Role & responsibilities
1. Data Loss Prevention (DLP)
- Own the end-to-end DLP strategy across all channels endpoint, email, web, cloud storage, and removable media
- Manage Sophos DLP policies in blocking mode define content rules, sensitive data patterns (PII, PCI, PHI, IP), and policy exceptions
- Administer Google Workspace DLP rules: Gmail, Drive, Meet, and Chat detect and block exfiltration of classified data
- Configure and maintain USB and removable media blocking policies via Sophos Endpoint Protection
- Establish DLP incident workflows: alert triage, investigation, user notification, and management reporting
- Tune DLP policies to minimise false positives while maintaining blocking effectiveness document tuning rationale
- Conduct quarterly DLP policy reviews aligned with data classification updates and audit findings
- Produce monthly DLP incident summary reports for the DPO and IT Lead
1. Firewall & Switch Security
- Own Sophos XGS Firewall configuration lifecycle security zones, NAT rules, VPN tunnels (IPSec/SSL), HA failover, and firmware updates
- Administer managed network switches: VLAN configuration, port security, 802.1X authentication, storm control, and spanning tree hardening
- Implement and enforce network segmentation: DMZ, inter-VLAN routing controls, Guest VLAN isolation, and zero-trust perimeter principles
- Manage IDS/IPS rules within Sophos NGFW — tune signatures, review alerts, and document suppression decisions
- Conduct periodic firewall rule audits — identify stale, overly permissive, or shadow rules and produce a cleanup remediation log
- Enforce switch port security: disable unused ports, restrict MAC address counts, and apply BPDU guard on access ports
- Manage dual internet links (Airtel + Teleglobal) — failover logic, bandwidth policy, and traffic prioritisation
- Evaluate and implement Network Access Control (NAC) to control which devices can join the corporate network — currently an identified gap
- Maintain documented network topology diagrams, change logs, and baseline configuration backups for all firewall and switch devices
1. Data Security & Data Management
- Own the information classification scheme — define and maintain data tiers (Public, Internal, Confidential, Restricted) aligned to ISO 27001
- Ensure all data stores (Google Drive, email, AWS S3, Freshservice, endpoint local storage) are classified, labelled, and handled per policy
- Enforce data retention and disposal policies — define retention periods per data type (PII, financial, operational) and verify secure disposal of media and devices
- Manage encryption posture: ensure data at rest and in transit is encrypted; review Google Workspace TLS/SMIME settings, AWS S3 bucket encryption, and endpoint storage encryption
- Govern backup security — enforce authentication, encryption, and integrity verification for all backup media (email and Drive backups currently in scope)
- Assess and remediate data exposure risks: public-facing servers, shared drives with over-permissioned access, and API data flows
- Maintain a data flow map documenting where PII, PCI, and PHI is collected,
stored, processed, and transmitted — refresh annually and on material changes
- Support the DPO in responding to data subject requests, breach investigations, and regulatory notifications under GDPR and CCPA
1. Data Protection & Privacy Compliance
- Act as the technical arm of the Data Protection function — translate DPO requirements into enforceable technical controls
- Maintain and improve compliance with GDPR, CCPA, and ISO 27001 data protection obligations — document control mappings and evidence
- Conduct Data Protection Impact Assessments (DPIAs) for new systems, integrations, or data processing activities
- Oversee access control hygiene: enforce least-privilege across Google Workspace, AWS IAM, and Sophos Central — conduct quarterly access reviews
- Manage identity lifecycle for data access: provisioning, periodic recertification, and timely revocation on offboarding
- Enforce MFA across all data-access surfaces: Google Workspace, AWS console, VPN, remote admin tools — document exceptions
- Manage third-party data processor agreements (DPAs) from a technical controls perspective — verify vendor security posture annually
- Support cyber insurance questionnaire submissions — provide accurate technical responses for data protection sections
- Monitor and respond to data protection-related security alerts — coordinate with the DPO on breach determination and notification timelines
1. Security Best Practices & Standards
- Define, document, and enforce Atidiv's security baseline standards — covering endpoints, network devices, cloud accounts, SaaS apps, and user accounts
- Own the patch management lifecycle: define patching cadence (critical: 72 hours, high: 7 days, medium: 30 days), track SLA compliance, and report on remediation status — currently an identified gap
- Implement CIS Benchmark hardening for endpoints (Windows/macOS), Sophos, AWS, and Google Workspace — document deviations with risk acceptance
- Enforce password and authentication standards: minimum complexity, no shared credentials, MFA everywhere, and periodic credential rotation for privileged accounts
- Govern software installation controls: enforce admin-only installation via Sophos and Google Workspace policies; maintain approved software list
- Conduct quarterly internal vulnerability scans; coordinate annual VAPT with third-party vendor — scope to include firewall, endpoints, web-facing systems, and AWS workloads
- Lead phishing simulation campaigns (GoPhish, quarterly) — design scenarios, run campaigns, analyse click rates, and drive targeted remediation training
- Maintain the Information Security Policy suite — review annually and update following audit findings, incidents,
or regulatory changes
- Perform security risk assessments for new tools, SaaS onboarding, third-party integrations, and infrastructure changes before go-live
- Develop and maintain the Incident Response Plan — including ransomware playbook, escalation paths, and post-incident review process
1. Centralised Asset Security Management
- Own the security dimension of the CMDB in Freshservice — ensure all IT assets (laptops, servers, network devices, cloud instances, SaaS apps) are inventoried with ownership, classification, patch status, and security configuration state
- Implement and manage Sophos Central as the unified security console: endpoint protection, EDR, DLP, firewall, and MDM — enforce consistent policy across all managed devices
- Define and track security health metrics per asset: patch compliance %, EDR coverage %, DLP policy coverage, MFA adoption — produce weekly dashboard for IT Lead
- Enforce Google MDM for all corporate mobile devices and BYOD enrolled devices — ensure remote wipe, screen lock, and compliance policies are active
- Manage device lifecycle from a security standpoint: imaging standards, baseline configuration at provisioning, security sign-off before decommission, and secure data wipe before hardware return or disposal
- Identify and track unmanaged or shadow IT assets — establish a rogue device detection process using Sophos network scanning and firewall DHCP logs
- Maintain asset age and risk register — flag assets approaching end-of-support (OS, firmware) and escalate for upgrade or compensating control
- Evaluate and pilot a centralised IAM/UEM platform to consolidate device security management, patch deployment, and identity governance — aligns to the org's Zero Trust roadmap
- Produce quarterly asset security posture reports — coverage gaps, non-compliant devices, decommission backlog, and risk exposure summary
Preferred candidate profile
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience)
- 7–9 years of hands-on experience in network security, information security, or a combined infrastructure + security role
- Minimum 4 years of firewall administration experience — Sophos, Fortinet, Palo Alto, or Cisco ASA
- Demonstrated hands-on experience with DLP tools in a production environment (Sophos, Symantec, Forcepoint, or equivalent)
- Proven experience with data classification, data protection frameworks, and privacy compliance (GDPR / CCPA)
- Experience managing network switches in a corporate environment — VLAN design, port security, 802.1X
- Demonstrated experience with centralised endpoint/asset security management platforms (Sophos Central, Intune, Jamf, or equivalent)
- Experience in audit preparation and supporting at least two compliance cycles — ISO 27001 / SOC / VAPT
- Experience working in a managed services or multi-client IT environment is a solid plus
- Familiarity with ITSM and CMDB platforms (Freshservice, ServiceNow, or similar) for asset and change management
📌 Senior Network Security Engineer (Pune)
🏢 Atidiv
📍 Pune