IT Security & Compliance Engineer
Rapyuta Robotics - Chennai, Tamil Nadu, India - In-office - posted 2026-09-17
Apply on the company site
SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Rapyuta Robotics is seeking an experienced IT Security & Compliance Engineer to lead the organization's cybersecurity operations, cloud security, compliance initiatives, and security governance. The role combines hands-on security operations with strategic compliance enablement across the enterprise.
Key Responsibilities:
Security Operations & Incident Response: Monitor, investigate, and respond to security incidents, threats, malware, phishing, and ransomware attacks through Security Operations Center (SOC) activities. Perform incident response, root cause analysis, and threat hunting.
Compliance & Governance: Lead security compliance enablement aligned with ISO 27001 (already established; focus on organization-wide enablement) and NIST Cybersecurity Framework (currently in progress). Conduct risk assessments, internal audits, policy management, vendor security reviews, and security awareness programs.
Microsoft 365 Security: Administer and secure Microsoft 365 environments, including Microsoft Entra ID, Conditional Access, MFA, Microsoft Defender, Purview, DLP, email security, and audit monitoring.
Endpoint & Infrastructure Security: Manage endpoint security solutions, EDR platforms, device compliance, encryption, and vulnerability remediation. Implement and maintain network security controls including firewalls, VPNs, IDS/IPS, DNS security, and network segmentation.
Vulnerability Management: Conduct vulnerability assessments, coordinate penetration testing, manage patching, and track remediation activities.
Identity & Access Management: Manage IAM including RBAC, privileged access management, user lifecycle management, and periodic access reviews.
Security Architecture & DevSecOps: Perform security architecture reviews, application security assessments, cloud security reviews, secure configuration management, and support DevSecOps initiatives.
Documentation & Continuous Improvement: Maintain security documentation, risk registers, and ensure continuous improvement of the organization's security posture.
Requirements:
Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
Security Operations: Incident response & root cause analysis, threat hunting, SIEM monitoring, malware & phishing response.
Microsoft 365 Security: Microsoft Entra ID (Azure AD), Conditional Access & MFA, Microsoft Defender Suite, Microsoft Purview, Data Loss Prevention (DLP), Exchange Online Security, Secure Score Management.
Endpoint & Infrastructure Security: Microsoft Defender/CrowdStrike, Endpoint Detection & Response (EDR), BitLocker/FileVault, patch & vulnerability management.
Compliance & Governance: ISO 27001, NIST Cybersecurity Framework, risk management, internal & external audits, security policies & awareness, vendor risk assessment.
Identity & Access Management: RBAC, Privileged Access Management (PAM), access reviews, Joiner-Mover-Leaver (JML) process.
Security Engineering: Secure SDLC, security architecture reviews, cloud security assessments, secure configuration management, DevSecOps support.
SIEM Platforms: Microsoft Sentinel, Splunk, IBM QRadar, LogRhythm, Elastic SIEM.
Vulnerability Management Tools: Qualys, Nessus, Rapid7 InsightVM, OpenVAS.
Email Security: Exchange Online, Microsoft Defender for Office 365, SPF, DKIM, DMARC, anti-phishing policies.
Security Assessment Tools: Nmap, Wireshark, Burp Suite, OWASP ZAP, Metasploit.
Preferred Certifications: ISO 27001 Lead Implementer/Lead Auditor, Microsoft Certified: Cybersecurity Architect Expert/Security Administrator, CompTIA Security+, CISSP, CEH, SC-200, SC-300, AZ-500.