Cutshort logo
For Employers
vaaragonenterprisescom logo
Consultant Information Security - ISO 27001 Lead Implementer
Consultant Information Security - ISO 27001 Lead Implementer

Consultant Information Security - ISO 27001 Lead Implementer at vaaragonenterprisescom · Gurugram · 7 - 15 years · ₹12L - ₹25L / yr · Bootstrapped · Posted 25 Aug 2025

vaaragonenterprisescom's logo

Consultant Information Security - ISO 27001 Lead Implementer

satish agrawal's profile picture
Posted by satish agrawal
7 - 15 yrs
₹12L - ₹25L / yr
Gurugram
Skills
ISO 27001 LI
ISO 27701 Lead implementer
Information security
IT security
information security consultant
CISM

Job Title: Senior Consultant Information Security – IT

Job Purpose: Acting in a key technical management & execution capacity to

provide a conduit between M&S IT teams and key business stakeholders thereby

ensuring information technology needs are managed consistently, following

professional IT and global M&S standards, and delivered with a high quality and

customer satisfaction.

Reward level: Middle Management

Job Location Gurgaon

Experience 7 years

Relevant Experience 7 years

Reporting to: General Manager

Qualification: Bachelor’s degree in IT and relevant Information Security

Certifications

Key Deliverables:

 Provide support as Lead implementor towards ISMS and PIMS policies,

procedures, and guidelines and ensure to perform regular review and update.

 Gather evidence of continuous compliance with ISO 27001:2022 and ISO

27701:2019, DPDPA, IT Act and Cert In Regulation including audit logs,

records of reviews, timely closure of open audit and risks and sharing the

report with management.

 Conduct regular, documented information security and privacy risk

assessments on Security Tools and Technologies by identifying assets,

threats, vulnerabilities, likelihood, and impact.

 Prioritize identified vulnerabilities, detailed findings, remediation

recommendations, trending reports on vulnerability posture towards closure

with stakeholders.

 Implementation of a comprehensive, ongoing security project plan for

remediation of open audit gaps.

 Prepare regular report on overall information security posture, GRC maturity,

and risk landscape to relevant stakeholders

 Perform Root Cause Analysis and lessons learned from information security

incidents, actively participate in audits and support internal IT staff to perform

technical assessments and controls with evidence.

Key Relationships:

 Internal IT and business customers in MSR.

 Global/Local IT Vendor, market and global (HQ) colleagues,

 Internal staff - direct reports (where applicable)

 IT vendors, contractors (where applicable)

Knowledge Skills and Abilities:


 Must have ISO 27001 Lead Implementer and ISO 27701 Lead Implementer

certifications.

 In depth understanding of IT Act, DPDPA, Cert In regulations, CIS Controls as

well as UK DPA and ISO 31000

 Good to have certification on CISM (Certified Information Security Manager),

CISSP (Certified Information Systems Security Professional) and Cloud Security

certifications (e.g., CCSK, CCSP, vendor-specific like AWS Security Specialty)

 Familiarity with common vulnerability scanning tools like Qualys (features,

reporting, agent-based vs. network scans) and Cloud Security Posture

Management (CSPM) tools like Wiz (cloud service provider configurations,

misconfigurations, compliance checks in AWS, Azure, GCP).

 Conduct and lead IT DR drills and Tabletop exercises with internal IT teams.

 Hands on knowledge on common security technologies (e.g., firewalls, EDR,

Cloud Security, VAPT tools, SIEM, WAF, DLP, PAM, BAS, encryption etc.,).

 Ability to handle and manage Endpoint, Perimeter, Cloud and Data Security

technical consoles with configuration and fine tuning of policies.

 Understanding of various penetration testing types (e.g., network, web

application, API, mobile, cloud) and methodologies

 Knowledge of common attack vectors and exploitation techniques like MITRE

ATTACK and DEFEND, NIST Cyber Security Framework.

 Excellent technical writing skills for creating clear, concise, and comprehensive

security policies, standards, and procedures.

 Ability to analyse complex risk data and present actionable insights.

 Proficiency with GRC platforms or tools for managing policies, risks, and controls

 Exceptional verbal and written communication skills to articulate complex security

concepts to technical and non-technical stakeholders

 Strong technical skills to diagnose security issues, identify root causes, and

develop effective solutions.

 Ability to develop and deliver engaging security training sessions and awareness

campaigns to internal IT staff.

 Ability to stay updated with the latest security threats, vulnerabilities,

technologies, and regulatory changes.


mail updated resume- etalenthire[at]gmail[dot]com

satish- 88O 27 49 743

Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About vaaragonenterprisescom

Founded :
2023
Type :
Services
Size :
0-20
Stage :
Bootstrapped

About

N/A

Company social profiles

N/A

Similar jobs (10)

Mumbai
5 - 7 yrs
₹8L - ₹15L / yr
ISO/IEC 27001:2005
Information security governance
Compliance
Risk Management
Stakeholder management

We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the

design, implementation, and maintenance of our ISO 27001 Information Security Management

System (ISMS). This is a hands-on leadership role responsible for establishing a robust security

governance framework, achieving ISO 27001 certification, and embedding a culture of

continuous security improvement across the organization.

Key Responsibilities

● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation

from gap analysis through to successful Stage 1 and Stage 2 certification audits;

manage external auditor relationships

● Risk Management: Develop and operationalize the information security risk

management framework; conduct risk assessments, treatment planning, and risk

acceptance processes.

● Policy & Governance : Author, approve, and maintain the Statement of Applicability

(SoA), information security policies, standards, and procedures aligned with ISO 27001

Annex A controls.

● Control Implementation: Translate ISO 27001 Annex A controls into operational

security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to

implement and validate controls.

● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and

KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective

actions.

● Third-Party Risk: Oversee vendor security assessments and ensure supply chain

security controls meet organizational and ISO 27001 standards.

● Stakeholder Management: Report ISMS performance, risks, and compliance status to

senior leadership and the board; act as primary liaison for external auditors and

regulators.

Required Qualifications

● 5+ years of experience in information security governance, risk, and compliance

● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap

analysis → certification)

● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS

documentation requirements

● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,

OCTAVE, FAIR)

● Familiarity with internal audit practices and managing external certification bodies

● Excellent stakeholder management and ability to influence across technical and non-

technical teams

● Strong documentation and communication skills — able to translate complex standards

into actionable guidance

Preferred Qualifications

● Experience implementing ISMS in fintech, healthcare, or regulated industries

● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks

● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments

● Knowledge of automation for compliance evidence collection and control testing

● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead

Implementer

Why Join Us

● Opportunity to build the security governance function from the ground up

● High-visibility role with direct impact on customer trust and market differentiation

● Collaborative environment that values security as a business enabler, not a blocker

Company Profile:

We are a one-stop financial services shop, widely known for quality of its advice, personalized

service and cutting-edge technology. We started our journey in 2008. Currently we are serving

more than 50,000 investors with a team of 100 members. Our core product offering is mutual

fund, FD, Govt. Bonds, Debenture, etc.



Read more
NAM Info Pvt Ltd
Ramya Munirathnam
Posted by Ramya Munirathnam
Bengaluru (Bangalore), Chennai, Hyderabad, Mumbai, Pune
5 - 7 yrs
₹6L - ₹12L / yr
Cyber Security
GRC
Security Compliance

This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).

Key responsibilities:

  • Perform security control assessments against organizational policies, security standards, and regulatory requirements.
  • Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
  • Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
  • Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
  • Conduct control testing and risk assessments and support internal/external security audits.
  • Review security policies, procedures, standards, and governance frameworks for compliance.
  • Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
  • Support overall security governance, regulatory compliance, and IT risk management activities.

Required Skills

  • Cyber Security Risk & Compliance / GRC
  • IT Risk & Controls
  • Security Control Assessment & Testing
  • Security Audits
  • Backup & Disaster Recovery
  • BCP / DR
  • Risk Assessment
  • Compliance & Governance
  • Security Policies & Standards
  • Audit Finding & Remediation Management
Read more
P99soft
icon

The recruiter has not been active on this job recently. You may apply but please expect a delayed response.

Dubai
4 - 10 yrs
₹25L - ₹39L / yr
ISO/IEC 27001:2005
Web3js

IT Compliance Manager – Web3 & Digital Assets

📍 Location: Dubai, UAE

💼 Employment Type: Full-Time

🏢 Department: Technology / Compliance

📊 Experience: 5+ Years

🌐 Industry: FinTech / Web3 / Digital Assets


About the Role

We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.

The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.


Key Responsibilities

  • Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
  • Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
  • Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
  • Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
  • Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
  • Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
  • Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
  • Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
  • Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
  • Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.


Requirements

  • Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
  • 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
  • Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
  • Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
  • Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
  • Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
  • Experience working with auditors, regulators, and cross-functional technology teams.
  • Strong analytical, documentation, communication, and stakeholder-management skills.

UAE / Web3 Experience – Preferred

  • Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
  • Experience supporting VASP licensing or regulatory approvals.
  • Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
  • Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.

Preferred Certifications

  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • CAMS

Key Skills

IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management


Read more
Metadome.ai
at Metadome.ai
2 candid answers
Ananya  Arenavaru
Posted by Ananya Arenavaru
Bengaluru (Bangalore)
5 - 10 yrs
₹15L - ₹18L / yr
Jump Cloud
Sophos
google workspace
SSO
Sophos Central administration
+10 more

IT Systems Engineer

Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure

Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership

Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at

scale.

The Mission

About Metadome.ai

Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the

Metaverse Standards Forum and the VR/AR Association.


About the Role

We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.

This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.


Core Responsibilities

● Identity & Access Management — JumpCloud:

○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.

○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.

○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.

○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.

○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.

● Google Workspace Administration — GWS:

○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.

○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,

and sharing / visibility policies.○

○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.


Endpoint & Threat Protection — Sophos:

○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and

servers.

○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.

○ Maintain endpoint encryption, web / application control, and device-hardening standards.

○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.


Network, Firewall & Wi-Fi:

○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.

○ Administer enterprise Wi-Fi and wired networks (switches, access points), including

RADIUS-backed authentication.

○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.

○ Implement network monitoring, intrusion detection, and centralized logging.

Hardware, Software & Asset Management:

○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and

decommissioning.

○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.

○ Maintain an accurate hardware and software inventory and asset register.

○ Manage software deployment, patch management, and license compliance.


Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:

○ Operate and continuously improve the company's Information Security Management System

(ISMS).

○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control

implementation, evidence collection, and continuous monitoring.

○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA

assessments.

○ Serve as a primary point of contact during external audits and customer security reviews.

○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response

runbooks.

○ Drive security-awareness and phishing-simulation programs across the organization.


IT Operations & Support:

○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.

○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.

○ Manage backups, disaster recovery, and business-continuity testing.

○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within

budget.

○ Maintain documentation, runbooks, and standard operating procedures.

○ Own and report on the IT budget and asset allocation.


Required Skills & Experience

● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems

below rather than purely supervisory exposure.

● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.

● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.

● Sophos — hands-on endpoint / XDR administration and threat response.

● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.

● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one

full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.


Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.

System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.


Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.


Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.


Preferred Qualifications


●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.

●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.

●Scripting and automation for IT operations (Bash, PowerShell, or Python).

●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.

●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.


Why Join Us

You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running

flawlessly.



Read more
Potentiam Offshore Solutions Pvt Ltd
Bhavya Pallapu
Posted by Bhavya Pallapu
Bengaluru (Bangalore)
3 - 8 yrs
₹12L - ₹20L / yr
SOX 404
ITGC
NIST
ISO27001
CSF

Job title Sox Compliance Officer

Reporting to Potentiam company background (The Employer) Potentiam is a global provider of highly qualified professionals to European SMEs from our offices in Romania, South Africa and India. Potentiam works with clients in finance, energy, leisure, marketing, business services and technology industries, providing technical, professional multi- lingual highly motivated staff, most of whom have had experience of working for international companies. Staff cover a wide range of roles from accounting, marketing, data management, HR, sales/account management, engineering, technology, and operations. Potentiam manages our staff’s career development and personal development training, all infrastructure, HR and payroll with our clients directly managing day-to-day staff responsibilities and role training and development. Company website - https://potentiam.co.uk/

Potentiam’s client: It is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, document management and related services. It provide IME services through their medical panel of credentialed physicians and allied medical professionals. Their independent medical review process is fully contained within their private cloud network. Custom portals, applications, workflow enhancements and systems integration are part and parcel of their service. Their clients include property and casualty insurance carriers, law firms, third-party claim administrators and government agencies that use independent services to confirm the veracity of claims by sick or injured individuals under automotive, disability, liability and workers' compensation insurance coverages. They help clients in the U.S., Canada, the United Kingdom and Australia manage costs and enhance their risk management processes by verifying the validity of claims, identifying fraud and providing fast, efficient and quality IME services.

Industry: legal, insurance, and healthcare services.

Purpose of role:

We are seeking a Compliance Officer to join our compliance team. This role is responsible for auditing IT control activities, ensuring adherence to Sarbanes Oxley (SOx) requirements, and maintaining governance standards. The ideal candidate will work closely with external auditors, perform Entity-Level Controls (ELCs), and document narratives, processes, and procedures in a fast paced environment. Potentiam | Job Specification 2 of 2

Duties and responsibilities: Compliance & Audit Activities • Audit IT control operations performed by IT Controls Analysts to ensure compliance with SOx requirements. • Perform walkthroughs and testing of ITGCs and ELCs to validate control design and operating effectiveness. • Develop, maintain, and update SOx narratives, process flows, and control documentation. • Coordinate and liaise with external auditors during SOx audits and provide requested evidence. • Identify control gaps and recommend remediation plans in collaboration with stakeholders. • Experience with ISO 27001 and NIST CSF, including understanding of information security controls, risk management, control assessments, compliance requirements, and security governance practices. • Familiarity with Cyber Essentials Plus (CE+) and related security/compliance requirements, along with knowledge or experience using Vanta or similar GRC/compliance management platforms, is a strong plus. Governance & Reporting • Prepare compliance reports and dashboards for management review. • Ensure timely completion of SOx testing cycles and documentation updates. • Support risk assessments and contribute to strengthening the overall control environment. Collaboration & Communication • Work closely with IT, Finance, and Compliance teams to align SOx requirements with business processes. • Act as a point of contact for external auditors and internal stakeholders. • Provide training and guidance on SOx compliance and control documentation standards.

Skills/Experience • Experience in SOx compliance, auditing, and governance processes. • Strong knowledge of Entity-Level Controls (ELCs), ITGCs, and SOx documentation standards. • Experience with ISO 27001 and NIST CSF, including security controls, risk assessment, and compliance. • Familiarity with CE+ and Vanta or similar GRC/compliance platforms is a strong plus. • Ability to create and maintain narratives, process flows, and control matrices. • Excellent communication and stakeholder management skills. • Detail-oriented with strong analytical and problem-solving capabilities. Why Join Us? • Opportunity to play a critical role in compliance and governance initiatives. • Collaborative team environment with exposure to senior leadership and external auditors. • Professional growth in a dynamic, fast-paced environment.

Additional benefits • Health Insurance • Referral Bonus • Performance Bonus • Flexible Working options

Location and hours Bangalore Office / UK hours

Read less


Read more
Bengaluru (Bangalore), Hyderabad, Pune, Kolkata, Chennai, Mumbai
1 - 10 yrs
₹4L - ₹30L / yr
Security Information and Event Management (SIEM)
Cyber Security
Burp suite
Metasploit
Network Security

We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.


Responsibilities

  • Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
  • Monitor and respond to security events using SIEM tools as part of SOC operations
  • Test application security using Burp Suite and similar tools
  • Support ISO 27001 compliance, audits and security policies
  • Harden network infrastructure, firewalls and access controls
  • Document findings and track fixes with engineering teams


Requirements

  • 1+ years of experience in VAPT, SOC or security engineering
  • Hands-on experience with Burp Suite and SIEM tools
  • Knowledge of the OWASP Top 10 and network security fundamentals
  • Exposure to ISO 27001 or similar frameworks
  • Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Read more
One of our US based Client
One of our US based Client
Agency job
via HyrHub by Shwetha Naik
Remote only
4 - 8 yrs
Best in industry
IT security
IT security audit
GDPR

The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.


 KEY RESPONSIBILITIES

 All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.

  • Performs daily health checks as documented by the IT Security team.
  • Supports the Security team by documenting and performing support tasks.
  • Participates in change management, incident management, audit and business continuity processes.
  • Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
  • Participates in internal and external compliance (SOC 2) audits.
  • Recommends security enhancements.

Job specifics:

  • Familiarity with standard security concepts, practices and procedures.
  • Knowledge of Windows operating systems.
  • Strong Documentation, communication skills and attention to detail.
  • Able to work independently and as a part of a team to deliver completed projects on-time.
  • Identifies ways to continuously improve own and/or company performance.
  • Knowledge of security toolsets
  • Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
  • Knowledge of database security.
  • Knowledge of SIEM technology and security event correlation and monitoring.
  • Experience with AWS.             
  • Proficient with computer software including Salesforce 


 EDUCATION & EXPERIENCE  

  • Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
  • Minimum of 3 years of hands-on IT Security & Audit experience.
  • Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.


Read more
Remote only
5 - 10 yrs
₹18L - ₹18L / yr
ServiceNow
GRC
skill iconJavascript
ACL

ServiceNow USEM Technical Consultant -(Offshore) Contract Role

· Location- Remote

· Contract- 6 months

Job Description

Position Description:  

The ServiceNow USEM (SecOps) Technical Consultant (Security Operations) is responsible to lead the design, development, and implementation of security operations (SecOps) solutions on the ServiceNow platform. This role is responsible for integrating security workflows, enhancing automation, and optimizing security response processes to ensure robust cybersecurity operations. 

Primary Responsibilities: 

Design, configure, and implement ServiceNow GRC/IRM modules, focusing on Policy, Compliance, and Risk Management frameworks. Develop custom solutions utilizing Flow Designer, Business Rules, Client Scripts, UI Actions, UI Policies, and Script Includes.

Configure Service Portal/Employee Center components, Service Catalog record producers, notifications, inbound email actions, and email-actionable approvals.

Manage Access Control Lists (ACLs) and role-based access designs alongside SLA definitions and task-based SLA behaviors.

Handle update set management and oversee code promotion across development, test, and production instances.

 


Requirements

Qualifications: 

· 5+ years hands-on ServiceNow development experience, with demonstrable delivery on client-facing implementation projects

· 2+ years working directly in ServiceNow GRC/IRM, specifically Policy and Compliance Management and/or Risk Management. Candidates whose GRC exposure is limited to a single mod

· Demonstrated experience with Flow Designer, business rules, client scripts, UI Actions, UI Policies, and script includes

· Experience configuring notifications and inbound email actions, including email-actionable approvals

· Experience with ACL configuration and understanding of role-based access design

· Experience with SLA definitions and task-based SLA behavior

· Experience with Service Catalog record producers and Employee Center / Service Portal configuration

· Proficiency with update set management and promotion across development, test, and production instances

· ServiceNow Certified System Administrator (CSA) required CIS Advanced Risk preferred 


· Work Experience: 5+ years

· Industry: Technology

 

Read more
Five exceptions Software Solution
Neha Daka
Posted by Neha Daka
Indore
4 - 8 yrs
₹3.5L - ₹10L / yr
ApplicationSecurity,Cybersecurity, DevSecOps,CI/CD
DAST
SAST
Cloud Computing

Job Title: AppSec / AI Security Engineer


Employment Type: Full-time/ Permanent

Location: Indore (Work from Office)


About the Role

We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.

If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.

 

Key Responsibilities

  • Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
  • Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
  • Develop structured code review workflows incorporating specifications, scan results, and code provenance.
  • Optimize security scanning tools to reduce false positives and drive developer adoption.
  • Investigate and manage security findings using established remediation and documentation processes.
  • Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
  • Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.


Required Skills & Experience

  • Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
  • Experience implementing automated security scanning and enforcement — not just operating existing tools.
  • Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
  • Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
  • Ability to design, build, and own security automation and governance solutions from the ground up.
  • Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
  • Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
  • Strong analytical mindset and ability to independently assess security risk across internal and external codebases.


Preferred Qualifications

  • ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
  • Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
  • Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
  • AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
  • Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
  • Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).


About Company:

Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.

 

For more info, please visit our website:  https://5exceptions.com

Read more
Risosu Consulting LLP
at Risosu Consulting LLP
1 candid answer
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos