Technical Program Manager at Recruitify · Remote only · 11 - 20 years · ₹1L - ₹24L / yr · Remote only · Posted 7 Oct 2025

Key Responsibilities:
Security Program & Project Delivery
· Lead the planning, execution, and delivery of security initiatives including vulnerability management programs, NAC implementation, SIEM integration, and incident response enhancements.
· Coordinate cross-functional security projects across IT, infrastructure, compliance, and executive stakeholders.
· Ensure alignment with security frameworks including NIST, ISO 27001, CIS Controls, MITRE ATT&CK, and regulatory standards like HIPAA and GDPR.
Technical Oversight & Reporting
· Act as the SME across multiple domains including cloud security (AWS, Azure, GCP), endpoint security (Crowdstrike, Symantec), and network security (Fortinet, NAC, IDS/IPS).
· Translate technical requirements into business-aligned roadmaps and timelines.
· Own the development of project documentation including scope, timelines, resource allocation, risk logs, and communications plans.
Vulnerability & Risk Management
· Collaborate with vulnerability and threat management teams to prioritize and drive remediation projects.
· Design and deliver reporting dashboards and metrics (KPIs/KRIs) for executive leadership.
· Support remediation planning from external assessments (e.g., Red/Purple Team, penetration testing).
Incident Response Coordination
· Partner with SOC and engineering teams to ensure effective execution of the Cyber Incident Response Plan (CIRP).
· Facilitate tabletop exercises, after-action reviews, and response drills aligned with NIST 2.0.
Vendor & Stakeholder Management
· Coordinate security vendor evaluations, POCs, onboarding, and performance reviews.
· Work with 3rd party consultants, auditors, and MDR service providers to ensure timely delivery of contracted services.
· Act as liaison between technical teams and leadership to manage expectations and ensure strategic alignment.
Continuous Improvement & Governance
· Maintain and update project governance structures to align with industry best practices.
· Champion continuous improvement by assessing and refining project methodologies, tools, and templates.
· Contribute to policy updates, compliance audits, and control gap remediation plans.
Required Skills & Qualifications:
· Bachelor’s degree in Cybersecurity, Information Technology, or related field.
· 8+ years of IT experience with a minimum of 3–5 years in a dedicated cybersecurity or InfoSec project management role.
· Proven success delivering complex, cross-functional security projects in manufacturing, healthcare, or enterprise environments.
· Strong understanding of cybersecurity domains including cloud security, endpoint protection, identity management, and threat detection.
· Familiarity with GRC processes, compliance audits, and risk frameworks (NIST, ISO, CIS, HIPAA, GDPR).
· Proficiency in project management tools (e.g., Jira, MS Project, Smartsheet) and reporting dashboards (e.g., Power BI, Tableau).
· Exceptional written and verbal communication skills, including executive-level presentation and documentation abilities.
Preferred Certifications:
· PMP, PRINCE2, or equivalent Project Management certification
· CISSP, CISM, or CISA (strongly preferred)
· Certified ScrumMaster (CSM) or other Agile experience a plus

About Recruitify
About
Company social profiles
Similar jobs (10)
A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.
Key Responsibilities
- Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
- Conduct vulnerability assessments, penetration testing, and risk analysis.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
- Collaborate with IT and business teams to integrate security into system architecture and processes.
- Lead incident response drills and disaster recovery planning.
- Provide guidance and mentorship to junior cybersecurity staff.
- Stay updated on emerging threats, tools, and technologies.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5–10 years of proven experience in cybersecurity engineering or related roles.
- Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
- Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
- Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.
Skills
- Advanced problem-solving and analytical skills.
- Strong communication and leadership abilities.
- Ability to manage complex projects and handle escalations effectively.
- Proactive mindset with adaptability to evolving cyber threats.
Job Summary
We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.
Key Responsibilities
- Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
- Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
- Review policies, procedures, controls, and audit evidence.
- Identify gaps, risks, observations, and recommend remediation.
- Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
- Support clients during certification, surveillance, and external audits.
- Conduct client meetings, interviews, and control walkthroughs.
- Coordinate evidence collection and remediation tracking.
- Develop and review information security policies and procedures.
- Stay updated with cybersecurity standards, regulations, and best practices.
Required Skills
- Strong understanding of Information Security, GRC, Risk & Compliance.
- Good knowledge of ISO 27001:2022 and SOC 2.
- Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
- Strong analytical, documentation, communication, and report-writing skills.
- Ability to independently manage client engagements.
Qualifications
- Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
- 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
- Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.
IT Compliance Manager – Web3 & Digital Assets
📍 Location: Dubai, UAE
💼 Employment Type: Full-Time
🏢 Department: Technology / Compliance
📊 Experience: 5+ Years
🌐 Industry: FinTech / Web3 / Digital Assets
About the Role
We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.
The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.
Key Responsibilities
- Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
- Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
- Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
- Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
- Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
- Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
- Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
- Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
- Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
- Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.
Requirements
- Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
- 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
- Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
- Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
- Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
- Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
- Experience working with auditors, regulators, and cross-functional technology teams.
- Strong analytical, documentation, communication, and stakeholder-management skills.
UAE / Web3 Experience – Preferred
- Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
- Experience supporting VASP licensing or regulatory approvals.
- Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
- Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- CAMS
Key Skills
IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management
The role primarily focuses on the administration and operational support of security platforms, with a heavy emphasis on Netskope.
You will:
- Administer and optimize security platforms including Netskope (CASB/SSE), CyberArk EPM, Mimecast, and others
- Monitor, analyze, and respond to security events generated by these platforms, ensuring timely triage and resolution
- Develop, tune, and maintain security policies (DLP, web controls, email security, endpoint privilege management) to reduce risk and false positives
- Lead troubleshooting and root cause analysis for security incidents and platform issues across endpoint, cloud, and email security domains
- Collaborate with engineering, IT, and business teams to implement security controls and drive remediation of identified risks
- Integrate security tools with ServiceNow for incident management, request workflows, and automated response actions
- Build and maintain operational dashboards and reporting for security posture, tool effectiveness, and KPIs
- Support onboarding of new applications, users, and use cases into Netskope, Mimecast, and CyberArk EPM
- Contribute to security architecture decisions and continuous improvement of tooling and processes
- Develop and maintain runbooks, standard operating procedures, and knowledge base documentation
You bring:
- Bachelor’s degree or 5+ years of equivalent experience in Cybersecurity or related field
- 7+ years of experience in security engineering or security operations roles
- Strong hands-on experience with Netskope (CASB/SSE), CyberArk EPM, and Mimecast administration and operations
- Experience integrating and operating workflows within ServiceNow (incident, change, and request management)
- Solid understanding of endpoint security, DLP, email security, and cloud security concepts
- Experience tuning security tools to reduce false positives and improve detection fidelity
- Familiarity with identity and access management concepts, including privilege management and least privilege principles
- Ability to analyze security events and translate findings into actionable remediation steps
- Strong cross-functional collaboration and communication skills
- Experience developing documentation, runbooks, and operational processes
- Ability to manage multiple priorities and operate effectively in a fast-paced environment
MUST HAVE: Netskope Subject Matter Expertise (SME)
- Netskope expertise is non-negotiable.
- Candidates must be capable of serving as effective platform administrators.
- Candidates should have a deep understanding of security policies within Netskope.
Responsibilities
The successful candidate will:
- Support Netskope as the primary platform.
- Administer and maintain security controls.
- Fine-tune DLP policies.
- Investigate access-related platform issues.
- Support ticket resolution related to Netskope.
- Work with feedback coming from the SOC team.
- Manage policy adjustments to reduce false positives.
Job Summary
Project Manager is responsible for planning, executing, monitoring, and successfully delivering technology projects within agreed scope, timeline, budget, and quality standards. The role requires close coordination with business stakeholders, technical teams and senior management to ensure projects achieve their intended business outcomes.
Key Responsibilities
- Define project scope, objectives, deliverables, timelines, and success criteria.
- Develop and maintain detailed project plans, schedules, budgets, and resource requirements.
- Lead cross-functional teams including developers, infrastructure, QA, and business analysts.
- Coordinate release planning, sprint goals, release timelines, dependencies, and deployment activities.
- Manage project scope, risks, issues, dependencies, and change requests.
- Track project progress and provide regular status reports to stakeholders and management.
- Identify potential risks and implement appropriate mitigation and contingency plans.
- Coordinate requirements gathering and ensure alignment between business and technical teams.
- Facilitate project meetings, reviews and steering committee meetings.
- Ensure projects follow organizational IT governance, security, compliance, and quality standards.
- Coordinate testing, deployment, implementation, and transition to operational teams.
- Manage stakeholder expectations and resolve conflicts or escalated issues.
- Manage testing, deployment, documentation, and project closure.
- Conduct project closure activities and evaluate project performance and outcomes.
Required Qualifications
- Minimum 8 years of experience in IT project management or a related technology role.
- Proven experience managing end-to-end IT projects.
- Strong understanding of project management methodologies such as Agile, Scrum, Waterfall, or hybrid methodologies.
- Experience with project management tools such as Jira, Azure DevOps, Microsoft Project, Smartsheet, or similar platforms.
- Strong knowledge of software development lifecycle (SDLC), IT infrastructure, cloud technologies, or enterprise applications, depending on the project portfolio.
- Strong communication, leadership, organizational, and problem-solving skills.
Key Skills
- Project planning and execution
- Stakeholder management
- Risk and issue management
- Budget and resource management
- Agile/Scrum methodology
- Change management
- Team leadership
- Negotiation and conflict resolution
- Reporting and documentation
- Strategic thinking and problem solving
Require Experience : Minimum 8 years
Location : Indore -Onsite
Interview mode : Virtual
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles
2
Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,
3
Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.
4
Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.
5
Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.
6
Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.
7
Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.
8
Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.
About Nerve Solutions
Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.
We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.
About the Role
We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.
The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.
Roles & Responsibilities
- Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
- Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
- Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
- Set up user accounts, systems, and required software for new employees and support onboarding activities.
- Monitor network performance and employee network activities to ensure system security and compliance.
- Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
- Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
- Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
- Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
- Assist in implementing information security best practices, security audits, and compliance initiatives.
- Coordinate with internal teams to ensure IT services effectively support business operations.
- Stay updated with the latest cybersecurity threats, technologies, and industry best practices.
Required Skills
- 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
- Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
- Experience troubleshooting hardware, software, network, and user-related issues.
- Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
- Experience with Active Directory, user access management, and system administration.
- Familiarity with Microsoft 365 administration is an added advantage.
- Understanding of backup, disaster recovery, and IT asset management.
- Strong analytical and problem-solving skills with attention to detail.
- Good communication and documentation skills.
- Ability to work independently and collaboratively in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Information Technology, Computer Science, or a related field.
- Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.






