17 Sep
|
Krazy Bee Services
|
Bengaluru
17 Sep
Krazy Bee Services
Bengaluru
About the Role
We are looking for a Corporate IT / Enterprise Security Engineer to own and drive the security posture of our internal IT infrastructure, endpoint fleet, and enterprise applications. This role sits within our Cyber Security team and is responsible for protecting the organization's corporate environment from endpoints and networks to identity systems and data loss prevention. You will work closely with the IT, DevOps, and Security teams to implement and operationalize security controls, evaluate and deploy enterprise security products, respond to internal security incidents, and ensure compliance with audit requirements.
This is a hands-on role that requires both technical depth and the ability to drive cross-functional initiatives.
Key Responsibilities
Data Loss Prevention (DLP)
- Manage and operationalize the DLP solution (Zscaler / Netskope) across the organization policy creation, tuning, and incident response.
- Define and enforce DLP use cases for email, cloud storage, endpoints, and SaaS applications.
- Investigate DLP alerts, triage data exfiltration attempts, and coordinate with HR/Legal for policy violations.
- Continuously refine DLP policies to reduce false positives while maintaining detection coverage.
Endpoint Protection & Management
- Deploy, configure, and manage EDR/XDR solutions (SentinelOne or equivalent) across all corporate endpoints.
- Monitor endpoint security alerts, investigate suspicious activity, and drive remediation to closure.
- Maintain endpoint hardening baselines OS patching, application whitelisting, USB/peripheral controls.
- Conduct periodic security hygiene assessments of field/branch offices and remote workforce endpoints.
Identity & Access Management (IAM)
- Enforce MFA across all corporate applications; manage conditional access policies and SSO configurations.
- Conduct periodic access reviews identify and revoke stale/over-privileged accounts.
- Manage identity provider (IdP) security Google Workspace, JumpCloud, or equivalent directory services.
- Implement just-in-time (JIT) and least-privilege access for administrative accounts.
Enterprise Network Security
- Evaluate and manage enterprise Wi-Fi security solutions (Aruba / JumpCloud / equivalent).
- Implement network segmentation for corporate and guest networks. Monitor network traffic for anomalies using IDS/IPS and firewall logs.
- Manage VPN security configuration hardening, split-tunnel policies, and access controls.
Email & Communication Security
- Configure and maintain email security controls anti-phishing, DMARC/DKIM/SPF enforcement, and BEC detection.
- Run periodic phishing simulation campaigns and track employee susceptibility metrics.
MDM & SaaS Security
- Manage MDM/MAM solutions for corporate devices (Jumpcloud, Jamf, or equivalent).
- Discover and govern Shadow IT identify unapproved SaaS usage and enforce security policies.
- Conduct security posture assessments of enterprise SaaS applications (Google Workspace, Slack, Jira, etc.).
Audit & Compliance Support
- Support internal and external audits (KPMG, ISO 27001, SOC 2) by providing evidence, clarifications, and remediation tracking.
- Bifurcate and own Corp-IT specific audit findings; drive remediation to closure within defined SLAs.
- Maintain documentation asset inventories, security configurations, policy exceptions, and risk registers.
Security Awareness & Training
- Develop and deliver security awareness training programs for employees onboarding modules, annual refreshers.
- Create role-based training content for high-risk teams (finance, HR, customer support).
- Track training completion rates and correlate with phishing simulation performance.
Incident Response (IT Security)
- Act as the first responder for corporate IT security incidents credential compromise, malware infections, unauthorized access.
- Coordinate with the SOC team for escalated incidents; support forensic analysis when required.
- Maintain and update IT security incident response playbooks.
Required Skills & Qualifications
- 4 - 6 years of hands-on experience in IT Security, Enterprise Security, or a related cybersecurity role.
- Strong working knowledge of DLP platforms Zscaler, Netskope, Symantec DLP, or equivalent.
- Experience deploying and managing EDR/XDR solutions SentinelOne, CrowdStrike, Carbon Black, or equivalent.
- Solid understanding of IAM principles SSO, MFA, conditional access, directory services (Google Workspace, Azure AD, JumpCloud).
- Hands-on experience with enterprise network security firewalls, VPN, Wi-Fi security, network segmentation.
- Familiarity with email security DMARC, DKIM, SPF, anti-phishing tools, and BEC detection.
- Experience supporting audits ISO 27001, SOC 2, or RBI/CERT-In compliance frameworks.
- Robust analytical and troubleshooting skills with the ability to investigate and resolve security incidents independently.
- Good communication skills, ability to document findings, create reports, and present to non-technical stakeholders.
📌 Corporate IT / Enterprise Security Engineer (Bengaluru)
🏢 Krazy Bee Services
📍 Bengaluru