risk and control issues, challenge the status quo, and work with cross-functional and international teams to ideate pragmatic solutions that strengthen the risk management framework.
+ Strong understanding of industry-leading practices and control frameworks (e.g. CRI Profile, NIST CSF, ISO 27001, SOC, SOX, SWIFT, and COBIT).
+ An ability to explain complex ideas &/or sophisticated technical concepts in simple but impactful terms and use effective communication to influence outcomes.
+ Familiarity with office productivity, usage of open-source frameworks and business intelligence tools, including (but not limited to) Microsoft Office, PowerBI &/or Tableau.
The following are competitive advantages that we are interested in:
+ You are a Certified in Risk & Information Systems Control (CRISC), a Certified Information Systems Auditor (CISA), &/or Six Sigma-certified.
+ You have both led and performed technology &/or business risk and control assessments.
+ You have automated control assessment activities or analytics using one or more of the following: Python, JavaScript, .NET &/or SQL.
+ Good understanding of worldwide regulatory requirements.
**Our benefits**
To help you stay energized, engaged and inspired, we offer a wide range of benefits including a strong retirement plan, tuition reimbursement, comprehensive healthcare, support for working parents and Flexible Time Off (FTO) so you can relax, recharge and be there for the people you care about.
**Our hybrid work model**
BlackRock's hybrid work model is designed to enable a culture of collaboration and apprenticeship that enriches the experience of our employees, while supporting flexibility for all. Employees are currently required to work at least 4 days in the office per week, with the flexibility to work from home 1 day a week. Some business groups may require more time in the office due to their roles and responsibilities. We remain focused on increasing the impactful moments that arise when we work together in person - aligned with our commitment to performance and innovation. As a new joiner, you can count on this hybrid model to accelerate your learning and onboarding experience here at BlackRock.
**About BlackRock**
At BlackRock, we are all connected by one mission: to help more and more people experience financial well-being. Our clients, and the people they serve, are saving for retirement, paying for their children's educations, buying homes and starting businesses. Their investments also help to strengthen the global economy: support businesses small and large; finance infrastructure projects that connect and power cities; and facilitate innovations that drive progress.
This mission would not be possible without our smartest investment - the one we make in our employees. It's why we're dedicated to creating an environment where our colleagues feel welcomed, valued and supported with networks, benefits and development opportunities to help them thrive.
For additional information on BlackRock, please visit @blackrock ( | Twitter: @blackrock ( | LinkedIn: is proud to be an Equal Opportunity Employer. We evaluate qualified applicants without regard to age, disability, family status, gender identity, race, religion, sex, sexual orientation and other protected attributes at law.
This advertiser has chosen not to accept applicants from your region.

Senior Insurance Underwriter - Risk Assessment

110001 Delhi, Delhi ₹90000 Annually WhatJobs

Posted today

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a reputable insurance provider, is seeking an experienced Senior Insurance Underwriter to join their team. This role involves evaluating insurance applications, assessing risks, and determining appropriate coverage and premiums. You will play a crucial part in ensuring the financial health and profitability of the company by making sound underwriting decisions. The ideal candidate will have a deep understanding of insurance products, risk management principles, and regulatory requirements. You will work closely with agents, brokers, and claims adjusters to gather necessary information and provide expert guidance. This position offers a hybrid work arrangement, combining the benefits of in-office collaboration with the flexibility of remote work. We are looking for individuals with strong analytical skills, attention to detail, and a commitment to ethical practices.

Key Responsibilities:
  • Analyze insurance applications to assess risks and exposures.
  • Determine the eligibility of applicants and set appropriate terms, conditions, and premiums.
  • Develop and maintain a thorough understanding of various insurance products and market trends.
  • Communicate effectively with agents, brokers, and policyholders to gather information and explain underwriting decisions.
  • Ensure compliance with company policies, procedures, and regulatory guidelines.
  • Review and manage a portfolio of existing policies, making adjustments as necessary.
  • Collaborate with the claims department to provide underwriting insights on complex cases.
  • Contribute to the development and refinement of underwriting guidelines and strategies.
  • Mentor and train junior underwriters.

Qualifications:
  • Bachelor's degree in Finance, Economics, Business Administration, or a related field.
  • Extensive experience as an Insurance Underwriter, with a specialization in a specific line of insurance (e.g., property, casualty, life).
  • Strong knowledge of underwriting principles, risk assessment techniques, and insurance regulations.
  • Excellent analytical, quantitative, and decision-making skills.
  • Proficiency in underwriting software and Microsoft Office Suite.
  • Strong negotiation and communication skills.
  • Ability to work independently and as part of a team.
  • Relevant professional designations (e.g., CPCU, AU) are highly desirable.

This hybrid role is based in Delhi, Delhi, IN . If you possess a keen eye for detail and a proven track record in insurance underwriting, we invite you to apply.
This advertiser has chosen not to accept applicants from your region.

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Compliance Engineer Jobs