Information Security Engineer
2 months ago
Job Description
- Develop and finalize policies, procedures, and guidelines related to IT and Infosec domains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2)
- Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards and security guidelines
- Assist in defining and reviewing the key metrics for management reporting
- Develop of cyber security standards, including incorporating industry practices and applicable compliance requirements
- Maintain the the security risk register and related policies
- Maintain the inventory of IT vendors as per regulatory guidelines.
- Develop review checklists, questionnaire, and manage evidences to assist the IT vendor risk management process
- Perform 3rd party security due-diligence reviews and periodic vendor risk assessments to assess vendor compliance.
- Coordinate with external stakeholders and auditors for IT and Infosec related reviews
- Coordinate for conducting periodic penetration testing exercises on in-scope applications and related infrastructure. Coordinate with stakeholders for timely closure of open risks.
- Assist in imparting security awareness training and executing phishing simulation exercises to employees.
- Assist IT and Infosec in gathering the metrics data and prepare management dashboards
- Lead the periodic IT and Infosec governance review meetings and gather feedback for improvement
- Assess the existing IT and Infosec processes and provide recommendations to improve
- Identify opportunities for IT and Infosec governance automation and lead the continuous compliance initiatives
- Support cross-entity teams/group entities to mirror the best practices implemented at the parent entity
- Develop templates for incident reporting and manage artifacts. Assist during incident investigation and collaborating with stakeholders.
- Audit Coordination:
- Coordinate and facilitate SOC 2 audits, acting as the primary point of contact for the external auditor.
- Gather evidence and documentation to demonstrate compliance with SOC 2 requirements.
- Address any audit findings and implement corrective actions.
Key Areas: SOC 2 Type 1 and Type 2, ISO 27001, GDPR ,security governance, vendor security due-diligence, vendor security reviews and assessment, preparation of security checklist, security awareness/phishing simulation, management dashboards, manage key metrics for IT and Infosec,
Certifications: good to have - CISSP, CISM, ISO 27001, or CISA (Knowledge and experience in SOC 2 is mandatory)
Experience :
- Should have 5 - 7 years of experience in information security domain and minimum should have 4 of years in overall IT and Infosec governance related activities.
- Must have sound knowledge in defining processes, developing policies, procedures, and guidelines, and preparing management reporting dashboards.
- Must have experience in guiding teams with respect to SOC 2 requirements
- Developing and implementing enterprise governance, risk, and compliance strategy and solutions
- Ability to document and explain details in a concise & understandable manner
- Industry recognized certificates relevant to the roles such as SOC 2, ISO 27001 are desired
- Ability to lead complex, cross-functional projects, and problem-solving initiatives.
- Passionate about IT/information security and update knowledge on daily basis to support the organization
- Candidates must have excellent verbal and written communication skills
- Familiarity with industry standards and regulations including PCI, ISO27001, SOC 2, GDPR, CIS, NIST is desired.
- Candidates from BFSI experience will be preferred
- Fair understanding of public cloud models (e.g. AWS, Google, Microsoft Azure) and their security implications
Skills :
- Candidate should be a good team player
- Should have good interpersonal skills
- Good written communication skills including ability to develop process documentation and security guidelines.
- Ability to apply critical thinking and logic to a wide range of intellectual and practical problems
- Ability to maintain composure under pressure and work calmly during an emergency
- Ability to manage multiple tasks and schedules
-
Traceable - GRC Engineer - Information Security
2 months ago
Bangalore, Karnataka, India Traceable AI Full timeAbout role : The GRC Engineer is essential for maintaining the organization's security and compliance through effective governance, risk management, and compliance frameworks. With a solid background in cybersecurity and experience in privacy regulations like GDPR and CPPA, this role involves monitoring internal controls, facilitating customer...
-
Senior Staff Information Security Engineer
4 weeks ago
Bangalore, Karnataka, India Head pro Full timeDuties & Responsibilities :- Assists in the execution of he Information Security Program, Data Governance practices, and Privacy assurance- Analyzes risk of existing network and system architectures against correlating policies and risks, and provides technical input for appropriate remediation or action plans- Participates in the following and enforcement...
-
Senior Staff Information Security Engineer
2 months ago
Bangalore, Karnataka, India HeadPro Consulting LLP Full timeLooking Candidates only from Bangalore with 30 Days notice period and Relevant experience of Information Security with 5 years in OT/IOT (SCADA).Network Segmentation experience in Information Security is MandatoryDuties & Responsibilities :- Assists in the execution of the Information Security Program, Data Governance practices, and Privacy assurance-...
-
Information Security Associate
2 months ago
Bangalore, Karnataka, India QUESS Full timeRole : Information Security Associate (Application/Infrastructure Security) No of years' experience required : 3 to 6 years Job Role : - Global service delivery of Information Security Architecture services for Commercial Vehicle locations. - Perform application threat modelling based on STRIDE/DREAD model, use C4 data model architecture to identify the...
-
Information Security Engineer
6 months ago
Bangalore, Karnataka, India HyrEzy Talent Solutions Full timeRoles & Responsibilities (BSc. IT, BE) with Information Security Certifications - CISM, CISSPEXPERIENCE :- Candidate must have strong experience in Information Security Management system, Policy & procedures creation, implementation- ISO27001 assessment - Specification for a framework of policies procedures that include all technical & operational controls-...
-
Karbon Card
2 months ago
Bangalore, Karnataka, India INTERROPAC PRIVATE LIMITED Full timeJob Description Position Summary : The Information Security Officer is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. The Head of IS responds to incidents, establishes appropriate standards and controls, manages security technologies, and...
-
Security Sustainment Engineer
2 months ago
Bangalore, Karnataka, India Mindlance Technology Full timeJob description : We're looking for a Staff Engineer, Security Sustainment to join our Cybersecurity department. In this role, you'll be responsible for ensuring security infrastructure is maintained at the highest level of protection and efficiency. The primary goal of this role is to support the security sustainment engineering team to maintain...
-
Principal Engineer
2 months ago
Bangalore, Karnataka, India Baxter international Full timePosting Title : Principal Engineer, Software - Product Security, PSS/GSSYour Role at Baxter :The role of Principal Engineer, Software - Product Security works in close collaboration with the project & cybersecurity lead on assigned tasks and provides inputs to the design and testing of the new product/project. The engineer also provides guidance to software...
-
Application Security Engineer
1 month ago
Bangalore, Karnataka, India Freelancer Recruiter Full timePrimary Skills : agile,c,java,SCA/SAST,OSA,jenkins,mobile application security,SSDLC automationSecondary Skills : Python, waterfall- Understanding of information security key concepts- Ability to analyze security issues (both white-box and black-box), determine their cause and impact on the business and identify the corrective action needed to eliminate and...
-
DevOps Security Operations Engineer
2 months ago
Bangalore, Karnataka, India Prime Infosoft Full timeWe are seeking a highly skilled AWS DevOps Engineer with extensive experience in FedRAMP setup and compliance. The ideal candidate will have a strong background in cloud infrastructure, automation, and security, with a focus on ensuring compliance with FedRAMP standards.Key Responsibilities :DevOps :- Develop and maintain CI/CD pipelines using tools like...
-
Uni Club
2 months ago
Bangalore, Karnataka, India UniCards Full timeJob Description :We are seeking a motivated and skilled Security Engineer-1 to join our dynamic team. The ideal candidate will have hands-on experience in security testing across all domains and possess a strong understanding of information security compliance requirements. This role will be responsible for ensuring the security and integrity of our systems,...
-
Security Engineer
1 month ago
Bangalore, Karnataka, India MNR Solutions Full timeCore Security Skills : - Network Security, including firewall configurations, intrusion detection/prevention systems (IDS/IPS)- Vulnerability assessment and penetration testing (VAPT)- Incident response and threat hunting- Security Information and Event Management (SIEM) tools (e.g., Splunk, QRadar, ArcSight)- Knowledge of secure coding practices and code...
-
Security Analyst
2 months ago
Bangalore, Karnataka, India MNR Solutions Full timeJob Description :We are looking for a skilled Security Analyst to join our team in Bangalore. The ideal candidate will have a strong understanding of cybersecurity principles and practices, with experience in monitoring and responding to security incidents.Responsibilities :- Monitor network traffic and security alerts to identify potential threats and...
-
Firmware Engineer
4 weeks ago
Bangalore, Karnataka, India PEOPLEPLUS PROFESSIONAL SERVICES PVT LTD Full timeLocation : Bangalore, IndiaExperience : 3-7 Years Notice Period : Immediate or up to 1 Month About the Role :We are seeking an experienced Firmware Engineer specializing in either Security or Memory Firmware to join our Research & Development (R&D) team. The role involves managing the complete software life cycle, including analysis, development,...
-
Lead - Security Operations
2 months ago
Bangalore, Karnataka, India MNR Solutions Private Limited Full timePosition Title : Lead - Security Operations Organization /Function : - Lead the team to perform daily operational security services we offer our customers. - Manage new rollout of security tools and process and manage upgrade projects - Years of experience 6 to 8 years Relevant Experience : - Minimum 6 years of Security Operations and at least 1 year as...
-
Security Operations Lead
2 months ago
Bangalore, Karnataka, India MNR Solutions Private Limited Full timePosition Title : Security Operations Lead - Organization /Function : Lead the team to perform daily operational security services we offer our customers. - Manage new rollout of security tools and process and manage upgrade projects - Years of experience 6 to 8 years - Relevant Experience : Minimum 6 years of Security Operations and at least 1 year as...
-
Product Security Specialist
4 weeks ago
Bangalore/Bengaluru, Karnataka, India, Karnataka ASCHPRO IT SOLUTIONS PRIVATE LIMITED Full timeRoles : INFORMATION SECURITY ARCHITECT. Work Timings : 1:30PM to 10:30PM IST. "Hybrid Work policy". At a minimum, we would like you to have : - 5 years of experience in Information Security. - 5 years of experience in Network Security, Endpoint Security, Data Security, Cloud Security, Application Security, Security Testing and/or similar area of security. -...
-
BluSapphire Cyber Systems
2 months ago
Bangalore, Karnataka, India Blusapphire Cyber Systems Pvt Ltd Full timePosition Details : Solution Engineer Continuing its strategic expansion, BluSapphire seeks experienced, dynamic professionals for the Solution Engineer role. This position plays a vital role in designing and implementing cybersecurity solutions to our esteemed clients.Location : Bangalore Desired Qualification : B.Tech or BE Computers / MCA. Certifications...
-
Cloud Security Engineer
2 months ago
Bangalore, Karnataka, India 2coms Full timeLooking For Cloud Security Professionals For Global IT MNC. Greetings From 2COMS Group!. Location : Bangalore/Chennai. Experience : 6+ years. Must-Have : The candidate should have 4 years of relevant experience in cloud security. Job Description : Networking and Firewall Management : - Understanding of network security principles, including firewalls,...
-
DevSecOps Manager
1 month ago
Bangalore, Karnataka, India Freelance Full timeJob Description :Business Requirements : - Provide oversight and experience with your understanding of Cloud services, DevOps/SecOps toolsets and platforms, Secure SDLC practices as well as monitoring and logging technologies. - Implement and integrate tools into our CI/CD pipelines that shift security left - Define and drive automation framework for Secure...