Information Security Compliance Officer

500032 Hyderabad, Andhra Pradesh ₹1000000 Annually WhatJobs

Posted 15 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly diligent and experienced Information Security Compliance Officer to establish and maintain robust security compliance programs. This is a fully remote position, allowing you to contribute to safeguarding sensitive information from anywhere. The ideal candidate will possess an in-depth understanding of various information security standards, regulations, and frameworks, with a proven ability to assess risks, implement controls, and ensure adherence to compliance requirements.

Responsibilities:
  • Develop, implement, and manage information security policies, procedures, and standards to ensure compliance with relevant regulations (e.g., GDPR, CCPA, HIPAA, ISO 27001, SOC 2).
  • Conduct regular security risk assessments and vulnerability analyses to identify potential threats and weaknesses.
  • Oversee the implementation and maintenance of security controls to mitigate identified risks.
  • Lead internal and external audits, ensuring preparedness and facilitating audit processes.
  • Develop and deliver security awareness training programs to employees across the organization.
  • Monitor security incidents and breaches, managing response and remediation efforts.
  • Work closely with legal, IT, and other departments to ensure alignment on compliance strategies.
  • Stay abreast of evolving regulatory requirements, industry best practices, and emerging security threats.
  • Develop and maintain comprehensive documentation for compliance processes and controls.
  • Manage third-party vendor risk assessments to ensure their compliance with security standards.
  • Prepare and present compliance reports to senior management and relevant stakeholders.
  • Conduct periodic reviews of security policies and procedures to ensure their continued effectiveness and relevance.
  • Establish key performance indicators (KPIs) to measure the effectiveness of the information security program.
  • Champion a culture of security awareness and compliance throughout the organization.
  • Manage data privacy initiatives and ensure adherence to data protection regulations.
Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Master's degree preferred.
  • 5-8 years of experience in information security, with a strong focus on compliance, risk management, and governance.
  • In-depth knowledge of information security frameworks such as NIST Cybersecurity Framework, ISO 27001, SOC 2, PCI DSS, GDPR, and HIPAA.
  • Experience in conducting security risk assessments and developing remediation plans.
  • Proven ability to manage audit processes and interact with auditors.
  • Excellent understanding of security technologies and controls.
  • Strong analytical, problem-solving, and organizational skills.
  • Exceptional written and verbal communication skills, with the ability to communicate complex compliance requirements clearly.
  • Ability to work independently in a remote environment and manage multiple priorities effectively.
  • Relevant security certifications such as CISSP, CISM, CRISC, CGEIT, or CISA are highly desirable.
  • Experience with GRC (Governance, Risk, and Compliance) tools.
  • Demonstrated ability to influence stakeholders at all levels of the organization.
Join our security-focused team and play a crucial role in ensuring our organization's compliance and security posture.
This advertiser has chosen not to accept applicants from your region.

Information Security Compliance Analyst

Hyderabad, Andhra Pradesh Phenom

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Description

We're seeking a full-time, phenomenal Compliance Analyst to ensure Phenom's adherence to regulatory and industry information security and privacy standards. This role involves conducting audits, managing compliance initiatives, assessing risk, and collaborating with teams across the organization to enforce compliance policies and standards. The Security Compliance Analyst will be pivotal in maintaining certifications and ensuring Phenom remains compliant with frameworks such as ISO 27001 or SOC 2.


What You’ll Do

  • Develop, implement, and maintain security policies, procedures, and controls to comply with regulatory and industry standards (e.G., SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC2, and others).
  • Manage compliance initiatives, ensuring timely updates and certifications for applicable frameworks.
  • Coordinate internal and external audits, including collecting evidence, managing documentation, and responding to auditor inquiries.
  • Perform internal compliance assessments to identify gaps and recommend remediation strategies.
  • Conduct regular risk assessments to identify processes, systems, and technology vulnerabilities.
  • Collaborate with stakeholders to develop and implement mitigation strategies.
  • Monitor compliance with security policies and standards, ensuring adherence across departments.
  • Work closely with the sales, legal, and technical teams to respond to customer security questionnaires, RFPs, and due diligence requests.
  • To streamline responses, maintain a library of frequently requested documentation, such as certifications, policies, and security process descriptions.
  • Ensure responses align with the organization's security posture, compliance frameworks, and contractual obligations.
  • Create and present reports on compliance status, audit results, and risk management metrics to leadership.
  • Develop and deliver compliance training programs to educate employees on regulatory requirements and best practices.
  • Promote a culture of compliance and security awareness across the organization.
  • Assess the compliance posture of vendors and third-party partners, ensuring contractual obligations align with security and privacy standards.
  • Manage vendor risk assessments and ensure ongoing monitoring of third-party relationships.
  • Draft, review, and update security and privacy policies in alignment with regulatory requirements.
  • Stay updated on regulatory and industry standards changes, recommending adjustments to policies and procedures as needed.


Must Have

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent work experience.
  • 4-6 years of experience in information security, compliance, or risk management roles.


Specialized Knowledge

  • Knowledge of regulatory and industry frameworks such as ISO 27001, SOC 2, and NIST CSF.
  • Familiarity with GRC (Governance, Risk, and Compliance) tools such as OneTrust or similar.
  • Basic understanding of security technologies (e.G., firewalls, SIEM, encryption) and their role in compliance.
  • Proficiency with documentation tools and audit management software.
  • Relevant certifications, such as Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP), are highly desirable.
This advertiser has chosen not to accept applicants from your region.

Information Security Compliance Governance Manager

Hyderabad, Andhra Pradesh Infinx

Posted today

Job Viewed

Tap Again To Close

Job Description

Designation/ Role: Compliance – Senior Manager

Experience: 12 to 15 years of experience in Compliance, Information Security and BCM Domains

Department: Compliance & Information Security

Work Timing: 9 hours/day;
5 days a week flexible shift timing between 10 am to 12 am IST. Should be ready to work as per US/UK shift timings as and when needed.

Qualifications: Graduate / B.E.

Professional Certifications: ISO27001 Lead Auditor/PCI DSS/CEH-EC council/CISA.

Key Skills: ISO 27001:2022 (ISMS), HIPAA, SOC 2 Type II, HITRUST, PCI DSS, VAPT and Cyber Security Assessments, Vulnerability Management, Third-party Risk management, Creating New Policies/SOPs, Filling the client questionnaire, Dark Web Monitoring, and Attack Surface Monitoring.



Experience

  • Mandatory
  • Expertise working with ISO 27001:2022, PCI DSS Certifications and HIPAA Assessments.
  • Internal and External audit experience of ISO standards ISO 27001.
  • Sound knowledge and audit experience of HIPAA compliance and HITRUST requirements.
  • Good hands-on experience in VAPT, Vulnerability management, Dark Web Monitoring, Attack Surface Monitoring, and cyber security management.
  • Should have hands-on experience in responding to Client’s RFP questionnaires/documents and performing Third-party Risk Management.
  • Should have hands-on experience working on SOC 2 Type II/ HITRUST/PCI DSS certification requirements.
  • Good knowledge of basic ITGC controls/Information Security.
  • Good written and verbal communication skills.
  • Experience in coordinating with vendors, external auditors and internal stakeholders for different compliance and information security tasks.
  • Experience in handling cybersecurity audits/assessments.
  • 12+years of relevant experience in the same field.


  • Desired
  1. Certified Lead Auditor for ISMS and Certified PCI DSS implementor.



Job Summary:

Compliance and Information Security Senior Manager will be a part of the core compliance team and will help drive, manage, implement, and evaluate the certification and compliance standards Infinx is certified for i.E., ISO 9001, ISO 27001, HIPAA, SOC2, VAPT, PCI DSS, HITRUST, Cyber Security Assessments, Dark Web Monitoring, Attack Surface Monitoring, VAPT Assessment, Third-Party Vendor Management, and Filling up of client security questionnaires/RFP documents.



Duties and responsibilities:


  • Communicate with internal and external stakeholders for all compliance related activities.
  • Participate in Compliance audit programs both internal and external for ISO, HIPAA, SOC2, VAPT, PCI DSS, HITRUST, Cyber Security assessments, etc., as and when needed.
  • Develop and review company policies and procedures, handle training programs and monitor compliance related matters.
  • Educate stakeholders to implement corrective actions.
  • Ensure corrective actions have been implemented for all identified compliance deficiencies.
  • Promote awareness related to privacy, and security and enforce compliance across the enterprise.
  • Support Implement and manage compliance programs effectively.
  • Report MR/CISO/Management about the status of compliance and information security in the organization through detailed reports.
  • Create, manage, and track effective action plans in response to audit observations and compliance violations.
  • Manage and perform internal audits to identify possible weaknesses or risks to the company’s information security management system.
  • Perform additional audits as and when required.
  • Assess the organization’s processes to determine the compliance risk and formulate necessary risk mitigation plans.
  • Ensure all employees are aware of their compliance responsibilities.
  • Working with the vendors and external auditors on all audits and assessments related tasks and ensuring to close the loop with them.
  • Work with the vendors in performing the third-party audits based on the frequency.
  • Handling Dark Web Monitoring / Attack Surface Monitoring tools and ensuring to mitigate the risks for the organization.
  • Work with internal stakeholders in filling up the client questionnaires and RFP documents for submitting them timely.
  • Ensure to send awareness mailers to users.
  • Experience in handling Phishing Simulation campaigns across the organization.
This advertiser has chosen not to accept applicants from your region.

Security Compliance Specialist

Hyderabad, Andhra Pradesh Phenom

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Description

We're seeking a full-time, phenomenal Compliance Analyst to ensure Phenom's adherence to regulatory and industry information security and privacy standards. This role involves conducting audits, managing compliance initiatives, assessing risk, and collaborating with teams across the organization to enforce compliance policies and standards. The Security Compliance Analyst will be pivotal in maintaining certifications and ensuring Phenom remains compliant with frameworks such as ISO 27001 or SOC 2.


What You’ll Do

  • Develop, implement, and maintain security policies, procedures, and controls to comply with regulatory and industry standards (e.G., SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC2, and others).
  • Manage compliance initiatives, ensuring timely updates and certifications for applicable frameworks.
  • Coordinate internal and external audits, including collecting evidence, managing documentation, and responding to auditor inquiries.
  • Perform internal compliance assessments to identify gaps and recommend remediation strategies.
  • Conduct regular risk assessments to identify processes, systems, and technology vulnerabilities.
  • Collaborate with stakeholders to develop and implement mitigation strategies.
  • Monitor compliance with security policies and standards, ensuring adherence across departments.
  • Work closely with the sales, legal, and technical teams to respond to customer security questionnaires, RFPs, and due diligence requests.
  • To streamline responses, maintain a library of frequently requested documentation, such as certifications, policies, and security process descriptions.
  • Ensure responses align with the organization's security posture, compliance frameworks, and contractual obligations.
  • Create and present reports on compliance status, audit results, and risk management metrics to leadership.
  • Develop and deliver compliance training programs to educate employees on regulatory requirements and best practices.
  • Promote a culture of compliance and security awareness across the organization.
  • Assess the compliance posture of vendors and third-party partners, ensuring contractual obligations align with security and privacy standards.
  • Manage vendor risk assessments and ensure ongoing monitoring of third-party relationships.
  • Draft, review, and update security and privacy policies in alignment with regulatory requirements.
  • Stay updated on regulatory and industry standards changes, recommending adjustments to policies and procedures as needed.


Must Have

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent work experience.
  • 4-6 years of experience in information security, compliance, or risk management roles.


Specialized Knowledge

  • Knowledge of regulatory and industry frameworks such as ISO 27001, SOC 2, and NIST CSF.
  • Familiarity with GRC (Governance, Risk, and Compliance) tools such as OneTrust or similar.
  • Basic understanding of security technologies (e.G., firewalls, SIEM, encryption) and their role in compliance.
  • Proficiency with documentation tools and audit management software.
  • Relevant certifications, such as Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP), are highly desirable.
This advertiser has chosen not to accept applicants from your region.

Mainframe Security & Compliance Administrator

Hyderabad, Andhra Pradesh Kyndryl

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Who We Are**
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.
**The Role**
As a System Administrator at Kyndryl, you'll solve complex problems and identify potential future issues across the spectrum of platforms and services. You'll be at the forefront of new technology and modernization, working with some of our biggest clients - which means some of the biggest in the world.
There's never a typical day as a System Administrator at Kyndryl, because no two projects are alike. You'll be managing systems data for clients and providing day-to-day solutions and security compliance. You'll oversee a queue of assignments and work directly with technicians, prioritizing tickets to deliver the best solutions to our clients.
One of the benefits of Kyndryl is that we work with clients in a variety of industries, from banking to retail. Whether you want to broaden your knowledge base or narrow your scope and specialize in a specific sector, you can find your opportunity here. You'll also get the chance to share your expertise by recommending modernization options, identifying new business opportunities, and cultivating relationships with other teams and stakeholders. Does the work get challenging at times? Yes! But you'll collaborate with a diverse group of talented people and gain invaluable management and organizational skills, which will come in handy as you move forward in your career.
Your future at Kyndryl
Every position at Kyndryl offers a way forward to grow your career, from Junior System Administrator to Architect. We have opportunities for Cloud Hyperscalers that you won't find anywhere else, including hands-on experience, learning opportunities, and the chance to certify in all four major platforms. One of the benefits of Kyndryl is that we work with clients in a variety of industries, from banking to retail. Whether you want to broaden your knowledge base or narrow your scope and specialize in a specific sector, you can find your opportunity here.
**Who You Are**
You're good at what you do and possess the required experience to prove it. However, equally as important - you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused - someone who prioritizes customer success in their work. And finally, you're open and borderless - naturally inclusive in how you work with others.
**Required Technical and Professional Expertise**
A minimum of five years' experience managing security and compliance within mainframe environments, demonstrating proficiency in the following areas
**1. Mainframe Security Concepts**
+ Familiarity with essential mainframe security principles and system architecture
+ Skilled in z/OS security features as well as relevant subsystems
**2. Security Software & Tools**
+ Hands-on experience with mainframe security solutions such as:
+ **RACF (Resource Access Control Facility)** for managing identity and access
+ Other platforms like **CA ACF2 or CA Top** Secret
+ Capable in administering user accounts, assigning access rights, and handling profile management
+ Able to develop and maintain security policies
**3. Access Management**
+ Proven track record in setting up and maintaining user IDs, groups, roles, and access privileges
+ Applies least privilege principles effectively
+ Manages resource classes and custom access rule sets
+ Enforces password standards, account lockout procedures, and multi-factor authentication
**4. Compliance & Auditing**
+ Understands regulatory requirements impacting mainframes **(SOX, HIPAA, PCI-DSS, GDPR)**
+ Conducts security log reviews and system access audits
+ Prepares audit materials and uses specialized tools for compliance monitoring
+ Analyzes SMF records tied to security events
**5. Incident Management**
+ Detects, investigates, and responds to security incidents
+ Performs forensic analysis following breaches or suspicious activities
+ Works with incident response teams to implement remediation
**6. Encryption & Data Protection**
+ Knowledgeable about encryption methods and protecting mainframe data
+ Puts into practice encryption controls for data at rest and in transit (e.g., **DFSMS, ICSF** )
**7. Policy & Procedure Development**
+ Creates, updates, and enforces security protocols and operational guidelines for mainframes
+ Records configuration changes and security updates
**8. System & Network Security**
+ Collaborates with system programmers to patch vulnerabilities
+ Ensures secure network connections to mainframe systems
+ Manages secure communications using SSL/TLS, SSH, and similar protocols
**9. Monitoring & Alerting**
+ Implements monitoring systems to catch unauthorized actions or policy breaches
+ Sets up automated alerts for significant security events
**Preferred Technical and Professional Experience**
+ Experience using IBM Security zSecure for auditing and meeting compliance needs
+ Familiar with Identity and Access Management (IAM) systems
+ Has knowledge of automated compliance management frameworks
+ Participates in disaster recovery planning and ensures business continuity
**Being You**
Diversity is a whole lot more than what we look like or where we come from, it's how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we're not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you - and everyone next to you - the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That's the Kyndryl Way.
**What You Can Expect**
With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter - wherever you are in your life journey. Our employee learning programs give you access to the best learning in the industry to receive certifications, including Microsoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.
**Get Referred!**
If you know someone that works at Kyndryl, when asked 'How Did You Hear About Us' during the application process, select 'Employee Referral' and enter your contact's Kyndryl email address.
Kyndryl is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, age, veteran status, or other characteristics. Kyndryl is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
This advertiser has chosen not to accept applicants from your region.

Lead Security Compliance Engineer

Hyderabad, Andhra Pradesh Marriott Tech Accelerator

Posted today

Job Viewed

Tap Again To Close

Job Description

About Us:

Marriott International Inc., headquartered in Bethesda, Maryland, USA, was founded in May 1927 by J. Willard Marriott and Alice S. Marriott with a modest nine-seat A&W root beer stand. Guided by the family's leadership and core principles, Marriott International today has grown into a global hospitality giant, operating approximately 9,000 properties and over 30 leading brands in more than 140 countries and territories.

From such humble beginnings to becoming the world’s largest hotel company, Marriott International has never stopped searching for inventive ways to serve its customers, provide opportunities for its associates, and grow their business. At Marriott Tech Accelerator center (MTA), Hyderabad, India, Marriott is exploring the world we live in and all its possibilities. At Marriott Tech Accelerator, we are a team of passionate engineering minds dedicated to creating and building cutting-edge solutions that streamline operations and elevate guest experiences.

Marriott Tech Accelerator center is fully owned and operated by ANSR. All associates at Marriott Tech Accelerator will be ANSR employees, delivering services exclusively to ANSR's client, Marriott International.

To know more about us, please visit Marriott Tech Accelerator careers page


Role Title: Senior Engineer II – Security & Compliance

Position Summary:

The Senior Security & Compliance Engineer represents a challenging opportunity to lead, design, and implement solutions critical to securing cloud infrastructure core to Marriott’s mission. Apply to this position if you have a software development background, have expertise in areas of Cloud Security, DevOps, and infrastructure automation with a focus on integrating security best practices. The core responsibilities are to contribute to a team working to improve technical security best practices through identifying and developing security standards through automated technical security patterns and pipelines, developing automations to strengthen configurations within our public and private clouds, and developing processes to automate manual processes.

The Cloud Infrastructure Security & Compliance team is where the rubber meets the road as to translating information security policy into enterprise standards, practices, and automations. You will use Cloud and DevOps SME skills to participate as a leading contributor to designing, implementing, arbitrating, and influencing security best practices across a complex organization.


Job Responsibilities:

  • Improve cloud security posture through script and pipeline development using technologies like python, boto3, Ansible, Harness, and Jenkins
  • Participate, lead, and adjudicate best practices secure application and infrastructure architecture
  • Research and publish standards for use of security technologies such as secrets management, key management, or rehydration patterns
  • Utilize understanding of progressive infrastructure practices such as containers, Kubernetes, and DevOps to implement security automation within these systems and associated processes
  • Develop techniques, strategies, and script automation to discover and implement hardening to Public cloud resources and services (AWS, Azure, GCP, Alibaba Cloud)
  • Support cloud and virtual machine image hardening and delivery
  • Support custom tool development using software development languages such as Python or NodeJS
  • Provide and presents status, analysis and reporting to internal stakeholders, Executive Management and Senior Leadership
  • Train and/or mentors other team members, and peers as appropriate
  • Identify opportunities to enhance the service delivery, operations, and continual service improvement processes
  • Perform other compliance-related functions as required
This advertiser has chosen not to accept applicants from your region.

Infrastructure Security Compliance Architect

Hyderabad, Andhra Pradesh People Prime Worldwide

Posted today

Job Viewed

Tap Again To Close

Job Description

About Client:

Our client is a global digital solutions and technology consulting company headquartered in Mumbai, India. The company generates annual revenue of over $4.29 billion (₹35,517 crore), reflecting a 4.4% year-over-year growth in USD terms. It has a workforce of around 86,000 professionals operating in more than 40 countries and serves a global client base of over 700 organizations.

Client: LTIMINDTREE


Job Type: C2H


Role: Senior Infrastructure Security & Compliance Engineer

Experience: 8-12y


Work Location:Bangalore


Payroll on : People Prime World Wide


Notice :0-15days


Job Description:

Senior Infrastructure Security & Compliance Engineer (Zero-Touch GPU Cloud – GitOps-Driven Compliance & Resilience)


We are seeking a Senior Infrastructure Security & Compliance Engineer with 10+ years of experience in infrastructure and platform automation to drive the Zero-Touch Build, Upgrade, and Certification pipeline for our on-prem GPU cloud environment. This role is focused on integrating security scanning, policy enforcement, compliance validation, and backup automation into a fully GitOps-managed GPU cloud stack, spanning hardware → OS → Kubernetes → platform layers.


Key Responsibilities

  • Design and implement GitOps-native workflows to automate security, compliance, and backup validation as part of the GPU cloud lifecycle.
  • Integrate Trivy into CI/CD pipelines for container and system image vulnerability scanning.
  • Automate kube-bench execution and remediation workflows to enforce Kubernetes security benchmarks (CIS/STIG).
  • Define and enforce policy-as-code using OPA/Gatekeeper to validate cluster and workload configurations.
  • Deploy and manage Velero to automate backup and disaster recovery operations for Kubernetes workloads.
  • Ensure that all compliance, scanning, and backup logic is declarative and auditable through Git-backed repositories.
  • Collaborate with infrastructure, platform, and security teams to define security baselines, enforce drift detection, and integrate automated guardrails.
  • Drive remediation automation and post-validation gates across build, upgrade, and certification pipelines.
  • Monitor evolving security threats and ensure tooling is regularly updated to detect vulnerabilities, misconfigurations, and compliance drift.


Required Skills & Experience

  • 10+ years of hands-on experience in infrastructure, platform automation, and systems security.
  • Primary key skills required are Python/Go/Bash scripting, OPA Rego policy writing, CI integration for Trivy & kube-bench, GitOps
  • Strong knowledge and practical experience with:
  • Trivy for container, filesystem, and configuration scanning
  • kube-bench for Kubernetes CIS benchmark compliance
  • Velero for Kubernetes-native backup and disaster recovery
  • OPA/Gatekeeper for policy-as-code and admission control
  • Deep understanding of GitOps workflows (e.G., Argo CD, Flux) and how to integrate security tools declaratively.
  • Proven experience automating security, compliance, and backup validation in CI/CD pipelines.
  • Solid foundation in Kubernetes internals, RBAC, pod security, and multi-tenant best practices.
  • Familiarity with vulnerability management lifecycles and security risk remediation strategies.
  • Experience with Linux systems administration, OS hardening, and secure bootstrapping.
  • Proficiency in scripting languages such as Python, Go, or Bash for automation and tooling integration.
  • Bonus:
  • Experience with SBOMs, image signing, or container supply chain security
  • Exposure to regulated environments (e.G., PCI-DSS, HIPAA, FedRAMP)
  • Contributions to open-source security/compliance projects


  • Seniority Level
  • Mid-Senior level
  • Industry
  • IT Services and IT Consulting
  • Software Development
  • Employment Type
  • Contract
  • Job Functions
  • Information Technology
  • Skills
  • Infrastructure Security
  • Compliance Engineering
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Security compliance Jobs in Hyderabad !

Information Security and Compliance Specialist

Hyderabad, Andhra Pradesh McDonald's

Posted today

Job Viewed

Tap Again To Close

Job Description

About McDonald’s:

One of the world’s largest employers with locations in more than 100 countries, McDonald’s Corporation has corporate opportunities in Hyderabad. Our global offices serve as dynamic innovation and operations hubs, designed to expand McDonald's global talent base and in-house expertise. Our new office in Hyderabad will bring together knowledge across business, technology, analytics, and AI, accelerating our ability to deliver impactful solutions for the business and our customers across the globe.


Position Summary:

Privacy, Security, & Risk Specialist: (Supervisor, Data Governance_G3_EDAA0104)

As a Data Risk & Compliance Analyst within the Enterprise Data Governance (EDG) team, you will play a key role in supporting data risk management, privacy, and compliance efforts across the organization. You will operationalize and enhance processes that support secure data practices, regulatory alignment, and the protection of sensitive data assets. Working cross-functionally with business, legal, privacy, and cybersecurity teams, you will help ensure that data governance capabilities are implemented with integrity and transparency.

This role combines technical acumen, risk assessment, and compliance management to support data discovery, access controls, data classification, and privacy risk assessments.


Who we’re looking for:

Primary Responsibilities:

  • Risk & Privacy Controls Execution : Maintain and support risk and privacy controls across key processes such as data retention, access monitoring, and records destruction.
  • Data Discovery & Classification Enablement : Help drive the implementation of data discovery, tagging, and classification activities by identifying structured data with privacy and regulatory implications.
  • Governance Platform Integration : Collaborate in testing and integrating data governance capabilities with risk and compliance systems (e.G., GRC tools, OneTrust, ServiceNow IRM).


Key Responsibilities:

  • Partner with the privacy, legal, and security teams to operationalize privacy-by-design, records management, and access governance.
  • Support the creation, enhancement, and enforcement of data handling policies, including ROPA, data classification, and regulatory reporting.
  • Maintain and analyze Records of Processing Activities (ROPA) and ensure accuracy and traceability of critical data elements.
  • Assist with privacy and compliance risk assessments, tracking mitigation plans, and supporting enterprise audit requests.
  • Align with Identity and Access Management teams to manage privileged access appropriately, supporting the governance of access control and provisioning.
  • Assist in developing data quality metrics, health indices, and access provisioning dashboards.
  • Provide expert guidance to EDG councils and data stewards regarding privacy, data protection, and compliance requirements.
  • Support the organization in addressing questions about security classification, data-sharing agreements, and retention schedules.


Skill:

  • Bachelor’s degree in information technology, Computer Science, or a related field.
  • 5+ years of experience in data governance, privacy, information risk, and compliance.
  • Familiarity with NIST CSF, NIST Privacy Framework, and ISO 27001.
  • Hands-on experience with GRC and privacy tools like OneTrust, RSA Archer, Collibra, or ServiceNow IRM.
  • Strong understanding of data discovery and classification technologies;
    ability to define policies and regex rules.
  • Knowledge of information governance, access control, and secure records lifecycle management.
  • Excellent analytical and communication skills with the ability to work across technical and business teams.
  • Cybersecurity certifications preferred (e.G., CISSP, CISA).


Work location: Hyderabad, India

Work pattern: Full time role.

Work mode: Hybrid.

This advertiser has chosen not to accept applicants from your region.

Senior Infrastructure Security & Compliance Engineer

Hyderabad, Andhra Pradesh People Prime Worldwide

Posted today

Job Viewed

Tap Again To Close

Job Description

About Client:

Our client is a global digital solutions and technology consulting company headquartered in Mumbai, India. The company generates annual revenue of over $4.29 billion (₹35,517 crore), reflecting a 4.4% year-over-year growth in USD terms. It has a workforce of around 86,000 professionals operating in more than 40 countries and serves a global client base of over 700 organizations.

Client: LTIMINDTREE


Job Type: C2H


Role: Senior Infrastructure Security & Compliance Engineer

Experience: 8-12y


Work Location:Bangalore


Payroll on : People Prime World Wide


Notice :0-15days


Job Description:

Senior Infrastructure Security & Compliance Engineer (Zero-Touch GPU Cloud – GitOps-Driven Compliance & Resilience)


We are seeking a Senior Infrastructure Security & Compliance Engineer with 10+ years of experience in infrastructure and platform automation to drive the Zero-Touch Build, Upgrade, and Certification pipeline for our on-prem GPU cloud environment. This role is focused on integrating security scanning, policy enforcement, compliance validation, and backup automation into a fully GitOps-managed GPU cloud stack, spanning hardware → OS → Kubernetes → platform layers.


Key Responsibilities

  • Design and implement GitOps-native workflows to automate security, compliance, and backup validation as part of the GPU cloud lifecycle.
  • Integrate Trivy into CI/CD pipelines for container and system image vulnerability scanning.
  • Automate kube-bench execution and remediation workflows to enforce Kubernetes security benchmarks (CIS/STIG).
  • Define and enforce policy-as-code using OPA/Gatekeeper to validate cluster and workload configurations.
  • Deploy and manage Velero to automate backup and disaster recovery operations for Kubernetes workloads.
  • Ensure that all compliance, scanning, and backup logic is declarative and auditable through Git-backed repositories.
  • Collaborate with infrastructure, platform, and security teams to define security baselines, enforce drift detection, and integrate automated guardrails.
  • Drive remediation automation and post-validation gates across build, upgrade, and certification pipelines.
  • Monitor evolving security threats and ensure tooling is regularly updated to detect vulnerabilities, misconfigurations, and compliance drift.


Required Skills & Experience

  • 10+ years of hands-on experience in infrastructure, platform automation, and systems security.
  • Primary key skills required are Python/Go/Bash scripting, OPA Rego policy writing, CI integration for Trivy & kube-bench, GitOps
  • Strong knowledge and practical experience with:
  • Trivy for container, filesystem, and configuration scanning
  • kube-bench for Kubernetes CIS benchmark compliance
  • Velero for Kubernetes-native backup and disaster recovery
  • OPA/Gatekeeper for policy-as-code and admission control
  • Deep understanding of GitOps workflows (e.g., Argo CD, Flux) and how to integrate security tools declaratively.
  • Proven experience automating security, compliance, and backup validation in CI/CD pipelines.
  • Solid foundation in Kubernetes internals, RBAC, pod security, and multi-tenant best practices.
  • Familiarity with vulnerability management lifecycles and security risk remediation strategies.
  • Experience with Linux systems administration, OS hardening, and secure bootstrapping.
  • Proficiency in scripting languages such as Python, Go, or Bash for automation and tooling integration.
  • Bonus:
  • Experience with SBOMs, image signing, or container supply chain security
  • Exposure to regulated environments (e.g., PCI-DSS, HIPAA, FedRAMP)
  • Contributions to open-source security/compliance projects


  • Seniority Level
  • Mid-Senior level
  • Industry
  • IT Services and IT Consulting
  • Software Development
  • Employment Type
  • Contract
  • Job Functions
  • Information Technology
  • Skills
  • Infrastructure Security
  • Compliance Engineering
This advertiser has chosen not to accept applicants from your region.

Senior Infrastructure Security & Compliance Engineer

Hyderabad, Andhra Pradesh People Prime Worldwide

Posted today

Job Viewed

Tap Again To Close

Job Description

About Client:
Our client is a global digital solutions and technology consulting company headquartered in Mumbai, India. The company generates annual revenue of over $4.29 billion (₹35,517 crore), reflecting a 4.4% year-over-year growth in USD terms. It has a workforce of around 86,000 professionals operating in more than 40 countries and serves a global client base of over 700 organizations.
Client : LTIMINDTREE

Job Type : C2H

Role: Senior Infrastructure Security & Compliance Engineer
Experience: 8-12y

Work Location:Bangalore

Payroll on : People Prime World Wide

Notice :0-15days

Job Description:
Senior Infrastructure Security & Compliance Engineer (Zero-Touch GPU Cloud – GitOps-Driven Compliance & Resilience)

We are seeking a Senior Infrastructure Security & Compliance Engineer with 10+ years of experience in infrastructure and platform automation to drive the Zero-Touch Build, Upgrade, and Certification pipeline for our on-prem GPU cloud environment. This role is focused on integrating security scanning, policy enforcement, compliance validation, and backup automation into a fully GitOps-managed GPU cloud stack, spanning hardware → OS → Kubernetes → platform layers.

Key Responsibilities
Design and implement GitOps-native workflows to automate security, compliance, and backup validation as part of the GPU cloud lifecycle.
Integrate Trivy into CI/CD pipelines for container and system image vulnerability scanning.
Automate kube-bench execution and remediation workflows to enforce Kubernetes security benchmarks (CIS/STIG).
Define and enforce policy-as-code using OPA/Gatekeeper to validate cluster and workload configurations.
Deploy and manage Velero to automate backup and disaster recovery operations for Kubernetes workloads.
Ensure that all compliance, scanning, and backup logic is declarative and auditable through Git-backed repositories.
Collaborate with infrastructure, platform, and security teams to define security baselines, enforce drift detection, and integrate automated guardrails.
Drive remediation automation and post-validation gates across build, upgrade, and certification pipelines.
Monitor evolving security threats and ensure tooling is regularly updated to detect vulnerabilities, misconfigurations, and compliance drift.

Required Skills & Experience
10+ years of hands-on experience in infrastructure, platform automation, and systems security.
Primary key skills required are Python/Go/Bash scripting, OPA Rego policy writing, CI integration for Trivy & kube-bench, GitOps
Strong knowledge and practical experience with:
Trivy for container, filesystem, and configuration scanning
kube-bench for Kubernetes CIS benchmark compliance
Velero for Kubernetes-native backup and disaster recovery
OPA/Gatekeeper for policy-as-code and admission control
Deep understanding of GitOps workflows (e.g., Argo CD, Flux) and how to integrate security tools declaratively.
Proven experience automating security, compliance, and backup validation in CI/CD pipelines.
Solid foundation in Kubernetes internals, RBAC, pod security, and multi-tenant best practices.
Familiarity with vulnerability management lifecycles and security risk remediation strategies.
Experience with Linux systems administration, OS hardening, and secure bootstrapping.
Proficiency in scripting languages such as Python, Go, or Bash for automation and tooling integration.
Bonus:
Experience with SBOMs, image signing, or container supply chain security
Exposure to regulated environments (e.g., PCI-DSS, HIPAA, FedRAMP)
Contributions to open-source security/compliance projects

Seniority Level
Mid-Senior level
Industry
IT Services and IT Consulting
Software Development
Employment Type
Contract
Job Functions
Information Technology
Skills
Infrastructure Security
Compliance Engineering
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Compliance Jobs View All Jobs in Hyderabad