Posted today · be early
Information Security Engineer - India
Q4 Inc.
IndiaremotePosted 1 day ago
Skill Required
InfosecSecurity-ComplianceInformation-Security-EngineerCompliance-ManagementSecurity-OperationsIT-Security-EngineerInformation-Systems-Security-EngineerSecurity-EngineerInformation-Security-EngineeringIT-Security-EngineeringData-Security-EngineerCybersecurity-EngineerSecurity EngineersecurityPenetration TestingISO 27001TestNGRustandAIContract
Key highlights
- 2–5 years of professional experience in information security compliance.
- Proven track record with SOC 2 audit programs.
- Deep fluency in ISO 27001, SOC 2, and GDPR/DPIA frameworks.
- Hands‑on experience managing compliance programs and leading internal audits.
- Ability to execute client security questionnaires and due‑diligence requests.
- Preferred ISO 27001 Lead Auditor or Implementer certification.
Role overview
Step into a pivotal position as our Information Security Engineer where your expertise directly shapes our security posture, compliance standards, and market trust. You will own complex client due diligence, manage critical framework audits, and execute compliance strategy with precision from day one.
Responsibilities
- Execute client security questionnaire responses, due diligence requests, and policy updates on a daily and weekly basis to drive measurable business outcomes.
- Manage and optimize ISO 27001, SOC 2, and DPIA compliance frameworks utilizing our core documentation and security management tools.
- Partner closely with internal audit teams, external certification bodies, and penetration testing partners, ensuring clear alignment, robust service delivery, and strict adherence to SLAs.
- Translate complex data, technical security constraints, or compliance requirements into highly actionable strategies and audit evidence.
- Drive continuous operational excellence while navigating a high-velocity, resilient work environment.
Requirements
- 2–5 years of professional experience in information security compliance, with a proven track record of successfully navigating multiple recent audit programs (specifically SOC 2) and maintaining audit readiness. Demonstrated deep fluency in ISO 27001, SOC 2, and Data Privacy frameworks (GDPR/DPIA).
- 2–5 years of hands‑on experience managing compliance programs, leading internal audits, and responding to customer security questionnaires.
- Advanced, day‑one capability utilizing vulnerability management tracking tools, penetration testing remediation systems, and compliance management platforms.
- Exceptional executive storytelling; proven ability to articulate security controls, ROI, and compliance documentation to external clients, enterprise stakeholders, and audit bodies.
Nice to have
- ISO 27001 Lead Auditor or Implementer certification.
- Experience with automated compliance tools (such as Vanta, Drata, or Secureframe).
Additional details
- At Q4, we make an impact together, obsess over our customers, operate with integrity, and bring big ideas to life.
- Q4 is charting a bold new path for investor relations as the first AI-driven IR Ops Platform, providing everything an IR team needs to succeed on a single, powerful platform.
- Over 2,600 customers, including many of the most respected brands in the world, trust Q4 to help drive premium valuations for their companies.
- We hire smart, curious, and talented people to push boundaries, reimagine what’s possible, and turn challenges into opportunities.
- We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.
- Originally posted on Himalayas.