Responsibilities
- Support organization's annual SOC 2 Type II audit program, including control design, evidence collection, remediation management, auditor coordination, and continuous compliance monitoring.
- Partner with business and technology stakeholders to ensure security, availability, confidentiality, and change management controls are effectively implemented and operating throughout the audit period.
- Drive successful completion of SOC 2 Type II examinations with minimal findings by maintaining an audit-ready environment, strengthening internal controls, and promoting a culture of security and compliance.
- Develop and maintain policies, procedures, risk assessments, and control documentation necessary to support ongoing compliance and future audit readiness.
- Administer and optimize Microsoft Sentinel SIEM platform.
- Develop and maintain security monitoring, analytics rules, alerting, dashboards, and automation workflows.
- Investigate security incidents and coordinate containment, remediation, and recovery activities.
- Monitor and respond to threats identified through Microsoft Defender, Sentinel, AWS security services, and third-party platforms.
- Conduct threat hunting, vulnerability management, and security assessments.
- Lead incident response activities and coordinate forensic investigations as needed.
- Maintain security documentation, playbooks, and response procedures.
- Support penetration testing, tabletop exercises, and disaster recovery testing.
- Design and maintain secure Microsoft Azure environments.
- Implement Azure security best practices utilizing: Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), Defender for Cloud, Azure Security Center, Microsoft Purview.
- Secure AWS cloud environments including: IAM, CloudTrail, GuardDuty, Security Hub, Config, CloudWatch.
- Implement zero-trust security principles across cloud platforms.
- Maintain and support hybrid infrastructure environments including: Microsoft Azure, AWS, Active Directory, Microsoft Entra ID, Windows Server, Virtualization platforms, Microsoft 365, Network and security appliances.
- Design and implement high-availability and disaster recovery solutions.
- Manage identity lifecycle and privileged access controls.
- Support cloud migrations and infrastructure modernization initiatives.
- Lead technical compliance activities supporting SOC 2 Type II audits.
- Collaborate with external auditors and internal stakeholders during audit engagements.
- Develop, maintain, and document security controls and evidence repositories.
- Perform periodic access reviews, risk assessments, and control testing.
- Recommend remediation activities to address audit findings and security gaps.
- Support regulatory and contractual security requirements.
- Develop automation using: PowerShell, Azure Automation, Logic Apps, Sentinel SOAR capabilities.
- Improve security operations through automated detection, response, and reporting.
- Create executive and operational cybersecurity metrics and dashboards.
Requirements
- 3-5+ years of cybersecurity and infrastructure engineering experience.
- 3+ years managing Microsoft Azure environments.
- 2+ years administering Microsoft Sentinel or comparable SIEM platforms.
- Experience supporting SOC 2 Type II audits.
- Experience securing AWS cloud environments.
- Experience with incident response and vulnerability management.
- Experience with Microsoft 365 security technologies.
- Microsoft Azure
- Microsoft Sentinel
- Microsoft Defender Suite
- Microsoft Entra ID (Azure AD)
- Active Directory
- Microsoft 365 Security
- AWS Security Services
- PowerShell scripting
- Vulnerability Management Platforms
- Incident Response Procedures
- Security Monitoring and SIEM Operations
- Network Security Fundamentals
- Firewall Administration
Nice to Have
- Microsoft Purview
- Microsoft Defender XDR
- Terraform
- Infrastructure as Code
- Intune
- DLP Technologies
- Security Automation and SOAR
- Compliance Management Platforms
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Security Operations Analyst (SC-200)
- Microsoft Identity and Access Administrator (SC-300)
- Azure Security Engineer Associate (AZ-500)
- Azure Administrator Associate (AZ-104)
- AWS Certified Security Specialty
- CISSP
- CISM
- GIAC Certifications
- Security+
Work Arrangement
Remote (Worldwide) — India
Additional Information
- Fully Remote
- Participation in an on-call rotation for security incidents and critical infrastructure support.