Sr IT Engineer - Security
Experience: 7-12 Years
Location: Gurugram
Employment Type: Full-Time, Permanent
Department: IT & Information Security
Role Category: IT Security
Job Summary
We are looking for a Senior IT Security Engineer with strong experience in Cybersecurity, Security Compliance, Security Assurance, Technology Risk, and Security Control Assessments.
Key Responsibilities
- Assess technical cybersecurity controls, policies, procedures, and audit evidence.
- Conduct assessments against Cyber Essentials Plus, CIS Controls, NIST CSF, and NIST SP 800-series.
- Evaluate controls across IAM/PAM, MFA, endpoint, network, cloud, vulnerability, patching, logging, and encryption.
- Review security configurations, vulnerability reports, dashboards, architecture diagrams, and access-control evidence.
- Perform gap, risk, control maturity, and certification-readiness assessments.
- Track security remediation activities and control deficiencies.
- Work with SOC, IAM, Network, Cloud, Infrastructure, Endpoint, and Security Engineering teams.
- Translate technical security gaps into business risks and actionable remediation plans.
- Support security compliance frameworks such as ISO 27001, PCI DSS, TISAX, SOC 2, and SOX.
- Contribute to process improvements, research, documentation, and continuous improvement.
Mandatory Skills
- Cybersecurity / Security Assurance
- Cybersecurity Compliance
- Security Control Assessment
- Technology Risk & Risk Assessment
- NIST CSF / NIST SP 800
- CIS Controls
- Cyber Essentials Plus
- Vulnerability & Patch Management
- IAM / PAM / MFA
- Endpoint & Network Security
- Cloud Security
- Logging & Monitoring
- Incident Response
- Encryption & Secure Configuration
- Security Gap & Maturity Assessments
Preferred Skills
- ISO 27001
- PCI DSS
- TISAX
- SOC 2
- SOX
- CISSP / CISM / CRISC / Security+
- ISO 27001 Lead Auditor / Implementer
Candidate Profile
- 7+ years of relevant experience in cybersecurity, security compliance, assurance, technology risk, or security control assessment.
- Strong ability to review technical evidence and assess control effectiveness.
- Excellent communication and presentation skills.
- Ability to work independently, research new security requirements, and manage tight timelines.
- Strong understanding of IT and business control implementation and assessment.
Education
UG/PG: Degree in IT, Business Informatics, Computer Science, or a related field.