
Information Security Specialist II
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in India.
• Take full ownership and manage the enterprise Data Loss Prevention (DLP) program from start to finish, which includes designing and modifying policies, handling exceptions, and rolling out new functionalities.
• Collaborate with Legal and data custodians to establish and enforce safeguards for high-risk company assets.
• Keep an up-to-date inventory of protected assets, reviewed quarterly with Legal.
• Conduct security assessments for Azure and AWS cloud environments and address any identified issues.
• Assist with Azure cloud security engineering tasks, such as Microsoft Graph API automation, secure configuration, and strengthening identity and workloads.
• Manage High and Critical security alerts in non-US time zones, ensuring documented resolution within the service level agreement (SLA).
• Enhance L2 support efficiency through standard operating procedures (SOPs), expert guidance, escalation support, and automation playbooks.
• Serve as the integration owner and backup contact for third-party managed detection and response services.
• Ensure compliance of Information Security operations with ISO 27001, data privacy regulations, and other pertinent requirements.
• Assist with internal audits, FedRAMP, and Legal inquiries.
• Contribute to Information Security special projects and offer backup support across critical security and GIT domains.
• Create reports, technical presentations, and KPI/metrics reports for management.
• Analyze security logs, investigate threats and vulnerabilities, and respond to security incidents.
• Adjust DLP policies and manage business exception requests.
• Evaluate firewall, intrusion detection, and encryption tool configurations.
• Assess and test networks and cloud infrastructure for vulnerabilities and recommend remediation strategies.
• Review and audit Azure and AWS Security Groups.
• Work with security experts and stakeholders to enhance the overall security posture of the organization.
• A minimum of eight (8) years of relevant information security experience, with hands-on responsibility for an enterprise security program.
• Bachelor’s degree in Information Security, Computer Science, or a related field; or equivalent work experience is required.
• Proven experience in managing an enterprise DLP program, including policy creation, tuning, exception handling, and sensitivity labeling for Confidential and Restricted data.
• Familiarity with Microsoft Purview DLP and Information Protection is preferred.
• Experience in designing, assessing, and remediating Azure cloud security controls, including Defender for Cloud, Entra ID, Azure Policy, and both network and workload security.
• AWS knowledge is considered an advantage.
• Direct experience in L2/L3 incident response, including ownership of High and Critical cases to resolution in collaboration with an MSSP or 24x7 SOC partner.
• Proven ability to write SOPs, runbooks, and automation/SOAR playbooks.
• Proficient in writing incident reports.
• Familiarity with Microsoft Graph API and scripting automation using PowerShell and Python.
• Understanding of information security and data privacy laws and frameworks, such as ISO 27001 and GDPR.
• Experience in supporting both internal and external audits.
• Professional certifications preferred include CISSP, CCSP, AZ-500, SC-400, GCIH, or equivalent.
• Willingness to handle non-US-hour escalations for global incidents.
• Excellent written and verbal communication skills.
• Ability to collaborate effectively with Legal, business stakeholders, and global IT teams.
• Availability to manage High and Critical escalations during non-US time zones.
• Competitive insurance packages for you and your immediate family.
• Annual health checkup.
• Marriage leave.
• Paternity leave.
• Employee Assistance Programme.
• Extensive opportunities for learning and development.
Reli Group
Second Nature
ASRC Federal
Kyndryl
Get handpicked remote jobs straight to your inbox weekly.