IT Security Engineer (Mumbai)

IT Security Engineer (Mumbai)

19 Sep
|
CustomerInsights.AI
|
Mumbai

19 Sep

CustomerInsights.AI

Mumbai

About CustomerInsights.AICustomerInsights.AI is a global analytics and AI-driven company founded in 2018, enabling data-driven commercial decision-making for Life Sciences organizations. Our product ecosystem, including ciPARTHENON and ciATHENA, leverages Analytics Automation, Artificial Intelligence, and Machine Learning to deliver timely, actionable insights to key stakeholders. With teams across North America and India, we work with client organizations ranging from emerging startups to large enterprises.

Position OverviewWe are seeking a proactive and detail-oriented IT Security Engineer with 4+ years of hands-on experience in cybersecurity operations, endpoint security, vulnerability management, and identity security. In this role, you will be a critical part of our IT team, responsible for both day-to-day L1 security operations and strategic security initiatives.You will work collaboratively with IT, audit, compliance, and business stakeholders to ensure our security posture remains strong, our endpoints are secured, and our Microsoft 365 & cloud environments are configured to the highest standards.

You will own and drive:End-to-end L1 IT Security operations — from device setup to user lifecycle managementMicrosoft 365 & Azure AD security governance, monitoring, and policy enforcementProactive threat detection, incident response, and vulnerability remediationSecurity documentation, compliance readiness, and audit evidence management

Key Responsibilities:L1 IT Operations & Endpoint ManagementDevice Provisioning:

Perform end-to-end laptop setup and configuration for new joiners:Imaging, OS configuration, software installation, and domain enrollmentApplying security baselines, disk encryption (BitLocker), and MDM enrollmentAsset tagging, inventory tracking, and documentation in the CMDBOnboarding:

Manage the complete employee onboarding process from an IT Security perspective:Create user accounts across Active Directory, Azure AD, and M365Assign role-based licenses, groups, and permissions as per approved access matrixConfigure MFA, SSO, and ensure secure first-login experienceWalk new employees through IT security policies and acceptable use guidelinesOffboarding:

Execute secure and timely employee offboarding processes:Disable/delete accounts across all systems within SLA on last working dayRevoke VPN, email, application, and cloud resource access immediatelyRetrieve company devices, wipe data, and update inventory recordsArchive mailboxes and transfer data ownership to Reporting ManagerEndpoint Security:

Implement and manage endpoint security controls including antivirus, EDR agents, disk encryption, USB controls, and device hardening policiesMDM Administration:

Administer MDM (Microsoft Intune / similar) enroll devices, push policies, and enforce complianceL1 Security Support:

Provide Level 1 security support for end-user security issues, phishing reports,



and access requestsMicrosoft 365 & Azure AD SecurityM365 Portal Review:

Conduct regular reviews of the Microsoft 365 Defender, Purview, and Compliance portals to identify security gaps, misconfigurations, and active threats:Review Secure Score recommendations and implement approved improvementsMonitor Exchange Online Protection (EOP), Defender for Office 365 alerts and quarantineAudit SharePoint, OneDrive, and Teams sharing settings and external accessPolicy Implementation:

Design, implement, and enforce Microsoft 365 security policies across the tenant:Conditional Access policies — location-based, device compliance, and risk-basedData Loss Prevention (DLP) policies for email, Teams, SharePoint, and endpointsInformation Protection labels and retention policies in Microsoft PurviewAnti-phishing, anti-spam, safe links, and safe attachments policies in DefenderPolicy Review:

Perform scheduled reviews of all active M365 security policies to ensure continued effectiveness:Review and update Conditional Access, DLP, and MFA policies quarterlyIdentify redundant or conflicting policies and propose rationalizationDocument policy change history and maintain an approval audit trailM365 Documentation:

Prepare and maintain comprehensive security documentation for M365 configurations:Maintain a current M365 security configuration baseline documentDocument all policy implementations with rationale, scope, and exceptionsKeep runbooks and SOPs updated for common M365 security tasksSecurity Suggestions:

Provide proactive security recommendations to improve the M365 security posture:Analyze Secure Score trends and present improvement roadmaps to managementResearch and propose adoption of new security features (e.g., Copilot for Security, SSPM tools)Benchmark tenant configuration against CIS M365 benchmarks and industry best practicesAzure AD Governance:

Monitor and manage Azure AD / Entra ID configurations:Enforce MFA, SSPR, and Privileged Identity Management (PIM)Review Guest user access, enterprise app permissions, and OAuth consent grantsConduct periodic User and Admin access reviews, action findings within SLASecurity Monitoring & Incident ResponseAlert Monitoring:

Monitor and triage alerts from SIEM, EDR, DLP, MDM, and M365 Defender portals dailyIncident Response:

Perform initial investigation, containment, and documentation for security incidents:Follow defined incident response playbooks for phishing, malware, data leakage,



and unauthorized accessEscalate confirmed incidents with a detailed timeline and impact assessmentVulnerability Management:

Conduct regular vulnerability scans, validate findings, and track remediation with IT and engineering teamsThreat Hunting:

Perform threat hunting activities and proactively identify indicators of compromise (IOCs)Identity & Access Management (IAM)Enforce MFA, RBAC, and least privilege access principles across all platformsConduct periodic access reviews and certifications; remediate access anomaliesSupport user onboarding and offboarding to ensure secure provisioning and deprovisioningManage privileged accounts and admin access with appropriate oversight and loggingCompliance, Documentation & Audit ReadinessPrepare audit-ready evidence packages for ISO 27001, SOC 2 Type II, and internal auditsMaintain and regularly update security SOPs, configuration baselines, and policy repositoriesSupport risk assessments and vendor security reviews; document findings and track remediationParticipate in security awareness programs and organization-wide risk mitigation initiatives

Qualifications:4+ years of hands-on experience in IT security, security operations, or related IT rolesStrong working knowledge of Microsoft 365 Security suite Defender, Purview, Entra ID, and IntuneExperience with endpoint security tools (EDR, antivirus, disk encryption, MDM)Familiarity with SIEM platforms, log monitoring, and alert triageUnderstanding of IAM concepts: MFA, RBAC, Conditional Access, PIMHands-on experience with vulnerability scanning tools (Qualys, Tenable, or similar)Knowledge of security frameworks: ISO 27001, SOC 2Strong documentation skills ability to write clear SOPs, policies, and audit evidenceExcellent communication and stakeholder management skillsAbility to manage multiple priorities in a dynamic work environmentFlexible to collaborate across different time zones, including IST and US business hours, based on team and project needsWilling to provide occasional extended-hour support, when required, for collaboration with US stakeholders, security operations, or critical incident support

Preferred Certifications (Not Mandatory)CompTIA Security+Microsoft SC-900 – Microsoft Security, Compliance, and Identity FundamentalsMicrosoft SC-200 – Microsoft Security Operations Analyst

Job Location:

Gurgaon

Why Join Us?Play a key role in shaping the next generation of intelligent enterprise platformsWork at the intersection of cutting-edge AI and real-world business impactCollaborate with passionate data scientists, engineers and domain expertsBenefit from a flexible work setting focused on continuous learning and innovation

Culture & ValuesWe foster a high-ownership, performance-driven culture where teams are encouraged to think creatively, act responsibly, and deliver measurable outcomes. Our values guide how we collaborate, make decisions, and build long-term partnerships.

📌 IT Security Engineer (Mumbai)
🏢 CustomerInsights.AI
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: it security engineer (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: it security engineer (mumbai) / mumbai