Lead Specialist - IT

ComplianceQuest

Dadri

On-site

INR 2,500,000 - 4,200,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ComplianceQuest is seeking a Senior / Lead Specialist – Enterprise Information Security & Operations in India to lead security, governance, and operational resilience of enterprise IT, identity, cloud, and business applications. This hands-on leadership role spans security engineering, SecOps/IR, IAM/PAM operations, and IT policies, ensuring audit readiness and strong risk controls.

You will work with cross-functional teams to translate risk into actionable controls, with a focus on Microsoft

Qualifications

  • 12+ years of experience in enterprise IT security operations, governance, and regulatory compliance.

Responsibilities

  • Lead enterprise security operations and governance across cloud, identity, endpoints, emails, networks and enterprise apps.
  • Drive zero-trust based security controls, secure configurations, and continuous monitoring.
  • Own incident response lifecycle including RCA and remediation actions.
  • Oversee SIEM/SOAR, EDR/XDR for detection and response; tune use-cases.
  • Lead vulnerability and patch governance with IT and Engineering.
  • Ensure secure-by-design posture across IT and business apps.
  • Provide security and operational oversight for ERP/CRM/HRIS and other SaaS apps.
  • Manage IAM/PAM, RBAC, Conditional Access, MFA, and access reviews.
  • Collaborate on MS 365/Azure security, DLP, data classification, external sharing.
  • Support ITSM/ITIL processes and audit readiness; align with ISO27001/SOC2/GDPR compliance.

Skills

Enterprise IT security
Security governance
Threat detection
IAM/PAM
RBAC & Access Reviews
Cloud security
Microsoft 365/Azure
Defender/EDR/XDR
ITIL processes
Vulnerability management

Tools

SIEM/SOAR
EDR/XDR tooling
Defender for Endpoint
Cloudflare

Job description

Job Description:
Role Overview

We are seeking a Senior / Lead Specialist – Enterprise Information Security & Operations to lead and continuously strengthen the security, governance, and operational resilience of enterprise IT, identity, cloud, and business application platforms. This is a hands‑on leadership role spanning security engineering, SecOps/IR, enterprise application management, IAM/PAM operations, IT policies & processes and compliance, ensuring business continuity, a strong security posture, and audit readiness across the organization.

The role requires demonstrated experience across Microsoft 365, Azure/Entra ID, enterprise SaaS applications, IAM/PAM, cloud security, ITSM (ITIL) processes, and regulatory compliance (e.g., ISO 27001, SOC 2, privacy laws). You will work cross‑functionally with Product, Engineering, Sales & Marketing, Legal, Compliance etc. and executive stakeholders to translate risk into actionable controls and measurable outcomes.

Key Responsibilities
1. Enterprise Information Security Operations & Governance
  • Lead enterprise‑wide security operations and governance across cloud, identity, endpoints, email, networks, and enterprise applications.

  • Design, implement, and continuously improve security controls aligned to Zero Trust and Defense‑in‑Depth, including secure configuration standards and continuous control monitoring where applicable.

  • Own the incident response (IR) lifecycle for security events, coordinating triage, investigation, containment, eradication, and root cause analysis (RCA) with internal teams, drive corrective and preventive actions.

  • Own Security monitoring using SIEM/SOAR and EDR/XDR capabilities (e.g., Microsoft Defender), including alert triage, use‑case tuning, and continuous improvement of detection coverage.

  • Drive vulnerability and patch governance in partnership with IT and Engineering (prioritization, remediation SLAs, risk acceptance, and reporting).

  • Maintain a strong security‑by‑design posture across IT and business application landscapes.

2. Enterprise Application Management & Security
  • Own security and operational oversight of enterprise SaaS and business‑critical applications (e.g., ERP/Finance, CRM, HRIS, Sales & Marketing tools, collaboration and analytics platforms) across departments.

  • Lead application onboarding, access governance, and lifecycle management, ensuring least privilege and segregation of duties.

  • Review and approve third‑party integrations, OAuth permissions, APIs, and service accounts.

  • Partner with application owners to ensure:

    • Secure configuration baselines

    • Logging, monitoring, and audit trails

    • Vendor risk and compliance alignment

3. Identity, Access & Privileged Access Management (IAM/PAM)
  • Participate in IAM strategy and operations across Entra ID (Azure AD) and integrated enterprise platforms, including identity lifecycle (joiner/mover/leaver) governance.

  • Own RBAC models, Conditional Access, MFA, access reviews, and privileged access controls (e.g., PIM/PAM, break‑glass accounts, just‑in‑time access) to enforce least privilege and segregation of duties.

4. Microsoft 365, Cloud & Infrastructure Security
  • Provide security leadership for Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive) and Azure workloads.

  • Oversee:

    • Email security, mail flow integrity, and threat protection

    • Endpoint and device security (Intune, Defender)

    • Secure DNS, web traffic, CDN, and firewall services (e.g., Cloudflare)

  • Implement and govern information protection controls across Microsoft 365 (e.g., DLP and data classification/labeling) and support secure collaboration and external sharing.

  • Ensure cloud resources follow secure architecture patterns, centralized logging/telemetry, and monitoring standards to support detection, forensics, and audit requirements.

5. Risk Management, Compliance & Audit
  • Own enterprise risk management processes covering IT, cloud, and applications.

  • Lead internal and external audits including ISO 27001, SOC 2, GDPR, and customer assurance/audit requests.

  • Maintain audit‑ready documentation, evidence repositories, and control mappings.

  • Drive remediation programs and closure of findings using KPI‑driven tracking.

6. IT Operations, ITSM & Process Excellence
  • Partner with IT Operations teams to ensure secure and reliable service delivery across regions.

  • Embed security controls into ITIL‑aligned ITSM processes (Change, Incident, Problem, Access, Asset).

  • Define and monitor SLAs, KPIs, and operational risk indicators.

  • Drive standardization, automation, and documentation to scale enterprise operations.

Required Skills & Experience
Technical & Domain Expertise
  • 12+ years of experience in enterprise IT security operations, cybersecurity, and governance.

  • Strong hands‑on experience with:

    • Microsoft 365, Azure / Entra ID

    • IAM/PAM, RBAC, access reviews, Conditional Access, MFA

    • Enterprise SaaS and application security (SSO/SAML/OIDC, OAuth, service accounts)

    • Web and edge security (WAF/CDN/DNS, TLS, secure headers; e.g., Cloudflare)

    • ITSM/service governance (ITIL; change, incident, problem, access, asset)

    • Security operations tooling (SIEM/SOAR), detection engineering, and incident response workflows

    • Endpoint security (EDR/XDR) and device management (e.g., Defender for Endpoint, Intune)

    • Information protection (DLP, data classification/labeling; CASB concepts where applicable)

  • Experience with cloud and security platforms (e.g., Azure Security, Defender etc.).

Risk, Compliance & Privacy
  • Proven experience delivering and operating controls aligned to:

    • ISO 27001, SOC 2

    • GDPR, DPDP Act, privacy‑by‑design

  • Strong audit management and evidence‑handling capability.

  • Creation IT policies and procedures, implementations and monitoring

Leadership & Soft Skills
  • Strong stakeholder management and communication skills.

  • Ability to balance hands‑on execution with strategic leadership.

  • Ability to handle IR process till closure and manage stakeholders during the whole process.

  • Excellent documentation, analytical thinking, and training delivery capability

  • Willingness to participate and support a 24x7 production environment as needed.

Preferred Qualifications
  • Graduate/Postgraduate degree with obtained skills in Computer Science, Information Security, or equivalent experience.

  • ISO 27001 Lead Auditor / Implementer

  • ITIL v4 Foundation

  • Microsoft Azure certification(s) (e.g., AZ‑104, AZ‑500, SC‑200/SC‑300) or equivalent experience.

  • Security certifications (preferred): CISSP, CISM, CCSP, GIAC, or relevant Microsoft Security certifications.

Success Metrics
  • Stable and secure enterprise IT and application environment

  • Consistent clean audit outcomes with zero repeat findings

  • Reduced identity and privileged access risk

  • High stakeholder confidence in security and IT operations

  • Scalable, documented, and automation‑driven governance processes

  • IT policies and procedures creation and implementation

  • Internal IT audits and continuous improvements

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager – IT Operations
Manager – IT Operations

PPFAS Mutual Fund • Mumbai

On-site
INR 2,500,000 - 4,000,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Neurealm • Chennai District

On-site
INR 2,800,000 - 6,000,000
IT Security & Compliance Engineer
IT Security & Compliance Engineer

Rapyuta Robotics • Chennai District

On-site
INR 1,200,000 - 2,200,000
Competitive salary
Great team culture
System Administrator
System Administrator

AiVantage Inc (Global) • Ahmedabad District

On-site
INR 1,400,000 - 2,100,000
Cloud, DevOps & Information Security Lead
Cloud, DevOps & Information Security Lead

Greytip Software Private Limited • Bengaluru

On-site
INR 2,500,000 - 3,500,000
System Administrator
System Administrator

Aivantage Global • Ahmedabad District

On-site
INR 1,200,000 - 1,800,000
Principal Engineer- Info Sec
Principal Engineer- Info Sec

Acuity Analytics • Maharashtra

On-site
INR 1,500,000 - 2,100,000
System Administrator
System Administrator

AiVantage • Ahmedabad District

On-site
INR 600,000 - 1,200,000
Cloud and Infrastructure Operations- IT
Cloud and Infrastructure Operations- IT

Siemens • Gurugram District

On-site
INR 3,510,000 - 6,000,000
Principal Engineer- Information security
Principal Engineer- Information security

Acuity Analytics • Pune District, Gurugram District, Bengaluru

On-site
INR 1,800,000 - 2,600,000