Information Security Spec II

Jobgether SRL

India

Remote

INR 1,800,000 - 3,200,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Remote work in India
Annual health checkup
Marriage and paternity leave
Employee Assistance Programme
Learning and development opportunities
Global security exposure
Equal opportunity workplace

Job summary

Jobgether SRL is seeking an Information Security Spec II based in India to lead the enterprise Data Loss Prevention program, strengthen cloud security in AWS/Azure, and act as a senior escalation point for High and Critical incidents outside US hours. You will collaborate with Legal, IT, and MSSP partners to reduce risk and implement scalable security controls.

The role combines hands-on security engineering with incident leadership, automation, and compliance work across a global environment,

Qualifications

  • 8+ years in information security with ownership of enterprise programs.
  • Bachelor's degree in Information Security, CS or related field; advanced degree a plus.
  • Deep hands-on experience owning an enterprise DLP program with policy authoring and labeling.
  • Strong Azure cloud security expertise (Defender for Cloud, Entra ID, Azure Policy).
  • Experience with AWS security and cloud security assessments.
  • Proven L2/L3 incident response ownership of High and Critical incidents.
  • Ability to create/maintain SOPs, runbooks, automation playbooks, and security docs.
  • Knowledge of ISO 27001, GDPR, data privacy requirements.
  • Auditing/compliance support experience.
  • Strong written/verbal communication for stakeholders and executives.

Responsibilities

  • Own the enterprise DLP program end to end, including policy design and deployment with Legal and data owners.
  • Define and enforce protection controls for high-risk assets in line with regulatory requirements.
  • Maintain an inventory of protected data with Legal and data owners.
  • Assess Azure and AWS for risks and drive remediation of findings.
  • Support Azure security initiatives including identity hardening and Graph API automation.
  • Lead security incidents during non-US hours with defined SLAs and MSSP collaboration.
  • Coordinate with managed detection/response providers and third-party security operations.
  • Develop SOPs, runbooks, automation playbooks, and improve L2/L3 security support.
  • Monitor logs and cloud infrastructure for threats; coordinate investigations.
  • Review security configurations (firewalls, IDS, encryption, security groups).
  • Suggest remediation for vulnerabilities in networks and cloud environments.
  • Align security operations with ISO 27001 and privacy regulations; support audits/regulatory requests.
  • Prepare security reports, KPIs, and management metrics.
  • Contribute to security projects and broaden expertise across IT/security domains.

Skills

DLP ownership
Azure security
Cloud security
Incident response
Automation
PowerShell/Python
ISO 27001/GDPR
Security monitoring
Audit support
MSSP collaboration

Education

Bachelor's in Info Sec or CS

Tools

Purview DLP
Microsoft Graph API
Azure Defender
Azure Policy
AWS security
PowerShell
Python

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information Security Spec II based in India.

This is a high-impact information security role focused on protecting enterprise data, cloud environments, and critical business systems. You will own the enterprise Data Loss Prevention program while strengthening security across AWS and Azure environments. The role also serves as a senior escalation point for High and Critical security incidents during non-US hours. You will work closely with Legal, IT infrastructure, application teams, business stakeholders, and managed security providers to reduce risk and strengthen the organization's security posture. The position combines hands-on technical security engineering with incident leadership, automation, compliance, and operational improvement. It is an opportunity to influence enterprise security strategy while building scalable processes, controls, and capabilities across a global environment.

  • Own the enterprise Data Loss Prevention program end to end, including policy design, tuning, exception management, new functionality, and deployment in partnership with Legal and data owners.

  • Define and enforce protection controls for high-risk company assets, ensuring DLP policies align with legal, regulatory, privacy, and business requirements.

  • Maintain and periodically review an inventory of protected assets and sensitive data in collaboration with Legal and relevant data owners.

  • Assess Azure and AWS environments for security risks and drive remediation of identified findings, with a focus on reducing High and Critical cloud vulnerabilities.

  • Support Azure security engineering initiatives, including secure configuration, identity and workload hardening, Microsoft Graph API automation, and security control improvements.

  • Serve as the primary security escalation contact during non-US hours for High and Critical alerts, taking ownership of complex incidents from detection through documented closure within defined SLAs.

  • Partner with managed detection and response providers and act as an integration owner and backup point of contact for third-party security operations.

  • Strengthen L2 security support through standardized SOPs, expert guidance, structured escalation processes, automation, and SOAR playbooks that enable more issues to be resolved at the L2 level.

  • Monitor security logs and cloud infrastructure for potential threats, vulnerabilities, and anomalous activity, coordinating investigation and remediation as needed.

  • Review and audit security configurations, including firewalls, intrusion detection systems, encryption technologies, security groups, and cloud security controls.

  • Assess networks and cloud environments for vulnerabilities and recommend practical remediation strategies.

  • Ensure information security operations remain aligned with ISO 27001, data privacy regulations, customer commitments, and other applicable requirements.

  • Support internal and external audits, regulatory requests, FedRAMP activities, and Legal inquiries.

  • Prepare security reports, technical presentations, KPIs, and operational metrics to support management decision-making.

  • Contribute to special security projects and develop broader T-shaped expertise across key information security and IT domains.

Requirements
  • 8+ years of relevant information security experience, including hands‑on ownership of enterprise security programs.

  • Bachelor's degree in Information Security, Computer Science, or a related discipline, or equivalent professional experience. An advanced degree is a plus.

  • Deep hands‑on experience owning an enterprise DLP program, including policy authoring, tuning, exception management, data classification, and sensitivity labeling. Experience with Microsoft Purview DLP and Information Protection is preferred.

  • Strong Azure cloud security expertise, including experience with Defender for Cloud, Entra ID, Azure Policy, network security, workload protection, security assessments, and remediation at scale.

  • Experience with AWS security is an advantage, particularly in cloud security assessment, configuration, and remediation.

  • Proven L2/L3 incident response experience, including ownership of High and Critical security incidents through resolution in collaboration with an MSSP or 24/7 SOC.

  • Strong ability to create and maintain SOPs, incident runbooks, automation playbooks, and security documentation.

  • Working knowledge of Microsoft Graph API and scripting or automation using PowerShell, Python, or comparable technologies.

  • Strong understanding of information security and data privacy frameworks and regulations, including ISO 27001, GDPR, and related requirements.

  • Experience supporting internal or external security audits and compliance activities.

  • Strong knowledge of security monitoring, vulnerability assessment, cloud security controls, incident investigation, and production security operations.

  • Professional certifications such as CISSP, CCSP, AZ-500, SC-400, GCIH, or equivalent are preferred.

  • Excellent written and verbal communication skills, with the ability to explain security risks, technical trade‑offs, and remediation priorities to Legal, business stakeholders, executives, and technical teams.

  • Strong judgment, ownership, analytical thinking, and ability to make effective decisions during high‑severity security incidents.

  • Comfortable working collaboratively with global IT teams, application teams, business users, and external security service providers.

  • Willingness and ability to provide security escalation coverage during non-US hours for global High and Critical incidents.

Benefits
  • Remote work opportunity based in India.

  • Competitive total rewards package designed to support employee health, financial wellbeing, and professional development.

  • Competitive insurance plans covering employees and immediate family members.

  • Annual health checkup.

  • Marriage leave and paternity leave.

  • Employee Assistance Programme.

  • Extensive learning and development opportunities.

  • Opportunity to work on enterprise‑scale information security, cloud security, and data protection initiatives.

  • Exposure to global security operations, compliance programs, and modern cloud technologies.

  • Collaborative international environment with opportunities to develop broad technical and cross‑functional expertise.

  • Equal opportunity workplace welcoming candidates from diverse backgrounds.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Engineer, Information Security
Lead Engineer, Information Security

Lever, Inc. • India

Remote
INR 1,500,000 - 2,200,000
Fully remote within India
Senior technical ownership
Exposure to enterprise SIEM/EDR/cloud
+3
Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • India

On-site
INR 3,500,000 - 5,500,000
Remote-first environment
In-person team sprints abroad
Learning budget USD 2,000 (annual)
Senior Information Security Engineer (DevSecOps)
Senior Information Security Engineer (DevSecOps)

WLEN WorldJobs LLP • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Principal Engineer- Information security
Principal Engineer- Information security

Acuity Analytics • Pune District, Gurugram District, Bengaluru

On-site
INR 1,800,000 - 2,600,000
Principal Engineer- Info Sec
Principal Engineer- Info Sec

Acuity Analytics • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Information Security Engineer
Information Security Engineer

Customerinsights.ai • Gurugram District

On-site
INR 1,200,000 - 1,800,000
IT Security Team Lead
IT Security Team Lead

Creative Capsule • Goa

On-site
INR 2,500,000 - 4,500,000
DLP Analyst - Information Security
DLP Analyst - Information Security

Go Digit General Insurance Limited • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Manager - Governance and Compliance (Contractor)
Manager - Governance and Compliance (Contractor)

Lever, Inc. • India

Remote
INR 3,000,000 - 5,000,000
Remote work from anywhere in India
Global exposure and cross-region work
Leadership role with strategic impact
+1
IT Security Team Lead
IT Security Team Lead

Creative Capsule • India

On-site
INR 2,500,000 - 5,200,000