24 Sep
|
ComplianceQuest
|
Noida
24 Sep
ComplianceQuest
Noida
Role Overview
We are seeking a Senior / Lead Specialist – Enterprise Information Security & Operations to lead and continuously strengthen the security, governance, and operational resilience of enterprise IT, identity, cloud, and business application platforms. This is a hands-on leadership role spanning security engineering, SecOps/IR, enterprise application management, IAM/PAM operations, IT policies & processes and compliance, ensuring business continuity, a strong security posture, and audit readiness across the organization.
The role requires demonstrated experience across Microsoft 365, Azure/Entra ID, enterprise SaaS applications, IAM/PAM, cloud security, ITSM (ITIL) processes, and regulatory compliance (e.g., ISO 27001, SOC 2, privacy laws). You will work cross-functionally with Product, Engineering, Sales & Marketing, Legal, Compliance etc. and executive stakeholders to translate risk into actionable controls and measurable outcomes.
Key Responsibilities
1. Enterprise Information Security Operations & Governance
- Lead enterprise-wide security operations and governance across cloud, identity, endpoints, email, networks, and enterprise applications.
- Design, implement, and continuously improve security controls aligned to Zero Trust and Defense-in-Depth, including secure configuration standards and continuous control monitoring where applicable.
- Own the incident response (IR) lifecycle for security events, coordinating triage, investigation, containment, eradication, and root cause analysis (RCA) with internal teams, drive corrective and preventive actions.
- Own Security monitoring using SIEM/SOAR and EDR/XDR capabilities (e.g., Microsoft Defender), including alert triage, use-case tuning, and continuous improvement of detection coverage.
- Drive vulnerability and patch governance in partnership with IT and Engineering (prioritization, remediation SLAs, risk acceptance, and reporting).
- Maintain a strong security-by-design posture across IT and business application landscapes.
2. Enterprise Application Management & Security
- Own security and operational oversight of enterprise SaaS and business-critical applications (e.g., ERP/Finance, CRM, HRIS, Sales & Marketing tools, collaboration and analytics platforms) across departments.
- Lead application onboarding, access governance, and lifecycle management, ensuring least privilege and segregation of duties.
- Review and approve third-party integrations, OAuth permissions, APIs, and service accounts.
- Partner with application owners to ensure:
- Secure configuration baselines
- Logging, monitoring, and audit trails
- Vendor risk and compliance alignment
3. Identity, Access & Privileged Access Management (IAM/PAM)
- Participate in IAM strategy and operations across Entra ID (Azure AD) and integrated enterprise platforms, including identity lifecycle (joiner/mover/leaver) governance.
- Own RBAC models, Conditional Access, MFA, access reviews, and privileged access controls (e.g., PIM/PAM, break-glass accounts, just-in-time access) to enforce least privilege and segregation of duties.
4. Microsoft 365, Cloud & Infrastructure Security
- Provide security leadership for Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive) and Azure workloads.
- Oversee
- Email security, mail flow integrity, and threat protection
- Endpoint and device security (Intune, Defender)
- Secure DNS, web traffic, CDN, and firewall services (e.g., Cloudflare)
- Implement and govern information protection controls across Microsoft 365 (e.g., DLP and data classification/labeling) and support secure collaboration and external sharing.
- Ensure cloud resources follow secure architecture patterns, centralized logging/telemetry, and monitoring standards to support detection, forensics, and audit requirements.
5. Risk Management, Compliance & Audit
- Own enterprise risk management processes covering IT, cloud, and applications.
- Lead internal and external audits including ISO 27001, SOC 2, GDPR, and customer assurance/audit requests.
- Maintain audit-ready documentation, evidence repositories, and control mappings.
- Drive remediation programs and closure of findings using KPI-driven tracking.
6. IT Operations, ITSM & Process Excellence
- Partner with IT Operations teams to ensure secure and reliable service delivery across regions.
- Embed security controls into ITIL-aligned ITSM processes (Change, Incident, Problem, Access, Asset).
- Define and monitor SLAs, KPIs, and operational risk indicators.
- Drive standardization, automation, and documentation to scale enterprise operations.
Required Skills & Experience Technical & Domain Expertise
- 12+ years of experience in enterprise IT security operations, cybersecurity, and governance.
- Strong hands-on experience with:
- Microsoft 365, Azure / Entra ID
- IAM/PAM, RBAC, access reviews, Conditional Access, MFA
- Enterprise SaaS and application security (SSO/SAML/OIDC, OAuth, service accounts)
- Web and edge security (WAF/CDN/DNS, TLS, secure headers; e.g., Cloudflare)
- ITSM/service governance (ITIL; change, incident, problem, access, asset)
- Security operations tooling (SIEM/SOAR), detection engineering, and incident response workflows
- Endpoint security (EDR/XDR) and device management (e.g., Defender for Endpoint, Intune)
- Information protection (DLP, data classification/labeling; CASB concepts where applicable)
- Experience with cloud and security platforms (e.g., Azure Security, Defender etc.).
Risk, Compliance & Privacy
- Proven experience delivering and operating controls aligned to:
- ISO 27001, SOC 2
- GDPR, DPDP Act, privacy-by-design
- Solid audit management and evidence-handling capability.
- Creation IT policies and procedures, implementations and monitoring
Leadership & Soft Skills
- Strong stakeholder management and communication skills.
- Ability to balance hands-on execution with strategic leadership.
- Ability to handle IR process till closure and manage stakeholders during the whole process.
- Excellent documentation, analytical thinking, and training delivery capability
- Willingness to participate and support a 24x7 production environment as needed.
Preferred Qualifications
- Graduate/Postgraduate degree with obtained skills in Computer Science, Information Security, or equivalent experience.
- ISO 27001 Lead Auditor / Implementer
- ITIL v4 Foundation
- Microsoft Azure certification(s) (e.g., AZ-104, AZ-500, SC-200/SC-300) or equivalent experience.
- Security certifications (preferred): CISSP, CISM, CCSP, GIAC, or relevant Microsoft Security certifications.
Success Metrics
- Stable and secure enterprise IT and application environment
- Consistent clean audit outcomes with zero repeat findings
- Reduced identity and privileged access risk
- High stakeholder confidence in security and IT operations
- Scalable, documented, and automation-driven governance processes
- IT policies and procedures creation and implementation
- Internal IT audits and continuous improvements
📌 Lead Specialist - IT (Noida)
🏢 ComplianceQuest
📍 Noida