India (Remote) Remote (Global) Full-time INR 2,000,000 – 2,500,000 / year

XO Health Inc. is hiring a Cyber Security & Infrastructure Engineer

Responsibilities

  • Support organization's annual SOC 2 Type II audit program, including control design, evidence collection, remediation management, auditor coordination, and continuous compliance monitoring.
  • Partner with business and technology stakeholders to ensure security, availability, confidentiality, and change management controls are effectively implemented and operating throughout the audit period.
  • Drive successful completion of SOC 2 Type II examinations with minimal findings by maintaining an audit-ready environment, strengthening internal controls, and promoting a culture of security and compliance.
  • Develop and maintain policies, procedures, risk assessments, and control documentation necessary to support ongoing compliance and future audit readiness.
  • Administer and optimize Microsoft Sentinel SIEM platform.
  • Develop and maintain security monitoring, analytics rules, alerting, dashboards, and automation workflows.
  • Investigate security incidents and coordinate containment, remediation, and recovery activities.
  • Monitor and respond to threats identified through Microsoft Defender, Sentinel, AWS security services, and third-party platforms.
  • Conduct threat hunting, vulnerability management, and security assessments.
  • Lead incident response activities and coordinate forensic investigations as needed.
  • Maintain security documentation, playbooks, and response procedures.
  • Support penetration testing, tabletop exercises, and disaster recovery testing.
  • Design and maintain secure Microsoft Azure environments.
  • Implement Azure security best practices utilizing: Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), Defender for Cloud, Azure Security Center, Microsoft Purview.
  • Secure AWS cloud environments including: IAM, CloudTrail, GuardDuty, Security Hub, Config, CloudWatch.
  • Implement zero-trust security principles across cloud platforms.
  • Maintain and support hybrid infrastructure environments including: Microsoft Azure, AWS, Active Directory, Microsoft Entra ID, Windows Server, Virtualization platforms, Microsoft 365, Network and security appliances.
  • Design and implement high-availability and disaster recovery solutions.
  • Manage identity lifecycle and privileged access controls.
  • Support cloud migrations and infrastructure modernization initiatives.
  • Lead technical compliance activities supporting SOC 2 Type II audits.
  • Collaborate with external auditors and internal stakeholders during audit engagements.
  • Develop, maintain, and document security controls and evidence repositories.
  • Perform periodic access reviews, risk assessments, and control testing.
  • Recommend remediation activities to address audit findings and security gaps.
  • Support regulatory and contractual security requirements.
  • Develop automation using: PowerShell, Azure Automation, Logic Apps, Sentinel SOAR capabilities.
  • Improve security operations through automated detection, response, and reporting.
  • Create executive and operational cybersecurity metrics and dashboards.

Requirements

  • 3-5+ years of cybersecurity and infrastructure engineering experience.
  • 3+ years managing Microsoft Azure environments.
  • 2+ years administering Microsoft Sentinel or comparable SIEM platforms.
  • Experience supporting SOC 2 Type II audits.
  • Experience securing AWS cloud environments.
  • Experience with incident response and vulnerability management.
  • Experience with Microsoft 365 security technologies.
  • Microsoft Azure
  • Microsoft Sentinel
  • Microsoft Defender Suite
  • Microsoft Entra ID (Azure AD)
  • Active Directory
  • Microsoft 365 Security
  • AWS Security Services
  • PowerShell scripting
  • Vulnerability Management Platforms
  • Incident Response Procedures
  • Security Monitoring and SIEM Operations
  • Network Security Fundamentals
  • Firewall Administration

Nice to Have

  • Microsoft Purview
  • Microsoft Defender XDR
  • Terraform
  • Infrastructure as Code
  • Intune
  • DLP Technologies
  • Security Automation and SOAR
  • Compliance Management Platforms
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • Microsoft Security Operations Analyst (SC-200)
  • Microsoft Identity and Access Administrator (SC-300)
  • Azure Security Engineer Associate (AZ-500)
  • Azure Administrator Associate (AZ-104)
  • AWS Certified Security Specialty
  • CISSP
  • CISM
  • GIAC Certifications
  • Security+

Work Arrangement

Remote (Worldwide) — India

Additional Information

  • Fully Remote
  • Participation in an on-call rotation for security incidents and critical infrastructure support.
Required Skills
Incident Response
Job Details
Location India (Remote)
Work mode Remote (Global)
Employment Full-time
Salary INR 2,000,000 – 2,500,000 / year
Category DevOps & SRE
Posted 10 days ago
or drop your CV first
About company
XO Health Inc. logo
XO Health is the first health plan designed by and for self-insured employers that delivers a more unified health experience for everyone – from those who receive care, to those who deliver it, to those who pay for it.
All jobs at XO Health Inc. Visit website