
Principal Security Engineer
- India
- Permanent
- Full-time
- Build and manage a Security Controls framework that encompasses the regulatory and industry compliance frameworks we comply with.
- Perform detailed analysis and review of information security controls, as well as targeted gap assessments to identify any deviations from the framework.
- Propose and manage enterprise-wide security campaigns for managing deviations to reduce risk.
- Partner with other InfoSec and Engineering teams to define and prioritise security initiatives and investments using a risk-based approach.
- Align risk management initiatives with applicable compliance regulations.
- 10+ years of experience in Information Security or related fields such as Software Development, System Administration, QA Engineer, IT Audit, etc.
- Minimum of 6+ years of progressive experience managing programs related to information security and information security audits.
- Experience with building unified security controls frameworks.
- Experience with managing audits utilizing compliance frameworks such as PCI DSS, NIST CSF, NIST 800-53, ISO, SOC-2 etc.
- Experience with Security Engineering concepts such as Threat modeling, architecture reviews, etc.
- Certifications such as PCI QSA/ ISA, CISA, CRISC, ISO Lead Assessor, CISSP, etc.
- Prior experience with system administration, scripting, and/or automation techniques.