Corporate Risk and Compliance - Associate II

Zeta

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Diversity and inclusivity initiatives
Professional development opportunities

Job summary

Zeta in Bengaluru is seeking a Level 2 Information Security professional to bridge operations and governance. The ideal candidate will have strong technical expertise in security systems and excellent communication skills to collaborate effectively across teams.

Responsibilities include endpoint security management, network control audits, email security safeguarding, and ensuring compliance with industry standards. Candidates should possess a Bachelor's degree and relevant certifications in information security.

Qualifications

  • 3+ years of experience in Information Security, Risk & Compliance, Endpoint Security, or Technical GRC role.
  • Certifications such as Microsoft Certified Associate: SC-200, SC-300, or SC-900 are required.

Responsibilities

  • Assess and regulate/optimize Microsoft Entra ID and Intune MDM/MAM.
  • Monitor and audit perimeter and infrastructure security controls.
  • Manage anti-phishing, anti-spam policies, and authentication protocols.
  • Govern cloud security best practices across AWS and Azure.
  • Act as the Risk & Compliance guardian for the business.

Skills

Microsoft Stack
Networking & Perimeter Security
Email Protocols & Infrastructure
Multi-OS Mastery
Automation & Scripting
Compliance Automation
Cloud Infrastructure
Security Fundamentals
Frameworks & Process
Documentation & Audit Support
Emerging Tech & AI

Education

Bachelor of Technology (BE/B.Tech) in Computer Science or equivalent

Tools

Microsoft Defender
M365 product/security suites
Next-Gen Firewalls
Intune MDM/MAM
AWS
Azure

Job description

About the Role

We are seeking a highly capable Level 2 Information Security professional who effectively bridges the gap between hands‑on technical operations and governance. This role demands a unique combination of technical expertise across endpoint, network, and email security systems, paired with a Governance, Risk, and Compliance (GRC) mindset. Beyond managing technical controls, the ideal candidate must be an exceptional communicator capable of collaborating across diverse internal teams, managing security risk exceptions, and meticulously tracking open compliance and remediation items to closure.

Responsibilities
  • Endpoint & Identity Security: Assess and regulate/optimize Microsoft Entra ID (Conditional Access, Identity Protection) and Intune MDM/MAM to manage configuration and compliance profiles for both Windows and macOS environments. Investigate security timelines using Microsoft Defender for Endpoint.
  • Network Security: Assess, monitor, regulate and audit perimeter and infrastructure security controls across a multi‑vendor environment, including Next‑Gen Firewalls (Fortinet/SonicWall/Check Point/Cisco) and enterprise wireless architectures (Aruba Wi‑Fi).
  • Email Security & Gateway Security: Assess, monitor, regulate and audit enterprise email security gateways and protection suites (e.g., Defender for MS365). Manage anti‑phishing, anti‑spam, and safe attachments policies, and maintain foundational authentication protocols including SPF, DKIM, and DMARC.
  • Data Protection & DLP: Tune and monitor Endpoint and Network Data Loss Prevention policies, analyzing data flows to prevent unauthorized exposure of proprietary or regulated data.
  • Cloud Security Governance: Govern and enforce security best practices across AWS and Azure. Monitor security posture (CSPM), audit IAM configurations, and secure cloud storage.
  • GRC Alignment & Audit Support: Map everyday technical configurations to ISO 27001 and PCI‑DSS controls. Systematically gather and organize log/configuration evidence for internal and external auditors.
  • R&C Business Support: Act as the Risk & Compliance guardian for the business; review, evaluate, and respond to incoming IT tickets, change requests, and end‑user security queries to ensure no unauthorized risks are introduced.
  • Cross‑Functional Collaboration: Act as the security bridge to Helpdesk, Infrastructure, DevOps, and Business teams. Translate technical risks into clear, actionable business language to drive fixes.
  • Action Item Tracking: Meticulously track open vulnerabilities, audit gaps, and risk exceptions. Own the follow‑up lifecycle to ensure internal teams resolve items within agreed SLAs.
Skills
  • Microsoft Stack: Strong understanding of M365 product/security suites, Intune deployments, and hybrid identity environments.
  • Networking & Perimeter Security: Strong understanding of networking technologies, network security, enterprise firewalls, and secure perimeter controls.
  • Email Protocols & Infrastructure: Strong working knowledge of email security infrastructure, mail routing, and authentication standards (SPF, DKIM, DMARC).
  • Multi‑OS Mastery: Solid understanding of different operating systems, including enterprise management of Windows, Linux, and macOS environments.
  • Automation & Scripting: Strong understanding of developing and reviewing technical scripts using common languages (e.g., Bash/Shell, Python) to analyze logs or automate checks.
  • Compliance Automation: Experience automating and templating security processes, metrics, and documentation for strict compliance purposes.
  • Cloud Infrastructure: Solid understanding of public cloud technologies with hands‑on technical knowledge of at least one major public cloud platform (AWS or Azure).
  • Security Fundamentals: Comprehensive understanding and hands‑on of Vulnerability Assessments, Penetration Testing concepts, Identity & Access Management (IAM), and Endpoint Security.
  • Frameworks & Process: Practical understanding of IT security frameworks, controls, and auditing processes—including CIS, NIST, PCI‑DSS, and SOC 1/2.
  • Documentation & Audit Support: Ability to author clear Standard Operating Procedures (SOPs) and systematically manage compliance evidence collection.
  • Emerging Tech & AI: Basic understanding of AI tools and technologies, including their safe implementation and associated risk factors.
Experience and Qualifications
  • 3+ years of experience in Information Security, Risk & Compliance, Endpoint Security, Network Security or Technical GRC role.
  • Bachelor of Technology (BE/B.Tech) in Computer Science or equivalent.
  • Certifications (at least one of the following or equivalent is required):
    • Identity & Cloud Security (Microsoft Certified Associate: SC‑200, SC‑300, or SC‑900).
    • Security Fundamentals (ISC² CC, CompTIA Security+, or CEH).
    • Network Security (CCNA, Certified Security Associate, NSE 4, or JNCIA).
EEO Statement

Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infosec GRC Associate II
Infosec GRC Associate II

Zeta • Bengaluru

On-site
INR 800,000 - 1,200,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000
Information Security Engineer - GRC
Information Security Engineer - GRC

EDGE Executive Search • Gurugram District

On-site
INR 900,000 - 1,500,000
Manager — Information Security and Compliance
Manager — Information Security and Compliance

APEX Analytix • India

On-site
USD 120,000 - 150,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

Icertis • Maharashtra

On-site
INR 4,000,000 - 7,000,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens Mobility • Gurugram District

On-site
INR 2,500,000 - 4,000,000
IT Security Support Engineer
IT Security Support Engineer

Fusion Practices • Maharashtra

On-site
INR 600,000 - 900,000
Cybersecurity SME
Cybersecurity SME

Recruise • Hyderabad

On-site
INR 3,500,000 - 5,500,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000