Information Security Engineer

4 weeks ago


Bangalore, India Talent one Consulting Full time

Job Description

- Develop and finalize policies, procedures, and guidelines related to IT and Infosec domains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2)

- Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards and security guidelines

- Assist in defining and reviewing the key metrics for management reporting

- Develop of cyber security standards, including incorporating industry practices and applicable compliance requirements

- Maintain the the security risk register and related policies

- Maintain the inventory of IT vendors as per regulatory guidelines.

- Develop review checklists, questionnaire, and manage evidences to assist the IT vendor risk management process

- Perform 3rd party security due-diligence reviews and periodic vendor risk assessments to assess vendor compliance.

- Coordinate with external stakeholders and auditors for IT and Infosec related reviews

- Coordinate for conducting periodic penetration testing exercises on in-scope applications and related infrastructure. Coordinate with stakeholders for timely closure of open risks.

- Assist in imparting security awareness training and executing phishing simulation exercises to employees.

- Assist IT and Infosec in gathering the metrics data and prepare management dashboards

- Lead the periodic IT and Infosec governance review meetings and gather feedback for improvement

- Assess the existing IT and Infosec processes and provide recommendations to improve

- Identify opportunities for IT and Infosec governance automation and lead the continuous compliance initiatives

- Support cross-entity teams/group entities to mirror the best practices implemented at the parent entity

- Develop templates for incident reporting and manage artifacts. Assist during incident investigation and collaborating with stakeholders.

- Audit Coordination:

- Coordinate and facilitate SOC 2 audits, acting as the primary point of contact for the external auditor.

- Gather evidence and documentation to demonstrate compliance with SOC 2 requirements.

- Address any audit findings and implement corrective actions.

Key Areas: SOC 2 Type 1 and Type 2, ISO 27001, GDPR ,security governance, vendor security due-diligence, vendor security reviews and assessment, preparation of security checklist, security awareness/phishing simulation, management dashboards, manage key metrics for IT and Infosec,

Certifications: good to have - CISSP, CISM, ISO 27001, or CISA (Knowledge and experience in SOC 2 is mandatory)

Experience :

- Should have 5 - 7 years of experience in information security domain and minimum should have 4 of years in overall IT and Infosec governance related activities.

- Must have sound knowledge in defining processes, developing policies, procedures, and guidelines, and preparing management reporting dashboards.

- Must have experience in guiding teams with respect to SOC 2 requirements

- Developing and implementing enterprise governance, risk, and compliance strategy and solutions

- Ability to document and explain details in a concise & understandable manner

- Industry recognized certificates relevant to the roles such as SOC 2, ISO 27001 are desired

- Ability to lead complex, cross-functional projects, and problem-solving initiatives.

- Passionate about IT/information security and update knowledge on daily basis to support the organization

- Candidates must have excellent verbal and written communication skills

- Familiarity with industry standards and regulations including PCI, ISO27001, SOC 2, GDPR, CIS, NIST is desired.

- Candidates from BFSI experience will be preferred

- Fair understanding of public cloud models (e.g. AWS, Google, Microsoft Azure) and their security implications

Skills :

- Candidate should be a good team player

- Should have good interpersonal skills

- Good written communication skills including ability to develop process documentation and security guidelines.

- Ability to apply critical thinking and logic to a wide range of intellectual and practical problems

- Ability to maintain composure under pressure and work calmly during an emergency

- Ability to manage multiple tasks and schedules

(ref:hirist.tech)

  • Bangalore, India LinkedIn Full time

    Linked In is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We’re also committed to providing transformational opportunities for our...


  • Bangalore, India LinkedIn Full time

    LinkedIn is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day.We’re also committed to providing transformational opportunities for our own...


  • Bangalore, India LinkedIn Full time

    Linked In is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We’re also committed to providing transformational opportunities for our...


  • Bangalore, India LinkedIn Full time

    LinkedIn is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We’re also committed to providing transformational opportunities for our own...


  • Bangalore, India LinkedIn Full time

    About Linkedin Linked In is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We’re also committed to providing transformational...


  • Bangalore, India Navi Full time

    About Navi Navi is one of the fastest-growing financial services companies in India providing Personal & Home Loans, UPI, Insurance, Mutual Funds, and Gold. Navi's mission is to deliver digital-first financial products that are simple, accessible, and affordable. Drawing on our in-house AI/ML capabilities, technology, and product expertise, Navi is...


  • Bangalore, India Traceable AI Full time

    About role : The GRC Engineer is essential for maintaining the organization's security and compliance through effective governance, risk management, and compliance frameworks. With a solid background in cybersecurity and experience in privacy regulations like GDPR and CPPA, this role involves monitoring internal controls, facilitating customer...


  • bangalore, India Navi Full time

    About Navi Navi is one of the fastest-growing financial services companies in India providing Personal & Home Loans, UPI, Insurance, Mutual Funds, and Gold. Navi's mission is to deliver digital-first financial products that are simple, accessible, and affordable. Drawing on our in-house AI/ML capabilities, technology, and product expertise, Navi is...


  • Bangalore, India Muthoot Fincorp Ltd. Full time

    ROLE SUMMARY (PURPOSE) The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing...


  • bangalore, India Muthoot Fincorp Ltd. Full time

    ROLE SUMMARY (PURPOSE)The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing...


  • Bangalore, India Murf AI Full time

    At , we're simplifying multimedia creation by harnessing the power of artificial intelligence. Our platform empowers users to craft high-quality voiceovers effortlessly, without the need for recording equipment. Some interesting facts about Murf AI: Customers in 100+ countries 8 Mn+ registered users 6 X growth in revenue in the last 12 months ...


  • bangalore, India LinkedIn Full time

    LinkedIn is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We’re also committed to providing transformational opportunities for our own...


  • Bangalore, India Head pro Full time

    Duties & Responsibilities : - Assists in the execution of he Information Security Program, Data Governance practices, and Privacy assurance- Analyzes risk of existing network and system architectures against correlating policies and risks, and provides technical input for appropriate remediation or action plans- Participates in the following and enforcement...


  • bangalore, India Ambient Security Full time

    Ambient Security is an exciting new startup, looking to reduce the risk of privileged account takeovers and cyber attacks for large enterprises. The founder and CEO is a 7x cyber security entrepreneur with a track record of successful exits. Ws seeking software engineers at all levels to lead the design and implementation of innovative technologies. We are...


  • Bangalore, India HeadPro Consulting LLP Full time

    Looking Candidates only from Bangalore with 30 Days notice period and Relevant experience of Information Security with 5 years in OT/IOT (SCADA).Network Segmentation experience in Information Security is Mandatory Duties & Responsibilities : - Assists in the execution of the Information Security Program, Data Governance practices, and Privacy assurance-...


  • bangalore, India LinkedIn Full time

    LinkedIn is the world’s largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We’re also committed to providing transformational opportunities for our own...


  • Bangalore, India ORO Labs Full time

    Company Profile: Established in 2020 and headquartered in California, ORO Labs is a Saa S based procurement startup that makes procurement easy and efficient for all employees. We dramatically improve traditional procurement operations by taming the chaotic enterprise spending on business-critical purchases and supplier engagements. We have worked...


  • Bangalore, India ORO Labs Full time

    Company Profile: Established in 2020 and headquartered in California, ORO Labs is a SaaS based procurement startup that makes procurement easy and efficient for all employees. We dramatically improve traditional procurement operations by taming the chaotic enterprise spending on business-critical purchases and supplier engagements. We have worked...


  • Bangalore, India Navi Full time

    About Navi Navi is one of the fastest-growing financial services companies in India providing Personal & Home Loans, UPI, Insurance, Mutual Funds, and Gold. Navi's mission is to deliver digital-first financial products that are simple, accessible, and affordable. Drawing on our in-house AI/ML capabilities, technology, and product expertise, Navi is...


  • Bangalore, India MishiPay Full time

    Information Security Manager Mishipay Competitive basic salary and bonus Bangalore About the company: MishiPay is an international, leading checkout technology company that empowers shoppers to checkout instore using either self-checkout via their own smartphones, or using MishiPay's industry leading, minimalist, low cap-ex kiosks. We are...