01 Sep
|
InterviewPanel
|
Bengaluru
01 Sep
InterviewPanel
Bengaluru
Are you looking for a career defining role where your technical expertise directly protects national infrastructure? This position lets you lead cutting-edge solutioning across quantum-safe cryptography, drone security, and space systems for high-impact clients like the DRDO and Ministry of Defense.
-1 About Company:
Globals ITES Pvt Ltd offers a rare opportunity to operate at the absolute forefront of critical defense technology, developing sovereign, quantum-safe security solutions for satellite systems, UAV platforms, and tactical RF communications. By joining their team, you'll sit right at the agile intersection of advanced cryptography, embedded systems, and offensive/defensive security, working directly on high-stakes projects for key strategic public-sector customers. Its an ideal home for a driven professional eager to solve complex national security challenges while collaborating with world-class R&D; teams in a high-growth sector.
- 2. About the role
Globals is a growing cybersecurity and technology company delivering security and compliance-automation programmes for large enterprise customers. We are building out enterprise GRC / compliance-automation platform implementations, where the real engineering challenge is not the platform itself but the enterprise environment behind it: how Active Directory, Entra ID, Intune, Defender, multi-account AWS, Azure, OCI, CyberArk and on-premises data-centre infrastructure actually work, how reliable evidence can be collected from each of them, and how that evidence maps to compliance controls under ISO/IEC 27001 and SOC 2.
Our current team understands GRC and the compliance platform well, but needs deeper enterprise infrastructure and solution-architecture strength alongside it. This role fills that gap.
IN ONE LINE
We need someone who has run enterprise IT infrastructure and has also sat across the table from auditors.
This is a customer-facing engineering role. You will work directly with senior customer SMEs across identity, endpoint, cloud, network, security and GRC, translate what you learn into integration designs and evidence mappings, and drive technical issues to closure. You are not expected to be the deepest specialist in every product you are expected to have strong infrastructure fundamentals, real depth in two or three major areas, and enough breadth to work effectively with SMEs in the rest.
3. What makes this role different
Most compliance-platform roles are filled by GRC analysts or auditors who understand controls but cannot diagnose why an integration is failing. Most infrastructure roles are filled by engineers who have never sat in an audit. This role sits in the middle, and needs both.
A concrete example of the thinking we're hiring for: an ISO control requires endpoint encryption. A strong candidate doesn't just tick a box they ask where encryption is actually enforced, which tool reports it, whether that data is reliable and continuous, whether the GRC platform can even see it, what to do if it can't, whether manual evidence is acceptable, and who owns remediation. That instinct treating a control as a technical evidence problem, not a paperwork problem is the core of the job.
— 4. Key responsibilities
- Own technical troubleshooting for compliance-platform integrations — be the person who resolves why a source system and the GRC platform disagree.
- Validate integrations properly — never treat “Connected” as “Complete.” Validation means confirming connectivity, authentication, permissions, resource discovery, asset counts, sync status, evidence availability, tests generated, test results and control mappings, end to end.
- Investigate and resolve discrepancies between source systems and the platform — e.g. the platform showing 1 cloud account instead of 32, device counts differing between endpoint management and the GRC tool, tests disappearing or changing, a test passing with no visible evidence, stale assets, or a “healthy” sync with missing evidence.
- Work directly with customer infrastructure SMEs across AD, Intune, Azure, AWS, CyberArk, network, security, GRC and server teams — understand what they explain, ask the right questions, document the architecture, identify dependencies, and translate findings into an integration design.
- Build and maintain technical architecture documentation — integration architecture, data flows, service accounts, API permissions, firewall/network dependencies, authentication, sync frequency, troubleshooting runbooks, validation steps and acceptance criteria.
- Build and maintain Test Control Evidence mappings — for each test: source system, integration, asset/resource, evidence, status, control, ISO/SOC mapping, root cause and remediation owner.
- Support compliance-automation analysis — understand that integration count, test count, automated-evidence count, automated-control count and control readiness are different metrics that must not be conflated.
- Participate in customer calls with senior SMEs and management, and work with platform-vendor technical support — raising clean, reproducible tickets (exact issue, integration, tenant context, resource/test IDs, logs, screenshots, reproduction steps, expected vs actual behaviour).
- Drive every issue to closure with a root cause, classification, owner, dependency, next action, target date, validation and closure evidence.
-5 Must have
- Enterprise infrastructure fundamentals (hands-on): Windows Server and enterprise Windows environments, Active Directory, Group Policy, DNS/DHCP concepts, certificates, TLS/SSL, firewalls, proxies, network segmentation, virtualisation (VMware and/or Hyper-V), enterprise endpoint management, server management and infrastructure troubleshooting.
- Microsoft ecosystem depth in several of: Active Directory (multiple forests/domains), Entra ID / Azure AD, Entra Connect and hybrid identity, Microsoft Intune, Microsoft Defender for Endpoint, Group Policy. You can reason about scenarios like “devices are enrolled into Intune but security settings are enforced by on-prem GPO, and the platform can't see the effective state” and work out whether it's a configuration, evidence,
integration or platform issue.
- Working cloud knowledge of AWS and Azure — for AWS ideally IAM, AWS Organizations, AssumeRole, cross-account integration, delegated administrator accounts and resource discovery (CloudFormation / StackSets and GuardDuty a plus).
- Practical compliance exposure: you've supported audits such as ISO/IEC 27001, SOC 2, PCI DSS or similar. You understand what a control is, what evidence is, technical vs procedural controls, automated vs manual evidence, control ownership, test results, exceptions, remediation, audit evidence, Statement of Applicability concepts, and why evidence must be reliable and traceable. You do not need to be a lead auditor.
- Comfort with APIs and light scripting: REST APIs, JSON, OAuth / client-credentials, API troubleshooting, logs and Postman, plus PowerShell and/or Python. You don't need to be a software developer, but you should read API docs, test endpoints, understand payloads, map fields, modify scripts and troubleshoot authentication and data issues.
- Security fundamentals: vulnerability management, endpoint protection / EDR, patch management, encryption, privileged and service accounts, MFA, asset ownership and security hardening, with basic IAM and PAM concepts.
- Strong troubleshooting, documentation and stakeholder communication — able to work independently and with senior customer SMEs.
Good to have
- Oracle Cloud Infrastructure (OCI) exposure.
- SCCM / Microsoft Configuration Manager and Microsoft Graph experience.
- Deeper AWS multi-account operations (Organizations, StackSets, delegated admin, GuardDuty at scale).
- Vulnerability-management and EDR tooling depth; security hardening and benchmark experience.
- Experience producing architecture and integration documentation for enterprise customers.
Bonus (low weight — do not screen on these)
- Hands-on experience with any GRC / compliance-automation platform — Vanta, Drata, Sprinto, Secureframe, Hyperproof, OneTrust, ServiceNow GRC, Archer, AuditBoard or similar. The platform is learnable on the job; we will train the right infrastructure engineer on it.
- CyberArk experience. Desirable but not mandatory — you should be able to work alongside a CyberArk SME and understand PVWA, REST APIs, safes, service accounts, privileged-account inventory, password rotation and session data well enough to map that information into the GRC platform.
— 6. Experience & seniority
Approximately 5–8 years in enterprise IT infrastructure and/or infrastructure security, with genuine hands-on delivery — not purely coordination or documentation. Within that, we expect real depth in two or three of the major areas above (for example AD/Entra + Windows/endpoint, or AWS/Azure + identity) and working breadth across the rest. Seniority is at the senior-engineer level: someone who can own technical investigations end to end, work unsupervised, and hold their own in front of senior customer SMEs and management.
— 7. Education & certifications
Education (preferred, not rigid): BE / BTech / BSc in Computer Science, Information Technology, Electronics or a related field. Strong practical infrastructure experience outweighs degree specialisation.
Certifications (useful, none mandatory):
📌 Senior IT Infrastructure & Compliance Engineer (Bengaluru)
🏢 InterviewPanel
📍 Bengaluru