VI
Security & Compliance Analyst
VARITE INDIA PRIVATE LIMITED
- ๐ฎ๐ณ India
- On-site
- 10 months ago
- Incident Response
- Microsoft Defender
- Microsoft Sentinel
- triage
- Azure
- Incident Management
- ISO 27001
- NIST
- Microsoft Purview
- Defender
- Risk Management
- RBAC
- Zero Trust
- App Services
- Key Vault
- Conditional Access
- Identity Management
- Network Security
- Devops
- Purview
- CISSP
10 months ago
About The Client:
Client is a pioneering Software Engineering and IT consultancy company, transforming and executing at the intersection of Domain and Technology to create digital leaders for our people, clients, partners, and communities.
Essential Job Functions:
Security Monitoring, Incident Response & Mitigation
- Continuously monitor Microsoft Defender for Cloud and Microsoft Sentinel for threats and anomalies.
- Investigate, triage, and mitigate security incidents across Azure workloads, ensuring adherence to UAE NESA Incident Management controls (IM-xx series).
- Develop and maintain Sentinel analytic rules, automation playbooks, and incident response runbooks.
- Implement preventive and corrective actions to reduce recurring risks and vulnerabilities.
Compliance & Regulatory Alignment
- Ensure Azure resources comply with UAE NESA IA Standards, ADHICS, and global frameworks (ISO 27001, NIST, CIS).
- Utilize Microsoft Purview Compliance Manager and Defender for Cloud dashboards to monitor compliance posture.
- Maintain audit-ready evidence, policy documentation, and reports for NESA and internal audits.
- Support compliance mapping between Azure controls and NESA IA domains (e.g., AC โ Access Control, RM โ Risk Management, IS โ Information Security).
Governance & Policy Enforcement
- Define and enforce Azure Policies, RBAC, and Blueprints aligned to NESA control requirements.
- Implement Zero Trust, least-privilege, and segregation of duties principles across Azure resources.
- Continuously review and remediate non-compliant configurations detected by Defender for Cloud or policy scans.
Risk Assessment & Security Posture Management
- Conduct periodic risk assessments in line with NESA Risk Management (RM-xx) guidelines.
- Identify, prioritize, and mitigate security risks related to infrastructure, identity, and network layers.
- Track risk treatment plans and report posture improvement metrics to management.
- Perform continuous improvement on Azure workloads to maintain a high compliance score.
Security Configuration & Hardening
- Implement security baselines for VMs, App Services, Storage Accounts, Databases, and Key Vaults.
- Secure secrets and credentials using Azure Key Vault and Managed Identities per NESA Data Protection (DP-xx) controls.
- Apply MFA, Conditional Access, and Privileged Identity Management (PIM) to protect administrative accounts.
- Ensure all services use private endpoints, encryption at rest and in transit, and NSG/Firewall policies aligned with NESA network security guidelines.
Collaboration & Advisory
- Partner with DevOps, Infrastructure, and Application teams to embed security-by-design and compliance-by-default in all Azure deployments.
- Review architecture and deployment designs for alignment with NESA IA and Microsoft Cloud Security Baseline controls.
- Provide recommendations, awareness training, and technical guidance on NESA-compliant cloud security practices.
Qualifications :
Required Skills & Qualifications:
- Experience Required: 3+ years in Cloud Security, Compliance, and Governance (preferably Azure)
- Strong knowledge of Azure security services (Microsoft Defender for Cloud, Sentinel, Purview,
- Key Vault, PIM).
- Familiarity with UAE NESA IA Standards, ADHICS, and global frameworks (ISO 27001, NIST,
- CIS).
- Hands-on experience with Azure Policy, RBAC, Blueprints, and Zero Trust principles.
- Proficiency in incident response, risk assessment, and compliance audits.
- Excellent communication and collaboration skills.
- Preferred Certifications:
- Microsoft Certified: Azure Security Engineer Associate
- ISO 27001 Lead Implementer or Auditor
- Certified Information Systems Security Professional (CISSP) or equivalent.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral:
| 0-2 years | INR 5,000 |
| 2-6 years | INR 7,500 |
| 6+ years | INR 10,000 |
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
Security & Compliance Analyst ยท VARITE INDIA PRIVATE LIMITED