07 Aug
|
Extreme Networks
|
Bengaluru
07 Aug
Extreme Networks
Bengaluru
We are seeking a skilled Security & Compliance Engineer to implement and maintain security controls aligned with ISO 27001, SOC 2, and NIST 800-53. The role involves ensuring compliance readiness, integrating security into development lifecycles, and supporting audit activities while securing cloud-native and containerized environments.
Key Responsibilities:
- Follow established processes for the implementation and maintenance of security controls aligned with ISO 27001, SOC 2, and NIST 800-53.
- Collaborate with security leadership to ensure adherence to controls and procedures.
- Support internal and external audits by providing evidence, documentation, and remediation tracking.
- Develop and maintain automated security and compliance monitoring tools and dashboards.
- Translate regulatory requirements into technical requirements and integrate them into the Secure Development Lifecycle (SDLC).
- Conduct gap assessments and risk analysis, define remediation plans, and track completion.
- Apply hands-on expertise in Kubernetes security, including RBAC, pod security policies, network policies, and secrets management.
- Implement secure configurations and governance controls in cloud-native environments (AWS, Azure, or GCP).
- Integrate security controls into CI/CD pipelines using tools like GitLab CI, Jenkins, or GitHub Actions.
- Ensure proper access management, encryption, logging/monitoring, and network security.
Required Qualifications:
- 8+ years of experience in information security or compliance engineering roles.
- Solid understanding and practical experience with ISO 27001, SOC 2 (Type I and II), and NIST SP 800-53.
- Hands-on experience with DevOps security practices and secure CI/CD pipelines.
- Familiarity with cloud-native security, container orchestration, and infrastructure-as-code tools (Terraform, Helm, Ansible).
- Solid knowledge of access management, encryption, logging/monitoring, and network security principles.
- Demonstrated ability to lead technical initiatives and influence cross-functional teams.
Skills: CI/CD Security Integration, Cloud Security (AWS/Azure/GCP), Compliance Frameworks (ISO 27001/SOC 2/NIST 800-53), Infrastructure-as-Code Security (Terraform/Helm/Ansible), Kubernetes Security, Risk Assessment & Remediation
Experience: 8.00-14.00 Years
📌 DevSecOps- AWS/AZURE- Terraform/Ansible- CI/CD (Bengaluru)
🏢 Extreme Networks
📍 Bengaluru