06 Aug
|
ComplianceQuest
|
Noida
06 Aug
ComplianceQuest
Noida
Role Overview
We are seeking a Senior / Lead Specialist Enterprise Information Security Operations to lead and continuously strengthen the security, governance, and operational resilience of enterprise IT, identity, cloud, and business application platforms. This is a hands-on leadership role spanning security engineering, SecOps/IR, enterprise application management, IAM/PAM operations, IT policies processes and compliance , ensuring business continuity, a strong security posture, and audit readiness across the organization.
The role requires demonstrated experience across Microsoft 365, Azure/Entra ID, enterprise SaaS applications, IAM/PAM, cloud security, ITSM (ITIL) processes, and regulatory compliance (e.g., ISO 27001, SOC 2, privacy laws ). You will work cross-functionally with Product, Engineering, Sales Marketing, Legal, Compliance etc. and executive stakeholders to translate risk into actionable controls and measurable outcomes.
Key Responsibilities
1. Enterprise Information Security Operations Governance
- Lead enterprise-wide security operations and governance across cloud, identity, endpoints, email, networks, and enterprise applications.
- Design, implement, and continuously improve security controls aligned to Zero Trust and Defense-in-Depth , including secure configuration standards and continuous control monitoring where applicable.
- Own the incident response (IR) lifecycle for security events, coordinating triage, investigation, containment, eradication, and root cause analysis (RCA) with internal teams, drive corrective and preventive actions.
- Own Security monitoring using SIEM/SOAR and EDR/XDR capabilities (e.g., Microsoft Defender), including alert triage, use-case tuning, and continuous improvement of detection coverage.
- Drive vulnerability and patch governance in partnership with IT and Engineering (prioritization, remediation SLAs, risk acceptance, and reporting).
- Maintain a strong security-by-design posture across IT and business application landscapes.
2. Enterprise Application Management Security
- Own security and operational oversight of enterprise SaaS and business-critical applications (e.g., ERP/Finance , CRM , HRIS , Sales Marketing tools, collaboration and analytics platforms) across departments.
- Lead application onboarding, access governance, and lifecycle management , ensuring least privilege and segregation of duties.
- Review and approve third-party integrations, OAuth permissions, APIs, and service accounts .
- Partner with application owners to ensure:
- Secure configuration baselines
- Logging,
monitoring, and audit trails
- Vendor risk and compliance alignment
3. Identity, Access Privileged Access Management (IAM/PAM)
- Participate in IAM strategy and operations across Entra ID (Azure AD) and integrated enterprise platforms, including identity lifecycle (joiner/mover/leaver) governance.
- Own RBAC models, Conditional Access , MFA , access reviews, and privileged access controls (e.g., PIM/PAM, break-glass accounts, just-in-time access) to enforce least privilege and segregation of duties.
4. Microsoft 365, Cloud Infrastructure Security
- Provide security leadership for Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive) and Azure workloads.
- Oversee:
- Email security, mail flow integrity, and threat protection
- Endpoint and device security (Intune, Defender)
- Secure DNS, web traffic, CDN, and firewall services (e.g., Cloudflare)
- Implement and govern information protection controls across Microsoft 365 (e.g., DLP and data classification/labeling) and support secure collaboration and external sharing.
- Ensure cloud resources follow secure architecture patterns, centralized logging/telemetry , and monitoring standards to support detection, forensics, and audit requirements.
5. Risk Management, Compliance Audit
- Own enterprise risk management processes covering IT, cloud, and applications.
- Lead internal and external audits including ISO 27001, SOC 2, GDPR , and customer assurance/audit requests.
- Maintain audit-ready documentation, evidence repositories, and control mappings .
- Drive remediation programs and closure of findings using KPI-driven tracking.
6. IT Operations, ITSM Process Excellence
- Partner with IT Operations teams to ensure secure and reliable service delivery across regions.
- Embed security controls into ITIL-aligned ITSM processes (Change, Incident, Problem, Access, Asset).
- Define and monitor SLAs, KPIs, and operational risk indicators .
- Drive standardization, automation, and documentation to scale enterprise operations.
Required Skills Experience
Technical Domain Expertise
- 12+ years of experience in enterprise IT security operations, cybersecurity, and governance .
- Strong hands-on experience with:
- Microsoft 365, Azure / Entra ID
- IAM/PAM , RBAC, access reviews, Conditional Access, MFA
- Enterprise SaaS and application security (SSO/SAML/OIDC, OAuth, service accounts)
- Web and edge security (WAF/CDN/DNS, TLS, secure headers; e.g., Cloudflare)
- ITSM/service governance (ITIL; change, incident, problem, access, asset)
- Security operations tooling (SIEM/SOAR), detection engineering, and incident response workflows
- Endpoint security (EDR/XDR) and device management (e.g., Defender for Endpoint, Intune)
- Information protection (DLP, data classification/labeling; CASB concepts where applicable)
- Experience with cloud and security platforms (e.g., Azure Security, Defender etc.).
Risk, Compliance Privacy
- Proven experience delivering and operating controls aligned to:
- ISO 27001, SOC 2
- GDPR, DPDP Act, privacy-by-design
- Strong audit management and evidence-handling capability.
- Creation IT policies and procedures, implementations and monitoring
Leadership Soft Skills
- Solid stakeholder management and communication skills.
- Ability to balance hands-on execution with strategic leadership .
- Ability to handle IR process till closure and manage stakeholders during the whole process.
- Excellent documentation, analytical thinking, and training delivery capability
- Willingness to participate and support a 24x7 production environment as needed.
Preferred Qualifications
- Graduate/Postgraduate degree with obtained skills in Computer Science, Information Security, or equivalent experience.
- ISO 27001 Lead Auditor / Implementer
- ITIL v4 Foundation
- Microsoft Azure certification(s) (e.g., AZ-104, AZ-500, SC-200/SC-300) or equivalent experience.
- Security certifications (preferred): CISSP, CISM, CCSP, GIAC, or relevant Microsoft Security certifications.
Success Metrics
- Stable and secure enterprise IT and application environment
- Consistent clean audit outcomes with zero repeat findings
- Reduced identity and privileged access risk
- High stakeholder confidence in security and IT operations
- Scalable, documented, and automation-driven governance processes
- IT policies and procedures creation and implementation
- Internal IT audits and continuous improvements
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Lead Specialist - IT (Noida)
🏢 ComplianceQuest
📍 Noida