Verified today
Security Engineer - Risk and Policy Governance
About the role
Security Engineer focused on risk and policy governance, responsible for designing, implementing, and maintaining frameworks that align the organization’s information security posture with industry standards and regulatory requirements. Leads policy development, conducts risk assessments, ensures compliance with ISO 27001, NIST, GDPR, SOX, and manages risk registers. Collaborates across teams to embed governance into IT processes, supports audits, evaluates third‑party risks, drives security awareness, and reports on governance metrics.
What you’ll do
- Develop and enforce security policies, standards, and procedures.
- Conduct risk assessments and support mitigation planning.
- Ensure compliance with ISO 27001, NIST, GDPR, SOX.
- Maintain risk register and track control effectiveness.
- Collaborate with teams to integrate governance into IT processes.
- Support internal/external audits and provide security documentation.
- Evaluate third‑party security risks.
- Drive security awareness and contribute to governance reporting.
- Assess emerging technologies and threats.
What you’ll bring
- M.Tech/B.Tech or equivalent Bachelor's degree
- 5-10 years of experience in security engineering
Education
M.Tech/B.Tech or Equivalent Bachelor's Degree