70 Security Assessment jobs in India

Security & Compliance Specialist

Bengaluru, Karnataka [24]7.ai

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Position : Security & Compliance Specialist

Reports to: Manager InfoSec, GRC

Department: Information Security (InfoSec)

Location: Bangalore

Work Mode : Hybrid



Key Responsibilities


This role oversee the development, evaluation and implementation of governance, risk and compliance.


This role provides operational and conformance checking of information security implemented. The role will undertake specific audits tasks directly and will work with identified stakeholders to ensure that audit lifecycle is in compliance.


Additionally, this role will undertake regular conformance checking tasks to ensure compliance is met to acceptable security levels in different audits.


This role will also undertake a number of critical asks and requests from security projects which manages to successful delivery of projects and the associated resources.


Further, this role will work with all departments across Technology, Business and Third Party vendors/partners and manages inter-dependencies / work-streams and across multiple projects to ensure that Projects are delivered on time:


  • Provide consulting services for Technology & Business team for Audit Security process and implementation of controls.
  • Define Security assessment scope, requirements, time lines and goals.
  • Pro-actively reviews all gaps found on audits related to systems and types of access controls on various risks like Cyber Threats, Data Security and compliance and communicate for timely actions to mitigate them.
  • Supports in managing all type of internal and external InfoSec audits (end to end), status of Security assessment, Report Observations and remediation with all the agreed timelines.
  • Works with end customer SPOC to ensure all the desired requirements are delivered by liaising with all the business stakeholders.
  • Delivers Security Assessments projects on time, and at the expected quality, have root- cause analysis with clear action plan and obtain sign-off with all relevant parties.


Preferred Skills

  • Ensure the organization complies with local, federal and international regulatory and legal requirements
  • Stay up to date on all major privacy and data protection laws, GDPR, CCPA, DPA, PIPEDA etc.
  • Experience in handling various Security Assessments, regulatory requirements but not limited to PCI- DSS, ISO27001, ISO9001, GDPR, CCPA, SOC2 and privacy shield.
  • Practical understanding of security standards, Processes and risk frameworks.
  • Has good understanding of audit frameworks and various datasheet involved in preparing for the external audits.
  • Knowledge of current industry best practices and standards, local/international security and compliance guidance.
  • Broad, and commensurately high-level knowledge of Security technology, such as: PKI, firewalls, access management, encryption, IDS & IPS, Cyber threats, encryption, and identity management.
  • Strong time management, communication and prioritization skills.
  • Ability to work with Technical and Non- Technical business owners.
  • Practical understanding of security processes and risk frameworks.
  • Partners with External consultants/ internal stakeholders on Regulatory Changes to ensure regulatory changes are added within the system of record.
  • Drive integration with Compliance teams aligned to Business Units for all the related audits (end to end).
  • Knowledge of current industry best practices and standards, local/international security and compliance guidance.
  • Conducting deep dives into specific areas of focus based on Risk and Regulatory priorities as and when needed.
  • Proficiency in reviewing and assessing process flows to detect potential risks, deficient controls, duplicated effort, extravagance, and fraud, non-compliance with laws, regulations, and management policies.
  • Partners with other Operations Managers to ensure timely and effective delivery for all audit requirements.
  • Contribute to the Group ISMS content development, maintenance and maturity.
  • Take the interface between custom authorities and colleagues/partners on customs Audits.
  • Drive matrixed project planning and execution to deliver and sustain privacy compliance

Required Qualifications

  • Bachelor/Master of Science degree. Computer Science, Engineering, Telecommunications or management degree(would be advantage)
  • 6/6+ years’ experience in audits and compliance management
  • Excellent planning, multi-tasking, organization and problem solving skills.
  • Knowledge of certifications and framework like NIST, HIPAA, ISO 27K, PCI-DSS and SOC2.
  • Excellent communication skills.
  • Hold certifications like ISO9001, ISO 27001 and Green belt(added advantage)
This advertiser has chosen not to accept applicants from your region.

Analyst, IT Security Compliance

Bangalore, Karnataka 3M

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

3M has a long-standing reputation as a company committed to innovation. We provide the freedom to explore and encourage curiosity and creativity. We gain new insight from diverse thinking, and take risks on new ideas. Here, you can apply your talent in bold ways that matter.
**Job Description:**
**About the Role**
Join the dynamic and innovative team at **3M Global Technology Center LLP** as an **Analyst - Security Compliance** and take your career to new heights.
At 3M, innovation is at the core of everything we do. We empower curiosity, creativity, and bold thinking, while fostering an environment where diverse ideas thrive. By joining our team, you will have the opportunity to work with industry experts and cutting-edge technologies, helping shape a world-class security compliance program.
**What You'll Do**
As a key member of the Security Compliance team, reporting to the Team Lead - Security Compliance, you will:
+ Execute day-to-day cybersecurity risk, compliance, and assurance activities.
+ Support global cybersecurity certifications including **ISO 27001** and **ISO 27017** , evaluating control effectiveness and reviewing evidence of controls.
+ Assist in achieving ISO 27001 certification by identifying risks and implementing controls.
+ Maintain and continuously improve 3M's **Information Security Management System (ISMS)** .
+ Create, update, and manage ISMS documentation, reports, and audit records.
+ Act as **Subject Matter Expert (SME) for PCI DSS** , advising stakeholders, conducting internal assessments, and driving PCI DSS v4.0.1 reviews, gap assessments, and control evaluations.
+ Provide high-level knowledge support on other frameworks and standards including **SOC 2, COBIT, NIST, SWIFT, and GDPR** .
+ Deliver timely written reports, metrics, and updates to cybersecurity management.
+ Collaborate and communicate effectively across teams and with stakeholders.
**What We're Looking For**
+ **Education:** Bachelor's degree with a minimum of 3 years of experience in Information Security, GRC, or related roles.
+ **Certifications (preferred):** ISO 27001 Lead Auditor/Implementer, PCI ISA, CISA, CISM, CRISC, CISSP, or equivalent.
+ **Skills & Knowledge:**
+ Strong knowledge of information security risk standards, frameworks, and methodologies.
+ Experience working with **GRC tools** such as Archer (or similar).
+ Excellent written and verbal communication skills.
+ Ability to manage multiple priorities and adapt to evolving business needs.
Learn more about 3M's creative solutions to the world's problems at or on Instagram, Facebook, and LinkedIn @3M.
Safety is a core value at 3M. All employees are expected to contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement.
**Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.**
**3M Global Terms of Use and Privacy Statement**
Carefully read these Terms of Use before using this website. Your access to and use of this website and application for a job at 3M are conditioned on your acceptance and compliance with these terms.
Please access the linked document by clicking here ( , select the country where you are applying for employment, and review. Before submitting your application, you will be asked to confirm your agreement with the terms.
At 3M we apply science in collaborative ways to improve lives daily as our employees connect with customers all around the world. Learn more about 3M's creative solutions to global challenges at or on Twitter @3M or @3MNews.
3M does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
This advertiser has chosen not to accept applicants from your region.

IT Security & Compliance Lead

Genpact

Posted today

Job Viewed

Tap Again To Close

Job Description

IT Security & Compliance Lead

Location: Hyderabad

Experience: 5-8 years

Only Immediate Joiners.


Responsibilities

  • IT Security, Compliance and Administration the Security/Compliance Analyst works in compliance with all written and approved policies, rules and regulations. This also includes the review and audit of all required data and evidences presented to both internal and external auditors. This position will play a key role in meeting and exceeding compliance to current and future IT narratives already in place. This position also includes providing security oversight and review of all security policies and adherence to those policies. The Security/Compliance Analyst will perform threat analyses and recommend adjustments to our current threat stance accordingly
  • Specific Duties: (Describe the duties performed beginning with most important. For each duty, state frequency i.e. daily, weekly, or occasionally.)
  • Duties Percent of Time Spent (may change as business needs dictate)
  • Ensure compliance with current policies 25%
  • Prepare and support internal and external audits 25%
  • Review security policies and ensure compliance 25%
  • Prepare current threats analyses and make recommendations 15%
  • Miscellaneous duties as needed to support the IT Security, Compliance and Administration group 10%
  • Assignment Review and Approval of Work: (Indicate who assigns work, how instructions are provided, and who reviews and approves work when completed.)
  • Senior Manager of IT Security, Compliance and Administration assigns all work duties and provides general instructions.
  • Responsibility and Decision-Making: (Briefly specify responsibility for making decisions.)
  • Senior Manager of IT Security, Compliance and Administration assigns all work duties and provides general instructions. Main responsibility involves the compliance and security reviews. There is some reporting involved in this position.
  • Equipment and Software Operation: (How much time is spent operating equipment? Indicate the types of equipment operated. Include specific hardware and software used and product achieved through usage.)
  • MS Office is required, base knowledge of Microsoft Active Directory as is SharePoint also. Knowledge of most Anti-virus programs is a plus as is knowledge of security scanning programs such as Nexpose or Nessus.
  • Relations with Others: (What contacts are made other than immediate co-workers and supervisors?)
  • Position interacts with IT department personnel in relation to system issues. This person works with Business Analysts and Project Managers to schedule migrations. Interaction with the IT Helpdesk may be common.
  • Hardest Part of Job: (Describe the most difficult or most complex part of the job.)
  • Ensuring to ready for all audits and that the security stance is maintained to prevent malware intrusions
  • Experience Necessary: (List minimum education or equivalent experience required performing job successfully; type and length of work experience, and any special courses required.)
  • · Associate’s Degree or equivalent work experience.
  • · At least 2 years’ experience in a compliance/admin role.
  • · Experience with SharePoint 2010 and 2013
  • · Experience with Microsoft Office Suite (Word, Excel, PowerPoint, Visio)
  • · The ability to work with limited supervision.
  • · Superior oral communication and interpersonal skills required.
  • · Detail oriented individual with excellent work/time organizational skills, as well as analytical and problem solving skills, essential.
  • · Take personal ownership (going beyond assigned tasks to make projects better, identifies and reports issues, demonstrates strong concern for client and initiatives)
  • · Employee must be a team player with initiative and self-motivation; must be able to follow written and verbal instructions as well as interpret written policies; must be flexible to accept frequent change in priorities and possess the ability to coordinate tasks under critical time demands.
  • Learning Period: (How long would it take a new employee to handle this job satisfactorily? What parts would take the longest to learn?)
  • Employee could perform most tasks independently within 3 months. Detailed tasks take longer to learn, requiring assistance up to 3 months. Specific system interactions, interfaces and data processing impacts require the longest learning period.
  • Additional Information: (List any information not previously described that would help someone better understand this job.)
  • Documentation is a key process that must be maintained while in this role. Candidate must act as a subject matter expert to other groups and departments. Candidate must be proficient in the use of the following software:
  • • Microsoft Office – Word, Excel and PowerPoint
  • • Microsoft Visio
  • • Other tools as identified


PATCH MANAGEMENT SERVICES

Install anti-virus, operating System and middleware Software (engine and signature file) updates according to Customer-approved security/risk patching policies and procedures.

Test anti-virus, operating System, and middleware Software updates prior to distribution according to Customer-approved security/risk patching policies and procedures.

Scan Customer Systems according to Customer-approved security/risk patching policies and procedures.

Apply critical/risk patches within four (4) hours of Customer approval as required in outbreak situations, according to Customer-approved security/risk policies and procedures.

Push anti-virus, operating System and middleware Software patches/updates to any contingency environments.

  1. High Criticality: A vulnerability which if exploited may have a catastrophic or critical impact to the business if it were not to be mitigated through patching or other means.
  2. Medium Criticality: A vulnerability which if exploited may have a significant impact to the business if it were not to be mitigated through patching or other means.
  3. Low Criticality: A vulnerability which if exploited may have some impact to the business if it were not to be mitigated through patching or other means.
This advertiser has chosen not to accept applicants from your region.

Senior Security & Compliance Manager

Confidential

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Job Title: Senior Security & Compliance Manager (Independent Contractor, Remote)

Company: US-based SaaS company

Location: Remote (Must work US hours, 6 AM – 2 PM Pacific Time or 9am - 5pm Eastern Time)

Compensation: $3,500–$4,500/month USD


The Senior Security & Compliance Manager will oversee the full lifecycle of Company's information security operations, including SOC 2 (BDO) and ISO 27001 audits, penetration and vulnerability testing, RFP security responses, and policy management. This role requires hands-on experience with security frameworks, vendor risk management, and compliance documentation.

You’ll work closely with Company's Legal, IT, and Engineering teams to maintain a secure and audit-ready environment aligned with industry standards.


Key Responsibilities


Audit, Certification & Governance

  • Serve as internal lead for SOC 2, ISO AI, and ISO 27001 readiness, evidence collection, and auditor coordination.
  • Maintain and update Company's Statement of Applicability (SOA) and control library.
  • Manage security responses for client RFPs and due diligence questionnaires.


Security Operations

  • Oversee penetration testing and vulnerability testing (Tenable.io) cycles; track and validate remediation.
  • Maintain and enforce security-related policies, including access control, incident response, and DPA compliance.
  • Conduct monthly IT security plan reviews and update internal reports.
  • Manage change control, vendor security protocols, and breach notification procedures.


Risk & Asset Management

  • Conduct and document monthly risk assessments, including:
  • Review of Advanced Networks reports
  • Permission changes and audit logs
  • Data asset inventory
  • Hardware asset management and secure disposal tracking
  • Support vendor due diligence, reviewing risk scores, contracts, and compliance posture.


Documentation & Continuous Improvement

  • Maintain a comprehensive repository of policies, risk assessments, and testing results.
  • Recommend process or control improvements based on audit findings and security trends.
  • Support Legal with client and regulator data protection obligations (GDPR, CCPA, etc.).


Qualifications

  • 5+ years in information security, risk, or compliance (ideally within SaaS or regulated industries).
  • Direct experience with SOC 2, ISO 27001, or similar control frameworks.
  • Working knowledge of Tenable.io, or equivalent vendor risk platforms.
  • Strong understanding of data protection, access control, and change management.
  • Excellent writing and analytical skills; able to draft RFP responses and security documentation clearly.
  • Certifications (preferred): CISA, CISSP, CRISC, or ISO 27001 Lead Implementer.


Please note, this role reports to Company's Head of Legal.

This advertiser has chosen not to accept applicants from your region.

Information Security Compliance Manager

122001 Gurgaon, Haryana ₹95000 Annually WhatJobs

Posted 12 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly skilled and experienced Information Security Compliance Manager to join their growing team in Gurugram, Haryana, IN . This hybrid role is instrumental in ensuring that the organization's information security practices meet and exceed regulatory requirements and industry best practices. You will be responsible for developing, implementing, and managing comprehensive security compliance programs, conducting regular audits, and advising on risk mitigation strategies. The ideal candidate will possess in-depth knowledge of various security frameworks, strong analytical skills, and the ability to effectively communicate complex security concepts to both technical and non-technical stakeholders.

Key Responsibilities:
  • Develop, implement, and maintain the organization's information security compliance program.
  • Ensure adherence to relevant regulations, standards, and frameworks (e.g., ISO 27001, GDPR, HIPAA, NIST).
  • Conduct regular internal security audits and assessments to identify compliance gaps and vulnerabilities.
  • Develop and execute remediation plans for identified compliance issues.
  • Manage external audits and certifications processes.
  • Create and update security policies, procedures, and guidelines.
  • Provide training and awareness programs on information security compliance to employees.
  • Monitor and report on the status of compliance initiatives to senior management.
  • Stay current with evolving security threats, vulnerabilities, and regulatory changes.
  • Collaborate with IT, legal, and other departments to integrate security into business processes.
  • Manage third-party risk assessments related to security compliance.
  • Respond to security incidents from a compliance perspective.
  • Develop and maintain incident response plans related to compliance breaches.

Qualifications:
  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of 7 years of experience in information security, with at least 3-4 years focused on compliance and risk management.
  • In-depth knowledge of information security frameworks, standards, and regulations.
  • Experience conducting security audits and gap analyses.
  • Proficiency in risk assessment methodologies and tools.
  • Excellent understanding of IT controls and security best practices.
  • Strong analytical, problem-solving, and critical thinking skills.
  • Exceptional written and verbal communication skills, with the ability to explain complex technical concepts.
  • Relevant certifications such as CISSP, CISA, CISM, or CRISC are highly desirable.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Experience managing multiple compliance projects simultaneously.

This is a crucial role for an individual passionate about safeguarding sensitive information and ensuring the organization operates within a secure and compliant framework.
This advertiser has chosen not to accept applicants from your region.

Information Security Compliance Officer

208001 Kanpur, Uttar Pradesh ₹70000 Annually WhatJobs

Posted 21 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a diligent and knowledgeable Information Security Compliance Officer to oversee and enforce security policies and regulatory adherence within their organization. Based in Kanpur, Uttar Pradesh, IN , this role is critical in safeguarding sensitive information and ensuring the company meets all legal and industry compliance standards. Your primary responsibilities will include developing, implementing, and maintaining information security policies, procedures, and controls. You will conduct regular security audits, risk assessments, and gap analyses to identify potential vulnerabilities and areas of non-compliance. Collaborating with various departments, you will ensure that security protocols are understood and followed across the organization. This position also involves staying current with evolving cybersecurity regulations (e.g., GDPR, HIPAA, ISO 27001) and industry best practices, and translating these into actionable compliance strategies. The ideal candidate will possess a Bachelor's degree in Information Technology, Computer Science, Law, or a related field, along with significant experience in information security and compliance. Professional certifications such as CIPP, CISA, or CRISC are highly desirable. Strong analytical, critical thinking, and problem-solving skills are essential, as is the ability to communicate complex technical and regulatory requirements clearly to both technical and non-technical audiences. You must be detail-oriented, organized, and capable of managing multiple projects simultaneously. This is an excellent opportunity for a security professional passionate about governance, risk, and compliance to contribute to a robust security framework.
This advertiser has chosen not to accept applicants from your region.

Information Security Compliance Officer

500032 Hyderabad, Andhra Pradesh ₹1000000 Annually WhatJobs

Posted 23 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly diligent and experienced Information Security Compliance Officer to establish and maintain robust security compliance programs. This is a fully remote position, allowing you to contribute to safeguarding sensitive information from anywhere. The ideal candidate will possess an in-depth understanding of various information security standards, regulations, and frameworks, with a proven ability to assess risks, implement controls, and ensure adherence to compliance requirements.

Responsibilities:
  • Develop, implement, and manage information security policies, procedures, and standards to ensure compliance with relevant regulations (e.g., GDPR, CCPA, HIPAA, ISO 27001, SOC 2).
  • Conduct regular security risk assessments and vulnerability analyses to identify potential threats and weaknesses.
  • Oversee the implementation and maintenance of security controls to mitigate identified risks.
  • Lead internal and external audits, ensuring preparedness and facilitating audit processes.
  • Develop and deliver security awareness training programs to employees across the organization.
  • Monitor security incidents and breaches, managing response and remediation efforts.
  • Work closely with legal, IT, and other departments to ensure alignment on compliance strategies.
  • Stay abreast of evolving regulatory requirements, industry best practices, and emerging security threats.
  • Develop and maintain comprehensive documentation for compliance processes and controls.
  • Manage third-party vendor risk assessments to ensure their compliance with security standards.
  • Prepare and present compliance reports to senior management and relevant stakeholders.
  • Conduct periodic reviews of security policies and procedures to ensure their continued effectiveness and relevance.
  • Establish key performance indicators (KPIs) to measure the effectiveness of the information security program.
  • Champion a culture of security awareness and compliance throughout the organization.
  • Manage data privacy initiatives and ensure adherence to data protection regulations.
Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Master's degree preferred.
  • 5-8 years of experience in information security, with a strong focus on compliance, risk management, and governance.
  • In-depth knowledge of information security frameworks such as NIST Cybersecurity Framework, ISO 27001, SOC 2, PCI DSS, GDPR, and HIPAA.
  • Experience in conducting security risk assessments and developing remediation plans.
  • Proven ability to manage audit processes and interact with auditors.
  • Excellent understanding of security technologies and controls.
  • Strong analytical, problem-solving, and organizational skills.
  • Exceptional written and verbal communication skills, with the ability to communicate complex compliance requirements clearly.
  • Ability to work independently in a remote environment and manage multiple priorities effectively.
  • Relevant security certifications such as CISSP, CISM, CRISC, CGEIT, or CISA are highly desirable.
  • Experience with GRC (Governance, Risk, and Compliance) tools.
  • Demonstrated ability to influence stakeholders at all levels of the organization.
Join our security-focused team and play a crucial role in ensuring our organization's compliance and security posture.
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Security assessment Jobs in India !

Security & Compliance Engineer - Sovereign Cloud

Kochi, Kerala IBM

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Introduction**
At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, let's talk.
**Your role and responsibilities**
The ideal candidate for this role will become an active member of a globally distributed team responsible for building the Sovereign Cloud offering which is part of IBM's Multi Cloud Platform strategy. This role is focused on working with multiple technology and offering teams to ensure that both corporate and regulatory security & compliance requirements; are built into the solution. We are seeking a self-motivated, experienced security & compliance engineer. This role covers security assessment support, the knowledge/development of appropriate security documentation (i.e., System Security Plan (SSP), policies and procedures), data gathering, vulnerability management and ongoing continuous monitoring activities.
**Required technical and professional expertise**
* Working experience with NIST Security controls and technologies, including vulnerability management capabilities.
* Working experience with using tools such as Tenable, Nessus/Security Center, WebInspect, or Nexpose, etc.
* Participate in recurring ConMon meetings to review, submit required artifacts, assist with annual 3PAO security assessment, generate or facilitate deviation requests as required
* Flexible, self-motivated, and able to work independently in a fast paced environment
* Collaborate with cross-functional teams to ensure security and compliance requirements are integrated into the development lifecycle.
Expected years of experience: 8+ years
**Preferred technical and professional experience**
* Create dashboards and metric reports to ensure Continuous Monitoring program is meeting local compliance obligations
* Excellent communication skills and the proven ability to work effectively with all levels of IT and business management
* Track and oversee the vulnerability remediation efforts in order to advise leadership as required on status, blockers and potential risks
* Experience in filing deviation requests for vulnerabilities on behalf of product teams
* One or more related professional certifications (e.g. CISSP, CISM, CISA, CRISC, etc.)
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
This advertiser has chosen not to accept applicants from your region.

Security & Compliance IT Specialist/Engineer

aecc - digital innovation hub

Posted today

Job Viewed

Tap Again To Close

Job Description

Role Purpose:


Support the organisation’s security posture through monitoring, incident response coordination, and compliance activities. Work closely with IT operations, engineering, and leadership to ensure systems, data, and tools meet policy and risk standards


Key Responsibiliti es


  • Safeguard cloud and on-premises infrastructure by implementing and maintaining robust security controls.
  • Monitor Darktrace , SIEM , and other SOC tools to detect and respond to potential threats in real time.
  • Investigate security incidents and coordinate with cross-functional teams to ensure effective resolution.
  • Support the development, implementation, and continuous improvement of security policies and procedures.
  • Contribute to compliance reporting , audit preparation , and maintenance of all related documentation, including risk registers and incident logs.
  • Collaborate with the IT Operations team to strengthen access controls, endpoint protection, and data security measures.
  • Partner with the Engineering team to secure cloud infrastructure and applications using tools such as CSPM, DAST, SAST, IAST, and SCA .
  • Identify and assess vulnerabilities or misconfigurations, and ensure timely escalation for remediation.
  • Escalate high-risk issues and potential breaches to the Technical Architect .
  • Coordinate with the IT Operations Lead on endpoint management and access-related controls.
  • Work closely with leadership when incidents require strategic or business-level decisions.


What We’re Looking For

  • 3+ years of experience in security operations , SOC support , or a related field.
  • Hands-on experience with Darktrace , SIEMs , or similar security monitoring tools.
  • Understanding of IT compliance frameworks and risk management practices.
  • Strong analytical, documentation, and communication skills.
  • Ability to collaborate effectively with IT, engineering, and leadership teams.
  • Keen attention to detail and proactive approach to security.


What You Need to Succeed

  • Proactively escalate and resolve security alerts in a timely manner.
  • Maintain strong audit and compliance readiness at all times.
  • Minimize recurring or unresolved security incidents through effective follow-up and prevention.
  • Ensure accuracy, clarity, and completeness in all reports and documentation.
  • Continuously work to reduce exposure to known and potential risks.


Personal Attributes

  • Strong analytical and problem-solving skills.
  • High attention to detail and accuracy.
  • Proactive, vigilant, and responsive under pressure.
  • Collaborative and effective in cross-functional environments.
  • Ethical, responsible, and confidentiality-driven.
  • Clear and concise communicator.
  • Continuous learner with a keen interest in emerging security trends.




“This is a fully remote role, and we welcome applications from candidates based anywhere in India"

This advertiser has chosen not to accept applicants from your region.

Senior Infrastructure Security & Compliance Engineer

People Prime Worldwide

Posted today

Job Viewed

Tap Again To Close

Job Description

About Client:

Our client is a global digital solutions and technology consulting company headquartered in Mumbai, India. The company generates annual revenue of over $4.29 billion (₹35,517 crore), reflecting a 4.4% year-over-year growth in USD terms. It has a workforce of around 86,000 professionals operating in more than 40 countries and serves a global client base of over 700 organizations.


Job Type: C2H


Role: Senior Infrastructure Security & Compliance Engineer

Experience: 8-12y


Work Location:Bangalore


Payroll on : People Prime World Wide


Notice :0-15days


Job Description:

Senior Infrastructure Security & Compliance Engineer (Zero-Touch GPU Cloud – GitOps-Driven Compliance & Resilience)


We are seeking a Senior Infrastructure Security & Compliance Engineer with 10+ years of experience in infrastructure and platform automation to drive the Zero-Touch Build, Upgrade, and Certification pipeline for our on-prem GPU cloud environment. This role is focused on integrating security scanning, policy enforcement, compliance validation, and backup automation into a fully GitOps-managed GPU cloud stack, spanning hardware → OS → Kubernetes → platform layers.


Key Responsibilities

  • Design and implement GitOps-native workflows to automate security, compliance, and backup validation as part of the GPU cloud lifecycle.
  • Integrate Trivy into CI/CD pipelines for container and system image vulnerability scanning.
  • Automate kube-bench execution and remediation workflows to enforce Kubernetes security benchmarks (CIS/STIG).
  • Define and enforce policy-as-code using OPA/Gatekeeper to validate cluster and workload configurations.
  • Deploy and manage Velero to automate backup and disaster recovery operations for Kubernetes workloads.
  • Ensure that all compliance, scanning, and backup logic is declarative and auditable through Git-backed repositories.
  • Collaborate with infrastructure, platform, and security teams to define security baselines, enforce drift detection, and integrate automated guardrails.
  • Drive remediation automation and post-validation gates across build, upgrade, and certification pipelines.
  • Monitor evolving security threats and ensure tooling is regularly updated to detect vulnerabilities, misconfigurations, and compliance drift.


Required Skills & Experience

  • 10+ years of hands-on experience in infrastructure, platform automation, and systems security.
  • Primary key skills required are Python/Go/Bash scripting, OPA Rego policy writing, CI integration for Trivy & kube-bench, GitOps
  • Strong knowledge and practical experience with:
  • Trivy for container, filesystem, and configuration scanning
  • kube-bench for Kubernetes CIS benchmark compliance
  • Velero for Kubernetes-native backup and disaster recovery
  • OPA/Gatekeeper for policy-as-code and admission control
  • Deep understanding of GitOps workflows (e.g., Argo CD, Flux) and how to integrate security tools declaratively.
  • Proven experience automating security, compliance, and backup validation in CI/CD pipelines.
  • Solid foundation in Kubernetes internals, RBAC, pod security, and multi-tenant best practices.
  • Familiarity with vulnerability management lifecycles and security risk remediation strategies.
  • Experience with Linux systems administration, OS hardening, and secure bootstrapping.
  • Proficiency in scripting languages such as Python, Go, or Bash for automation and tooling integration.
  • Bonus:
  • Experience with SBOMs, image signing, or container supply chain security
  • Exposure to regulated environments (e.g., PCI-DSS, HIPAA, FedRAMP)
  • Contributions to open-source security/compliance projects


  • Seniority Level
  • Mid-Senior level
  • Industry
  • IT Services and IT Consulting
  • Software Development
  • Employment Type
  • Contract
  • Job Functions
  • Information Technology
  • Skills
  • Infrastructure Security
  • Compliance Engineering
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Assessment Jobs