
Security & Compliance Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Deliver initial response and operational assistance for information security incidents.
• Implement incident containment, response, escalation, and recovery processes.
• Create, sustain, and enhance security incident response runbooks and protocols.
• Collaborate with MDR/SOC teams to investigate, contain, and resolve security incidents.
• Assist in incident investigation, documentation, root-cause analysis, and post-incident evaluations.
• Monitor and document security incidents, actions taken, escalations, and remediation efforts.
• Aid in ISO 27001 information security management and compliance initiatives.
• Contribute to PDPL compliance efforts, security controls, assessments, and documentation.
• Assist with information classification, handling requirements, records management, and information governance processes.
• Organize and provide evidence for both internal and external security audits.
• Keep security risk registers updated and track mitigation and remediation efforts.
• Generate and maintain monthly security metrics, dashboards, and management reports.
• Support periodic security and governance reviews, including Y1.2 assessments and related activities.
• Manage and support BeyondTrust Privileged Access Management (PAM).
• Evaluate privileged access, access controls, approvals, and governance needs.
• Collaborate with governance, compliance, IT, security, and business teams on security initiatives.
• Assist with security control assessments, compliance reviews, and tracking remediation actions.
• Ensure accurate maintenance of security policies, procedures, records, evidence, and governance documents.
• Identify areas for enhancing security operations, incident preparedness, information governance, and compliance processes.
• Over 5 years of professional experience in IT security, information security, cybersecurity, security governance, or compliance.
• More than 3 years of hands-on experience in incident response and security operations.
• At least 2 years of experience with ISO 27001 and PDPL compliance or related information security regulatory frameworks.
• A minimum of 2 years of experience in information governance, including information classification and records management.
• Strong grasp of security incident response processes, including containment, escalation, investigation, and recovery.
• Experience in developing and maintaining incident response runbooks and operational procedures.
• Background in coordinating with SOC, MDR, or managed security service providers.
• Practical experience with BeyondTrust PAM administration.
• Solid understanding of privileged access management, access governance, and security controls.
• Experience in maintaining security risk registers and supporting risk assessments and remediation efforts.
• Proven ability to prepare security metrics, management reports, audit evidence, and compliance documentation.
• Comprehensive understanding of ISO 27001, information security governance, risk management, and audit processes.
• Practical knowledge of PDPL requirements and principles of information governance.
• Strong coordination abilities with the capability to work across security, governance, compliance, IT, and business teams.
• Exceptional written and verbal communication skills.
• Strong analytical, documentation, and problem-solving skills.
• Ability to work independently in a remote setting and manage multiple security and compliance priorities.
• Competitive salary and performance bonuses.
• Opportunities for professional development and growth.
• Flexible working hours and remote work options.
• Comprehensive health and wellness programs.
• Supportive and collaborative team environment.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.