Cyber Security & Infrastructure Engineer
XO Health
IndiaremotePosted 19 days ago
Skill Required
Cybersecurity-EngineeringInfrastructure-EngineeringCloud-SecuritySecurity-OperationsCompliance-EngineeringInfrastructure-Security-EngineerSecurity-Infrastructure-EngineerNetwork-And-Infrastructure-EngineerCybersecurity-EngineerIT-Infrastructure-EngineerInfrastructure-EngineerNetwork-Infrastructure-EngineerSr.-Infrastructure-Security-EngineerCybersecurity-Systems-EngineerSystems-Infrastructure-EngineerInfrastructure EngineerSecurity EngineerCybersecuritysecurityPenetration TestingBackup and RecoverySOCIAMAzureCloud SecurityWindows Serverrelated fieldVMwareEngineeringnetworkingautomationShell ScriptingObservabilityTerraformdesigninganalyticsTestNGdesignISO 27001CloudSIEMAWSFulltime
Key highlights
- Salary: ₹2,000,000—₹2,500,000 INR
- Experience: 3-5+ years of cybersecurity and infrastructure engineering experience
- Work Location: Fully Remote
- Technical Requirement: 3+ years managing Microsoft Azure environments
- Technical Requirement: 2+ years administering Microsoft Sentinel or SIEM platforms
- Notable Requirement: Experience supporting SOC 2 Type II audits
Role overview
XO Health is the first health plan designed by and for self-insured employers that delivers a more unified health experience for everyone – from those who receive care, to those who deliver it, to those who pay for it. We are growing a multi-disciplinary team of diverse and digitally empowered employees ready to rebuild trust in healthcare through comprehensive and unified transformation. The Cybersecurity & Infrastructure Engineer is responsible for designing, implementing, monitoring, and securing the organization's hybrid cloud and infrastructure environments. This role serves as a technical leader for cybersecurity operations, cloud security, compliance initiatives, infrastructure engineering, and incident response.
Responsibilities
- Support organization's annual SOC 2 Type II audit program, including control design, evidence collection, remediation management, auditor coordination, and continuous compliance monitoring.
- Partner with business and technology stakeholders to ensure security, availability, confidentiality, and change management controls are effectively implemented and operating throughout the audit period.
- Drive successful completion of SOC 2 Type II examinations with minimal findings by maintaining an audit-ready environment, strengthening internal controls, and promoting a culture of security and compliance.
- Develop and maintain policies, procedures, risk assessments, and control documentation necessary to support ongoing compliance and future audit readiness.
- Administer and optimize Microsoft Sentinel SIEM platform.
- Develop and maintain security monitoring, analytics rules, alerting, dashboards, and automation workflows.
- Investigate security incidents and coordinate containment, remediation, and recovery activities.
- Monitor and respond to threats identified through Microsoft Defender, Sentinel, AWS security services, and third-party platforms.
- Conduct threat hunting, vulnerability management, and security assessments.
- Lead incident response activities and coordinate forensic investigations as needed.
- Maintain security documentation, playbooks, and response procedures.
- Support penetration testing, tabletop exercises, and disaster recovery testing.
- Design and maintain secure Microsoft Azure environments (Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), Defender for Cloud, Azure Security Center, Microsoft Purview).
- Design and maintain secure AWS environments (IAM, CloudTrail, GuardDuty, Security Hub, Config, CloudWatch).
- Implement zero-trust security principles across cloud platforms.
- Infrastructure Engineering for Microsoft Azure, AWS, Active Directory, Microsoft Entra ID, Windows Server, Virtualization platforms, Microsoft 365, and Network and security appliances.
- Design and implement high-availability and disaster recovery solutions.
- Manage identity lifecycle and privileged access controls.
- Support cloud migrations and infrastructure modernization initiatives.
- Lead technical compliance activities supporting SOC 2 Type II audits.
- Collaborate with external auditors and internal stakeholders during audit engagements.
- Develop, maintain, and document security controls and evidence repositories.
- Perform periodic access reviews, risk assessments, and control testing.
- Recommend remediation activities to address audit findings and security gaps.
- Support regulatory and contractual security requirements.
- Improve security operations through automated detection, response, and reporting using PowerShell, Azure Automation, Logic Apps, and Sentinel SOAR capabilities.
- Create executive and operational cybersecurity metrics and dashboards.
Requirements
- 3-5+ years of cybersecurity and infrastructure engineering experience.
- 3+ years managing Microsoft Azure environments.
- 2+ years administering Microsoft Sentinel or comparable SIEM platforms.
- Experience supporting SOC 2 Type II audits.
- Experience securing AWS cloud environments.
- Experience with incident response and vulnerability management.
- Experience with Microsoft 365 security technologies.
- Technical Skill: Microsoft Azure
- Technical Skill: Microsoft Sentinel
- Technical Skill: Microsoft Defender Suite
- Technical Skill: Microsoft Entra ID (Azure AD)
- Technical Skill: Active Directory
- Technical Skill: Microsoft 365 Security
- Technical Skill: AWS Security Services
- Technical Skill: PowerShell scripting
- Technical Skill: Vulnerability Management Platforms
- Technical Skill: Incident Response Procedures
- Technical Skill: Security Monitoring and SIEM Operations
- Technical Skill: Network Security Fundamentals
- Technical Skill: Firewall Administration
Nice to have
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field preferred.
- Technical Skill: Microsoft Purview
- Technical Skill: Microsoft Defender XDR
- Technical Skill: Terraform
- Technical Skill: Infrastructure as Code
- Technical Skill: Intune
- Technical Skill: DLP Technologies
- Technical Skill: Security Automation and SOAR
- Technical Skill: Compliance Management Platforms
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Security Operations Analyst (SC-200)
- Microsoft Identity and Access Administrator (SC-300)
- Azure Security Engineer Associate (AZ-500)
- Azure Administrator Associate (AZ-104)
- AWS Certified Security Specialty
- CISSP
- CISM
- GIAC Certifications
- Security+
Benefits
- Fully Remote
- Full compensation packages are based on candidate experience and relevant certifications.
Additional details
- Job Title: CyberSecurity & Infrastructure Engineer - India (Remote)
- The position combines hands-on infrastructure administration with cybersecurity engineering responsibilities across Microsoft Azure, Microsoft Sentinel, Microsoft 365, Entra ID, AWS, networking, endpoints, and security platforms.
- Engineering plays a key role in maintaining compliance with SOC 2 Type II controls, improving cyber resilience, supporting audits, and advancing the organization's security maturity.
- Success Metric: Successful completion of annual SOC 2 Type II audits.
- Success Metric: Reduction in security incidents and mean time to respond (MTTR).
- Success Metric: Increased security automation and operational efficiency.
- Success Metric: Improved vulnerability remediation timelines.
- Success Metric: Successful implementation and optimization of Microsoft Sentinel.
- Success Metric: Cloud security posture improvements across Azure and AWS.
- Success Metric: Completion of disaster recovery exercises and security testing initiatives.
- Success Metric: Consistent compliance with security policies and regulatory requirements.
- Participation in an on-call rotation for security incidents and critical infrastructure support.
- This position is ideal for a hands-on engineer who enjoys both infrastructure modernization and cybersecurity leadership while helping drive a mature, audit-ready security program.
- Salary: ₹2,000,000—₹2,500,000 INR
- XO Health is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law.
- XO Health promotes a drug-free workplace.
- Originally posted on Himalayas