24 Sep
|
Probill RCM
|
Chandigarh
24 Sep
Probill RCM
Chandigarh
Role Overviews
We are seeking a Cyber Security Compliance Engineer to support security governance, control assurance, audit readiness, vulnerability follow-up, and continuous improvement across SOC, application, cloud, and infrastructure environments. The role translates security obligations into practical evidence, policies, control checks, and remediation actions.
Key Responsibilities
- Support security compliance assessments, control testing, evidence collection, gap analysis, remediation tracking, and audit responses.
- Maintain security policies, standards, SOPs, control matrices, risk registers, exception records, and compliance evidence repositories.
- Coordinate audit-evidence requests with SOC, IT, cloud, network, application, and business stakeholders.
- Map security controls and operational practices to applicable frameworks such as ISO 27001, NIST CSF, CIS Controls, and contractual requirements.
- Review incident, vulnerability, access-control, logging, retention, backup, and change-management evidence for completeness and compliance.
- Track security findings, assign owners and due dates, validate closure evidence, and escalate overdue or high-risk items.
- Support secure code-review coordination, application-security governance, dependency risk review, and Software Bill of Materials governance.
- Assist with RACI development, security awareness activities, third-party security reviews, and compliance reporting.
- Review SOC metrics, incident trends, control failures, and recurring observations to recommend preventive improvements.
- Contribute to management reports, audit presentations, risk summaries, and continuous-improvement plans.
- Participate in incident post-review activities and confirm that corrective and preventive actions are documented and tracked.
Required Qualifications and Skills
- 4 to 5 years of experience in cyber security compliance, GRC, security assurance, IT audit, or security operations governance.
- Working knowledge of ISO 27001, NIST CSF, CIS Controls, risk assessment, control testing, and audit-evidence management.
- Understanding of SOC operations, incident response, vulnerability management, identity and access management, logging, and cloud controls.
- Experience preparing policies, SOPs, risk registers, control mappings, remediation plans, and management reports.
- Ability to assess technical evidence and explain compliance gaps clearly to technical and non-technical stakeholders.
- Strong documentation, organization, analytical thinking, and follow-up skills.
Preferred Qualifications
- Knowledge of PCI DSS, SOC 2, GDPR, privacy controls, or sector-specific regulatory requirements.
- Exposure to Microsoft Sentinel, Defender, cloud-security dashboards, GRC platforms, or vulnerability-management tools.
- Familiarity with OWASP, secure SDLC, SBOM, third-party risk, and application-security assurance.
- Certifications such as ISO 27001 Lead Implementer or Auditor, CISA, CRISC, Security+, or equivalent.
Key Performance Areas
- Timely completion of evidence and control assessments
- Closure rate and ageing of compliance findings
- Accuracy of control mappings and audit documentation
- Quality of risk and compliance reporting
Work Arrangement This is a full time hybrid position based in Chandigarh. The role will primarily operate from home, with office attendance required for onboarding, workshops, operational needs, stakeholder meetings, or other business requirements. SOC roles may require rotational shifts, weekend coverage, and on-call availability according to the approved roster.
Work Location: In person
📌 Cyber Security Compliance Engineer (Chandigarh)
🏢 Probill RCM
📍 Chandigarh