A complete application in a minute — tailored resume and cover letter, ready to send.
CustomerInsights.AI is seeking a proactive IT Security Engineer with 4+ years of hands-on cybersecurity experience. You will lead L1 security operations, manage endpoint protection, and govern Microsoft 365 and Azure AD security across our global environments.
The role collaborates with IT, audit, and compliance to maintain a strong security posture and controls. The role covers device provisioning, onboarding/offboarding, and secure endpoint management, with emphasis on MFA, SSO, and policy
CustomerInsights.AI is a global analytics and AI-driven company founded in 2018, enabling data-driven commercial decision-making for Life Sciences organizations. Our product ecosystem, including ciPARTHENON and ciATHENA, leverages Analytics Automation, Artificial Intelligence, and Machine Learning to deliver timely, actionable insights to key stakeholders. With teams across North America and India, we work with client organizations ranging from emerging startups to large enterprises.
We are seeking a proactive and detail-oriented IT Security Engineer with 4+ years of hands-on experience in cybersecurity operations, endpoint security, vulnerability management, and identity security. In this role, you will be a critical part of our IT team, responsible for both day-to-day L1 security operations and strategic security initiatives.
You will work collaboratively with IT, audit, compliance, and business stakeholders to ensure our security posture remains strong, our endpoints are secured, and our Microsoft 365 & cloud environments are configured to the highest standards.
End-to-end L1 IT Security operations from device setup to user lifecycle management
Microsoft 365 & Azure AD security governance, monitoring, and policy enforcement
Proactive threat detection, incident response, and vulnerability remediation
Security documentation, compliance readiness, and audit evidence management
Device Provisioning: Perform end-to-end laptop setup and configuration for new joiners:
Imaging, OS configuration, software installation, and domain enrollment
Applying security baselines, disk encryption (BitLocker), and MDM enrollment
Asset tagging, inventory tracking, and documentation in the CMDB
Onboarding: Manage the complete employee onboarding process from an IT Security perspective:
Create user accounts across Active Directory, Azure AD, and M365
Assign role-based licenses, groups, and permissions as per approved access matrix
Configure MFA, SSO, and ensure secure first-login experience
Walk new employees through IT security policies and acceptable use guidelines
Offboarding: Execute secure and timely employee offboarding processes:
Disable/delete accounts across all systems within SLA on last working day
Revoke VPN, email, application, and cloud resource access immediately
Retrieve company devices, wipe data, and update inventory records
Archive mailboxes and transfer data ownership to Reporting Manager
Endpoint Security: Implement and manage endpoint security controls including antivirus, EDR agents, disk encryption, USB controls, and device hardening policies
MDM Administration: Administer MDM (Microsoft Intune / similar) enroll devices, push policies, and enforce compliance
L1 Security Support: Provide Level 1 security support for end-user security issues, phishing reports, and access requests
M365 Portal Review: Conduct regular reviews of the Microsoft 365 Defender, Purview, and Compliance portals to identify security gaps, misconfigurations, and active threats:
Review Secure Score recommendations and implement approved improvements
Monitor Exchange Online Protection (EOP), Defender for Office 365 alerts and quarantine
Audit SharePoint, OneDrive, and Teams sharing settings and external access
Policy Implementation: Design, implement, and enforce Microsoft 365 security policies across the tenant:
Conditional Access policies location-based, device compliance, and risk-based
Data Loss Prevention (DLP) policies for email, Teams, SharePoint, and endpoints
Information Protection labels and retention policies in Microsoft Purview
Anti-phishing, anti-spam, safe links, and safe attachments policies in Defender
Policy Review: Perform scheduled reviews of all active M365 security policies to ensure continued effectiveness:
Review and update Conditional Access, DLP, and MFA policies quarterly
Identify redundant or conflicting policies and propose rationalization
Document policy change history and maintain an approval audit trail
M365 Documentation: Prepare and maintain comprehensive security documentation for M365 configurations:
Maintain a current M365 security configuration baseline document
Document all policy implementations with rationale, scope, and exceptions
Keep runbooks and SOPs updated for common M365 security tasks
Security Suggestions: Provide proactive security recommendations to improve the M365 security posture:
Analyze Secure Score trends and present improvement roadmaps to management
Research and propose adoption of new security features (e.g., Copilot for Security, SSPM tools)
Benchmark tenant configuration against CIS M365 benchmarks and industry best practices
Azure AD Governance: Monitor and manage Azure AD / Entra ID configurations:
Enforce MFA, SSPR, and Privileged Identity Management (PIM)
Review Guest user access, enterprise app permissions, and OAuth consent grants
Conduct periodic User and Admin access reviews, action findings within SLA
Alert Monitoring: Monitor and triage alerts from SIEM, EDR, DLP, MDM, and M365 Defender portals daily
Incident Response: Perform initial investigation, containment, and documentation for security incidents:
Follow defined incident response playbooks for phishing, malware, data leakage, and unauthorized access
Escalate confirmed incidents with a detailed timeline and impact assessment
Vulnerability Management: Conduct regular vulnerability scans, validate findings, and track remediation with IT and engineering teams
Threat Hunting: Perform threat hunting activities and proactively identify indicators of compromise (IOCs)
Enforce MFA, RBAC, and least privilege access principles across all platforms
Conduct periodic access reviews and certifications; remediate access anomalies
Support user onboarding and offboarding to ensure secure provisioning and deprovisioning
Manage privileged accounts and admin access with appropriate oversight and logging
Prepare audit-ready evidence packages for ISO 27001, SOC 2 Type II, and internal audits
Maintain and regularly update security SOPs, configuration baselines, and policy repositories
Support risk assessments and vendor security reviews; document findings and track remediation
Participate in security awareness programs and organization-wide risk mitigation initiatives
Job Location: Gurgaon
We foster a high-ownership, performance-driven culture where teams are encouraged to think creatively, act responsibly, and deliver measurable outcomes. Our values guide how we collaborate, make decisions, and build long-term partnerships.
Website: https://www.customerinsights.ai/
LinkedIn: https://www.linkedin.com/company/customer-insights-ai/