Information Security Spec II
Accountabilities Own the enterprise Data Loss Prevention program end to end, including policy design, tuning, exception management, new functionality, and deployment in partnership with Legal and data owners.
Define and enforce protection controls for high-risk company assets, ensuring DLP policies align with legal, regulatory, privacy, and business requirements.
Maintain and periodically review an inventory of protected assets and sensitive data in collaboration with Legal and relevant data owners.
Assess Azure and AWS environments for security risks and drive remediation of identified findings, with a focus on reducing High and Critical cloud vulnerabilities.
Support Azure security engineering initiatives, including secure configuration, identity and workload hardening, Microsoft Graph API automation, and security control improvements.
Serve as the primary security escalation contact during non-US hours for High and Critical alerts, taking ownership of complex incidents from detection through documented closure within defined SLAs.
Partner with managed detection and response providers and act as an integration owner and backup point of contact for third-party security operations.
Strengthen L2 security support through standardized SOPs, expert guidance, structured escalation processes, automation, and SOAR playbooks that enable more issues to be resolved at the L2 level.
Monitor security logs and cloud infrastructure for potential threats, vulnerabilities, and anomalous activity, coordinating investigation and remediation as needed.
Review and audit security configurations, including firewalls, intrusion detection systems, encryption technologies, security groups, and cloud security controls.
Assess networks and cloud environments for vulnerabilities and recommend practical remediation strategies.
Ensure information security operations remain aligned with ISO 27001, data privacy regulations, customer commitments, and other applicable requirements.
Support internal and external audits, regulatory requests, FedRAMP activities, and Legal inquiries.
Prepare security reports, technical presentations, KPIs, and operational metrics to support management decision-making.
Contribute to special security projects and develop broader T-shaped expertise across key information security and IT domains.
Requirements
8+ years of relevant information security experience, including hands-on ownership of enterprise security programs.
Bachelor's degree in Information Security, Computer Science, or a related discipline, or equivalent professional experience. An advanced degree is a plus.
Deep hands-on experience owning an enterprise DLP program, including policy authoring, tuning, exception management, data classification, and sensitivity labeling. Experience with Microsoft Purview DLP and Information Protection is preferred.
Strong Azure cloud security expertise, including experience with Defender for Cloud, Entra ID, Azure Policy, network security, workload protection, security assessments, and remediation at scale.
Experience with AWS security is an advantage, particularly in cloud security assessment, configuration, and remediation.
Proven L2/L3 incident response experience, including ownership of High and Critical security incidents through resolution in collaboration with an MSSP or 24/7 SOC.
Strong ability to create and maintain SOPs, incident runbooks, automation playbooks, and security documentation.
Working knowledge of Microsoft Graph API and scripting or automation using PowerShell, Python, or comparable technologies.
Strong understanding of information security and data privacy frameworks and regulations, including ISO 27001, GDPR, and related requirements.
Experience supporting internal or external security audits and compliance activities.
Strong knowledge of security monitoring, vulnerability assessment, cloud security controls, incident investigation, and production security operations.
Professional certifications such as CISSP, CCSP, AZ-500, SC-400, GCIH, or equivalent are preferred.
Excellent written and verbal communication skills, with the ability to explain security risks, technical trade-offs, and remediation priorities to Legal, business stakeholders, executives, and technical teams.
Strong judgment, ownership, analytical thinking, and ability to make effective decisions during high-severity security incidents.
Comfortable working collaboratively with global IT teams, application teams, business users, and external security service providers.
Willingness and ability to provide security escalation coverage during non-US hours for global High and Critical incidents.
Benefits
Remote work opportunity based in India.
Competitive total rewards package designed to support employee health, financial wellbeing, and professional development.
Competitive insurance plans covering employees and immediate family members.
Annual health checkup.
Marriage leave and paternity leave.
Employee Assistance Programme.
Extensive learning and development opportunities.
Opportunity to work on enterprise-scale information security, cloud security, and data protection initiatives.
Exposure to global security operations, compliance programs, and modern cloud technologies.
Collaborative international environment with opportunities to develop broad technical and cross-functional expertise.
Equal opportunity workplace welcoming candidates from diverse backgrounds.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1