Information Security & Compliance at Timble Technologies · Delhi, Gurugram, Noida, Ghaziabad, Faridabad · 0.6 - 4 years · ₹1L - ₹4L / yr · Raised funding · Posted 18 Mar 2026

Role Objective
We are looking for a proactive InfoSec Associate to support our compliance and audit functions. You will play a key role in maintaining our ISO standards, handling vendor security assessments, and ensuring our documentation is audit-ready for our banking and NBFC clients.
Key Responsibilities
- Audit Support: Assist in internal and external audits for ISO 27001, SOC2, and ISO 27701.
- Vendor Compliance: Independently handle and respond to detailed Vendor Security Questionnaires from banks and NBFCs.
- Evidence Management: Collect, organize, and present technical audit evidence from engineering and IT teams.
- Policy & Documentation: Help draft and review Security Policies, SOPs, and ISMS documentation.
- Risk Tracking: Track audit observations and manage the Corrective Action Plan (CAPA) to ensure timely remediation.
- Data Privacy: Assist in aligning internal processes with the DPDP Act and GDPR requirements.
Required Skills & Competencies
- Framework Knowledge: Basic understanding of ISO 27001 and Risk Assessment principles.
- Technical Literacy: Ability to understand AWS/Azure cloud security settings from a compliance standpoint.
- Documentation: High proficiency in organizing audit trails and drafting professional security reports.
- Communication: Comfortable interacting with external auditors and internal technical teams.
Preferred Certifications (Good to Have)
- ISO 27001 Internal Auditor
- CompTIA Security+
- CISA (In-progress/Foundation)

About Timble Technologies
About
Timble technology is the fastest growing IT company dealing in Artificial Intelligence, Speech Recognition, Facial Recognition, Cyber Security, Bespoke Solutions in Delhi. Timble technology is achieving success and getting more and more reputation in the field of IT
Connect with the team
Similar jobs (10)
The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.
KEY RESPONSIBILITIES
All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.
- Performs daily health checks as documented by the IT Security team.
- Supports the Security team by documenting and performing support tasks.
- Participates in change management, incident management, audit and business continuity processes.
- Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
- Participates in internal and external compliance (SOC 2) audits.
- Recommends security enhancements.
Job specifics:
- Familiarity with standard security concepts, practices and procedures.
- Knowledge of Windows operating systems.
- Strong Documentation, communication skills and attention to detail.
- Able to work independently and as a part of a team to deliver completed projects on-time.
- Identifies ways to continuously improve own and/or company performance.
- Knowledge of security toolsets
- Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
- Knowledge of database security.
- Knowledge of SIEM technology and security event correlation and monitoring.
- Experience with AWS.
- Proficient with computer software including Salesforce
EDUCATION & EXPERIENCE
- Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
- Minimum of 3 years of hands-on IT Security & Audit experience.
- Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.
Job title Sox Compliance Officer
Reporting to Potentiam company background (The Employer) Potentiam is a global provider of highly qualified professionals to European SMEs from our offices in Romania, South Africa and India. Potentiam works with clients in finance, energy, leisure, marketing, business services and technology industries, providing technical, professional multi- lingual highly motivated staff, most of whom have had experience of working for international companies. Staff cover a wide range of roles from accounting, marketing, data management, HR, sales/account management, engineering, technology, and operations. Potentiam manages our staff’s career development and personal development training, all infrastructure, HR and payroll with our clients directly managing day-to-day staff responsibilities and role training and development. Company website - https://potentiam.co.uk/
Potentiam’s client: It is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, document management and related services. It provide IME services through their medical panel of credentialed physicians and allied medical professionals. Their independent medical review process is fully contained within their private cloud network. Custom portals, applications, workflow enhancements and systems integration are part and parcel of their service. Their clients include property and casualty insurance carriers, law firms, third-party claim administrators and government agencies that use independent services to confirm the veracity of claims by sick or injured individuals under automotive, disability, liability and workers' compensation insurance coverages. They help clients in the U.S., Canada, the United Kingdom and Australia manage costs and enhance their risk management processes by verifying the validity of claims, identifying fraud and providing fast, efficient and quality IME services.
Industry: legal, insurance, and healthcare services.
Purpose of role:
We are seeking a Compliance Officer to join our compliance team. This role is responsible for auditing IT control activities, ensuring adherence to Sarbanes Oxley (SOx) requirements, and maintaining governance standards. The ideal candidate will work closely with external auditors, perform Entity-Level Controls (ELCs), and document narratives, processes, and procedures in a fast paced environment. Potentiam | Job Specification 2 of 2
Duties and responsibilities: Compliance & Audit Activities • Audit IT control operations performed by IT Controls Analysts to ensure compliance with SOx requirements. • Perform walkthroughs and testing of ITGCs and ELCs to validate control design and operating effectiveness. • Develop, maintain, and update SOx narratives, process flows, and control documentation. • Coordinate and liaise with external auditors during SOx audits and provide requested evidence. • Identify control gaps and recommend remediation plans in collaboration with stakeholders. • Experience with ISO 27001 and NIST CSF, including understanding of information security controls, risk management, control assessments, compliance requirements, and security governance practices. • Familiarity with Cyber Essentials Plus (CE+) and related security/compliance requirements, along with knowledge or experience using Vanta or similar GRC/compliance management platforms, is a strong plus. Governance & Reporting • Prepare compliance reports and dashboards for management review. • Ensure timely completion of SOx testing cycles and documentation updates. • Support risk assessments and contribute to strengthening the overall control environment. Collaboration & Communication • Work closely with IT, Finance, and Compliance teams to align SOx requirements with business processes. • Act as a point of contact for external auditors and internal stakeholders. • Provide training and guidance on SOx compliance and control documentation standards.
Skills/Experience • Experience in SOx compliance, auditing, and governance processes. • Strong knowledge of Entity-Level Controls (ELCs), ITGCs, and SOx documentation standards. • Experience with ISO 27001 and NIST CSF, including security controls, risk assessment, and compliance. • Familiarity with CE+ and Vanta or similar GRC/compliance platforms is a strong plus. • Ability to create and maintain narratives, process flows, and control matrices. • Excellent communication and stakeholder management skills. • Detail-oriented with strong analytical and problem-solving capabilities. Why Join Us? • Opportunity to play a critical role in compliance and governance initiatives. • Collaborative team environment with exposure to senior leadership and external auditors. • Professional growth in a dynamic, fast-paced environment.
Additional benefits • Health Insurance • Referral Bonus • Performance Bonus • Flexible Working options
Location and hours Bangalore Office / UK hours
Read less
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
IT Compliance Manager – Web3 & Digital Assets
📍 Location: Dubai, UAE
💼 Employment Type: Full-Time
🏢 Department: Technology / Compliance
📊 Experience: 5+ Years
🌐 Industry: FinTech / Web3 / Digital Assets
About the Role
We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.
The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.
Key Responsibilities
- Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
- Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
- Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
- Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
- Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
- Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
- Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
- Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
- Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
- Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.
Requirements
- Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
- 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
- Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
- Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
- Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
- Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
- Experience working with auditors, regulators, and cross-functional technology teams.
- Strong analytical, documentation, communication, and stakeholder-management skills.
UAE / Web3 Experience – Preferred
- Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
- Experience supporting VASP licensing or regulatory approvals.
- Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
- Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- CAMS
Key Skills
IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.
Job Title: AppSec / AI Security Engineer
Employment Type: Full-time/ Permanent
Location: Indore (Work from Office)
About the Role
We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.
If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.
Key Responsibilities
- Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
- Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
- Develop structured code review workflows incorporating specifications, scan results, and code provenance.
- Optimize security scanning tools to reduce false positives and drive developer adoption.
- Investigate and manage security findings using established remediation and documentation processes.
- Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
- Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.
Required Skills & Experience
- Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
- Experience implementing automated security scanning and enforcement — not just operating existing tools.
- Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
- Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
- Ability to design, build, and own security automation and governance solutions from the ground up.
- Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
- Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
- Strong analytical mindset and ability to independently assess security risk across internal and external codebases.
Preferred Qualifications
- ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
- Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
- Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
- AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
- Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
- Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).
About Company:
Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.
For more info, please visit our website: https://5exceptions.com
IT Systems Engineer
Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure
Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership
Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at
scale.
The Mission
About Metadome.ai
Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the
Metaverse Standards Forum and the VR/AR Association.
About the Role
We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.
This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.
Core Responsibilities
● Identity & Access Management — JumpCloud:
○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.
○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.
○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.
○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.
○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.
● Google Workspace Administration — GWS:
○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.
○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,
and sharing / visibility policies.○
○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.
Endpoint & Threat Protection — Sophos:
○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and
servers.
○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.
○ Maintain endpoint encryption, web / application control, and device-hardening standards.
○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.
Network, Firewall & Wi-Fi:
○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.
○ Administer enterprise Wi-Fi and wired networks (switches, access points), including
RADIUS-backed authentication.
○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.
○ Implement network monitoring, intrusion detection, and centralized logging.
Hardware, Software & Asset Management:
○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and
decommissioning.
○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.
○ Maintain an accurate hardware and software inventory and asset register.
○ Manage software deployment, patch management, and license compliance.
Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:
○ Operate and continuously improve the company's Information Security Management System
(ISMS).
○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control
implementation, evidence collection, and continuous monitoring.
○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA
assessments.
○ Serve as a primary point of contact during external audits and customer security reviews.
○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response
runbooks.
○ Drive security-awareness and phishing-simulation programs across the organization.
IT Operations & Support:
○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.
○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.
○ Manage backups, disaster recovery, and business-continuity testing.
○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within
budget.
○ Maintain documentation, runbooks, and standard operating procedures.
○ Own and report on the IT budget and asset allocation.
Required Skills & Experience
● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems
below rather than purely supervisory exposure.
● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.
● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.
● Sophos — hands-on endpoint / XDR administration and threat response.
● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.
● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one
full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.
Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.
System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.
Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.
Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.
Preferred Qualifications
●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.
●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.
●Scripting and automation for IT operations (Bash, PowerShell, or Python).
●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.
●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.
Why Join Us
You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running
flawlessly.
About the role
We’re hiring an IT Systems Administrator for an NBFC to secure endpoints, SaaS, and networks across ~50 branches, ~250+ field staff, and ~50+ office users.
This is primarily an IT Admin + Security role, with secondary exposure to AWS cloud ops + light DevOps + basic DB access management.
If you’re an IT Admin aiming to break into AWS Cloud Ops + DevOps, this role is a strong next step — you’ll own core IT/security and get hands-on exposure to cloud operations and deployments.
Key responsibilities (Primary: IT Admin + Security)
- Manage endpoint security for laptops and mobiles (policies, patching, encryption, antivirus/EDR); drive MDM implementation now/future (e.g., Intune/Jamf).
- Administer Google Workspace (Gmail/Drive/Calendar): users, groups, permissions, SSO, MFA, sharing controls.
- Own joiner–mover–leaver lifecycle: provisioning/deprovisioning, access controls, periodic access reviews.
- Secure branch connectivity: VPN, internal Wi-Fi, internet usage controls; coordinate troubleshooting and standardization across branches.
- Manage HO security stack: firewall operations, rule changes with change control, monitoring/log review (basic but consistent).
- Secure SaaS tools (CRM/HRMS/comms like Slack/Zoom): role-based access, MFA enforcement, offboarding, integration/OAuth controls.
- Maintain IT asset inventory: procurement coordination, issuance/return, audits, warranty/AMC, license renewals; remote lock/wipe for lost devices.
- Handle security incidents: phishing, account compromise, device loss/theft — contain, investigate, recover, and prevent recurrence.
- Run backups and basic DR testing; maintain SOPs/documentation and train staff on cyber hygiene.
- Provide hands-on user support: laptop builds, software installs, Outlook/Excel issues, VPN/Wi-Fi troubleshooting, escalations and vendor coordination.
Secondary responsibilities (AWS + DevOps + DB ops support)
- Support AWS administration: IAM users/roles/policies, MFA, access key hygiene, basic log review (e.g., CloudTrail).
- Manage AWS access controls: security groups/firewall rules, IP allowlists/whitelisting (admin tools, databases, vendor access).
- Assist engineering with DevOps operations:
- CI/CD support (deployment coordination, rollbacks, environment configuration)
- Secrets/credentials management and rotation (no shared creds)
- DNS + SSL/TLS certificates, basic monitoring/alerting coordination
- Bonus: Docker/Kubernetes and Terraform exposure
- Basic database operations (admin-lite):
- DB user creation, roles/permissions, least-privilege access
- IP allowlisting/whitelisting for DB access via VPN/approved sources
- Backup/restore verification coordination and basic monitoring signals (connections/storage)
Requirements
- 3+ years in IT security / systems administration (BFSI or branch-heavy org preferred).
- Hands-on with Google Workspace or Microsoft 365 administration.
- Must have hands-on experience leading or executing an email suite migration (e.g., Google Workspace ↔ Microsoft 365), including mailbox migration, DNS cutover, MX/SPF/DKIM/DMARC reconfiguration, and user transition management.
- Strong endpoint/security fundamentals: encryption, patching, AV/EDR, remote support, device compliance.
- Comfortable with networks: VPN/Wi-Fi/LAN troubleshooting; firewall basics and change discipline.
- Strong operational discipline: asset tracking, vendor management, documentation, ticketing, user communication.
- Practical AWS familiarity (IAM, access controls, logging) and ability to support DevOps workflows.
Nice to have
- Experience implementing MDM at scale (Intune/Jamf/SureMDM).
- Exposure to SOC2 / ISO27001 evidence, controls, and audit workflows.
- Scripting for automation (PowerShell/Bash/Python).
- Familiarity with managed databases and secure access patterns.
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product






