Principal Engineer- Information security

Acuity Analytics

Pune District, Gurugram District, Bengaluru

On-site

INR 1,800,000 - 2,600,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Acuity Analytics, the trading name of Acuity Knowledge Partners, seeks an Information Security Specialist (Principal Engineer) in Pune/Bengaluru. You will perform hands-on cloud security assessments, architecture reviews and risk evaluations for engagements in financial services and corporate clients.

The role requires 5–7 years in information security with strong DLP, IAM, and cloud security experience. ISO 27001, SOC 2, CIS, CSA, NIST knowledge and collaboration with delivery teams are

Qualifications

  • Bachelor degree in Engineering, Computer Science, Information Security or equivalent.
  • 6-7 years of experience in information security and cloud security.
  • Preferred certifications: CCSP, AWS Security Specialty, Azure Security Engineer, CISSP, CISM, CISA, ISO 27001 LA/LI, or equivalent practical cloud/security certification.
  • Experience in professional services, IT outsourcing, financial services, or client delivery environments is preferred.

Responsibilities

  • Review cloud deployments for secure configuration, identity and access.
  • Assess architecture changes from security and risk perspectives.
  • Review IAM, privileged access and secrets management.
  • Map findings to ISO 27001, SOC 2, CIS, CSA, NIST and internal security policies.
  • Track remediation actions and drive closure with project owners and IT operations.

Skills

Cloud security
DLP implementation
SOC monitoring
ISO 27001 alignment
Stakeholder coordination

Education

Bachelor degree in Engineering, Computer Science, Information Security

Tools

Azure
AWS
Microsoft 365
SIEM

Job description

Job description

Acuity Analytics (the trading name of Acuity Knowledge Partners) is a global, tech-first organisation helping financial institutions and corporates make better decisions through research, data, analytics and AI-enabled solutions. We combine deep financial services expertise with strong engineering, digital and AI capabilities to solve complex, real-world problems.

With a team of 7,200+ analysts, data specialists and technologists across 28 locations, we work with more than 800 organisations worldwide to drive efficiency, unlock insight and deliver measurable impact. Our success is built on the strength of our peopleby investing in talent, encouraging collaboration and creating room to grow, we enable our teams to do their best work for clients.

Acuity became an independent business in 2019 following its acquisition from Moodys Corporation by Equistone Partners Europe. In 2023, funds advised by global private equity firm Permira acquired a majority stake, with Equistone remaining a minority investorsupporting our continued growth and innovation.

For more information, visit www.acuityanalytics.com


Position Title-Information Security Specialist (Principal Engineer)


Experience Level-5-7 years

Department-Information Security


Location-Pune/Bengaluru


Job purpose
  • Perform hands-on cloud security assessments, security architecture reviews and technical risk evaluations for projects assigned to Information Security.
  • Support DLP implementation, policy refinement, incident review, exception handling and operational improvement of data protection controls.
  • Translate ISO 27001, SOC 2, CIS, CSA, NIST and internal security policy expectations into practical technical controls and project-level recommendations.
  • Act as a pragmatic technical risk evaluator who can identify material security risks, propose compensating controls and track remediation to closure.
Role Design and Expected Capability Mix
Capability Area

Primary Expectations

Indicative Weight
Technical Security

Cloud security assessment, secure architecture review, DLP implementation and tuning, Microsoft 365 / SaaS controls, IAM, logging, monitoring, vulnerability and configuration review.-70%

Standards and Process Alignment

Map findings and recommendations to ISO 27001, SOC 2, CIS, CSA, NIST, client requirements and internal security policies.-20%

Stakeholder Execution

Coordinate with project, IT, delivery and compliance teams to validate risks, agree action plans, support exceptions and drive closure.-10%

Key responsibilities
A. Cloud Security Assessment and Architecture Review
  • Review cloud and SaaS deployments across Azure, AWS, Microsoft 365 and other business platforms for secure configuration, identity, access, monitoring, logging, encryption, network segmentation and data protection controls.
  • Assess project architecture, application onboarding requests, infrastructure changes and cloud service usage from security, privacy, client contractual and operational risk perspectives.
  • Recommend pragmatic remediation actions, compensating controls and secure design improvements that can be implemented by engineering, IT operations or delivery teams.
  • Review IAM, privileged access, service accounts, conditional access, secrets handling, key management, storage security, backup, resilience and security baseline adherence.
  • Review and audit Security Operations Centre monitoring practices, including log-source coverage, detection use cases, alert logic, alert thresholds, triage procedures, escalation paths, incident hand-offs, evidence retention and closure tracking.
  • Assess Web Application Firewall controls and network firewall rules, including business justification, least-privilege alignment, exposed services, source and destination restrictions, ports and protocols, logging, alerting, periodic recertification, exceptions, and removal of obsolete or overly permissive rules.
  • Validate that relevant cloud, application, WAF, firewall, identity, endpoint and data-protection events are integrated with SOC monitoring and escalated in line with incident-management, risk and client requirements.
  • Review SOC performance and control effectiveness through sampling of alerts and incidents, detection coverage, response timelines, escalation quality, root-cause analysis, remediation evidence and closure records.
  • Support secure cloud governance by tracking deviations, exceptions, control gaps and remediation status across assigned engagements.
B. DLP Implementation, Refinement and Operations
  • Support implementation, refinement and day-to-day management of DLP policies across email, endpoint, cloud storage, SaaS platforms and collaboration tools as applicable.
  • Review DLP alerts, violations and policy matches to identify true risks, false positives, noisy rules and opportunities for policy tuning.
  • Work with business, delivery and technology teams to refine DLP rules, sensitivity labels, data handling controls and exception handling practices.
  • Document DLP risk decisions, recurring patterns, policy exceptions, false-positive rationale and corrective actions in the approved tracker or system of record.
  • Contribute to awareness and adoption by converting DLP observations into practical guidance for users and project teams.
C. Technical Risk Review and Policy Exception Management
  • Serve as the Information Security reviewer for assigned project engagements, technical change reviews, production onboarding, client delivery initiatives and risk assessments.
  • Evaluate security risks pragmatically by considering likelihood, impact, data sensitivity, client exposure, compensating controls, operational feasibility and implementation timelines.
  • Manage policy exceptions by validating business justification, risk exposure, compensating controls, expiry dates, accountable owner, approval status and periodic review requirements.
  • Track remediation actions and exception closure with project owners, IT operations, delivery teams and control owners.
  • Escalate material, repeated or unmanaged risks with clear facts, business impact and recommended decision options.
D. Standards, Controls and Audit Alignment
  • Map technical control observations to relevant security standards, client commitments and internal policies, including ISO 27001, SOC 2, CIS controls, CSA CCM, NIST CSF and cloud security benchmarks.
  • Prepare concise evidence, control narratives and remediation updates to support audits, client security reviews and internal compliance checks.
  • Support maintenance of cloud security standards, DLP standards, data handling procedures, exception processes and technical security guidelines.
  • Contribute to control testing by validating whether security controls are implemented, operating and evidenced in a manner suitable for audit and risk review.
Key competencies
Required Qualifications and Certifications
  • Bachelor degree in Engineering, Computer Science, Information Security, Information Technology or equivalent practical experience.
  • 6-7 years of experience in information security, cloud security, security operations, security architecture review, DLP, technical risk assessment or related roles.
  • Preferred certifications: CCSP, AWS Security Specialty, Azure Security Engineer, CISSP, CISM, CISA, ISO 27001 LA / LI, or equivalent practical cloud / security certification.
  • Experience in professional services, IT outsourcing, financial services, KPO/BPO or client delivery environments is preferred.
Functional Competencies
  • Hands-on working knowledge of Azure, AWS, Microsoft 365 and SaaS security controls, including IAM, MFA, SSO, conditional access, logging, monitoring, encryption, endpoint controls, DLP and secure configuration management.
  • Ability to review project architecture and cloud designs for security risks, control gaps, data exposure, access weaknesses and operational vulnerabilities.
  • Working knowledge of DLP technologies and operations, including rule tuning, event triage, false-positive reduction, exception review and data classification alignment.
  • Good understanding of vulnerability management, cloud posture management, SIEM/logging, CASB/SSE concepts, endpoint security, secure SDLC touchpoints and incident triage.
  • Practical capability to review SOC monitoring effectiveness, SIEM detection coverage, alert quality and incident escalation, and to audit WAF and firewall rules against approved architecture, least-privilege principles, security standards and internal policies.
  • Ability to align technical findings with ISO 27001, SOC 2, CIS, CSA, NIST and internal information security policy requirements.
  • Strong documentation skills for risk assessments, exception notes, remediation plans, control evidence, DLP decisions and security review outcomes.
  • Practical judgement to separate material risks from low-value findings and recommend controls that are effective, auditable and feasible for business adoption.
Behavioral Competencies
  • Hands-on, self-driven and comfortable taking ownership of assigned technical security reviews.
  • Strong follow-through with project teams to drive remediation, evidence collection and closure.
  • Clear communicator who can explain technical risks in business terms without overstating or minimizing the issue.
  • Collaborative working style with IT, engineering, delivery, procurement, compliance and client-facing teams.
  • Ability to work in an unstructured environment, prioritize competing requests and make risk-based recommendations.
  • Continuous learner with interest in cloud security, DLP, data protection, AI-enabled security tooling and practical control automation.
Success Measures for the Role
  • Assigned cloud and project security reviews are completed with clear findings, risk ratings, recommendations and closure tracking.
  • DLP policies and alerts are progressively tuned to reduce noise while improving visibility of genuine data protection risks.
  • SOC monitoring coverage, SIEM alerting, WAF controls and firewall rules are periodically reviewed, with material gaps documented, risk-assessed and tracked to closure.
  • Policy exceptions are documented with business rationale, compensating controls, expiry dates and accountable owners.
  • Technical risks are mapped to applicable standards and internal policies in a manner that supports audit readiness.
  • Business and project teams receive pragmatic security guidance that improves control adoption without unnecessary delay.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer- Info Sec
Principal Engineer- Info Sec

Acuity Analytics • Pune District

On-site
INR 2,600,000 - 3,800,000
Infrastructure Security Officer
Infrastructure Security Officer

Thompsons HR Consulting Pvt Ltd • Pune District

Hybrid
INR 1,200,000 - 1,800,000
Information Technology-Security
Information Technology-Security

Yokohama-ATG • Mumbai

On-site
INR 3,500,000 - 6,000,000
P1-GP-Bharati-Information Security Engineer (Generalist – AI & Automation Focus)
P1-GP-Bharati-Information Security Engineer (Generalist – AI & Automation Focus)

atlas group • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Manager - Information Security
Manager - Information Security

DS Group • Dadri

On-site
INR 2,800,000 - 5,400,000
P1-GP-Bharati-Information Security Engineer (Generalist – AI & Automation Focus)
P1-GP-Bharati-Information Security Engineer (Generalist – AI & Automation Focus)

Atlas Systems • Bengaluru

Hybrid
INR 1,800,000 - 3,000,000
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
Security Analyst / Security Engineer
Security Analyst / Security Engineer

Kotak Investment Advisors • Mumbai

On-site
INR 3,500,000 - 6,000,000
Staff Security Architect
Staff Security Architect

KFC Corporation • Gurgaon

Hybrid
INR 1,800,000 - 2,500,000
Cloud, DevOps & Information Security Lead
Cloud, DevOps & Information Security Lead

Greytip Software Private Limited • Bengaluru

On-site
INR 2,500,000 - 3,500,000