28 Sep
|
Moodys Analytics
|
Pune
28 Sep
Moodys Analytics
Pune
Position Title- Information Security Specialist (Principal Engineer)
Experience Level-5-7 years
Department- Information Security
Location- Pune/Bengaluru
Key Responsibilities
A. Cloud Security Assessment and Architecture Review
- Review cloud and SaaS deployments across Azure, AWS, Microsoft 365 and other business platforms for secure configuration, identity, access, monitoring, logging, encryption, network segmentation and data protection controls.
- Assess project architecture, application onboarding requests, infrastructure changes and cloud service usage from security, privacy, client contractual and operational risk perspectives.
- Recommend pragmatic remediation actions, compensating controls and secure design improvements that can be implemented by engineering, IT operations or delivery teams.
- Review IAM, privileged access, service accounts, conditional access, secrets handling, key management, storage security, backup, resilience and security baseline adherence.
- Review and audit Security Operations Centre monitoring practices, including log-source coverage, detection use cases, alert logic, alert thresholds, triage procedures, escalation paths, incident hand-offs, evidence retention and closure tracking.
- Assess Web Application Firewall controls and network firewall rules, including business justification, least-privilege alignment, exposed services, source and destination restrictions, ports and protocols, logging, alerting, periodic recertification, exceptions, and removal of obsolete or overly permissive rules.
- Validate that relevant cloud, application, WAF, firewall, identity, endpoint and data-protection events are integrated with SOC monitoring and escalated in line with incident-management, risk and client requirements.
- Review SOC performance and control effectiveness through sampling of alerts and incidents, detection coverage, response timelines, escalation quality, root-cause analysis,
remediation evidence and closure records.
- Support secure cloud governance by tracking deviations, exceptions, control gaps and remediation status across assigned engagements.
B. DLP Implementation, Refinement and Operations
- Support implementation, refinement and day-to-day management of DLP policies across email, endpoint, cloud storage, SaaS platforms and collaboration tools as applicable.
- Review DLP alerts, violations and policy matches to identify true risks, false positives, noisy rules and opportunities for policy tuning.
- Work with business, delivery and technology teams to refine DLP rules, sensitivity labels, data handling controls and exception handling practices.
- Document DLP risk decisions, recurring patterns, policy exceptions, false-positive rationale and corrective actions in the approved tracker or system of record.
- Contribute to awareness and adoption by converting DLP observations into practical guidance for users and project teams.
C. Technical Risk Review and Policy Exception Management
- Serve as the Information Security reviewer for assigned project engagements, technical change reviews, production onboarding, client delivery initiatives and risk assessments.
- Evaluate security risks pragmatically by considering likelihood, impact, data sensitivity, client exposure, compensating controls, operational feasibility and implementation timelines.
- Manage policy exceptions by validating business justification, risk exposure, compensating controls, expiry dates, accountable owner,
approval status and periodic review requirements.
- Track remediation actions and exception closure with project owners, IT operations, delivery teams and control owners.
- Escalate material, repeated or unmanaged risks with clear facts, business impact and recommended decision options.
D. Standards, Controls and Audit Alignment
- Map technical control observations to relevant security standards, client commitments and internal policies, including ISO 27001, SOC 2, CIS controls, CSA CCM, NIST CSF and cloud security benchmarks.
- Prepare concise evidence, control narratives and remediation updates to support audits, client security reviews and internal compliance checks.
- Support maintenance of cloud security standards, DLP standards, data handling procedures, exception processes and technical security guidelines.
- Contribute to control testing by validating whether security controls are implemented, operating and evidenced in a manner suitable for audit and risk review.
Key Competencies
Required Qualifications and Certifications
- Bachelor degree in Engineering, Computer Science, Information Security, Information Technology or equivalent practical experience.
- 6-7 years of experience in information security, cloud security, security operations, security architecture review, DLP, technical risk assessment or related roles.
- Preferred certifications: CCSP, AWS Security Specialty, Azure Security Engineer, CISSP, CISM, CISA, ISO 27001 LA / LI, or equivalent practical cloud / security certification.
- Experience in skilled services, IT outsourcing, financial services, KPO/BPO or client delivery environments is preferred.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Principal Engineer- Info Sec (Pune)
🏢 Moodys Analytics
📍 Pune