Apply with hirly
Cybersecurity and Data privacy Engineer - RegTech
Infosys · Bangalore, India
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
As a Cybersecurity and Data Privacy Engineer, you will help design and validate security and privacy controls for a cloud-native enterprise platform used in regulated business workflows. You will work with architects, DevOps, engineering, product and QA teams to build security, access control, privacy and client-trust requirements into the platform from the start. Responsibilities
- Define and review security requirements across authentication, authorization, RBAC, tenant isolation, encryption, secrets management, API security and secure deployment.
- Design and validate data privacy controls for sensitive data, PII handling, retention, masking, deletion, access logging and secure data movement.
- Support threat modeling, secure architecture review, security test planning, vulnerability management and remediation tracking.
- Work with DevOps teams to implement security controls around cloud configuration, Key Vault, managed identities, private networking, security monitoring and policy guardrails.
- Review application security patterns including input validation, access control, session handling, secure logging, audit events and data leakage prevention.
- Support readiness for external certifications and client security reviews such as SOC 2, ISO 27001, ISO 27701, ISO 42001, SOC 1 and
Csa Star
where applicable.
- Contribute to security documentation, control mappings, privacy impact inputs, security questionnaires and audit evidence.
- Partner with AI engineers to design AI usage controls, prompt/data privacy rules, AI output logging and responsible AI guardrails. Technical requirements
- Minimum 7 years of experience in cybersecurity, application security, cloud security, data privacy, security engineering or risk/control roles.
- Strong understanding of IAM, RBAC, encryption, secrets management, API security, secure SDLC, vulnerability management and cloud security controls.
- Experience with Azure or other cloud security services, including identity, Key Vault, logging, monitoring, private networking and security posture management.
- Understanding of privacy principles including PII handling, minimization, retention, masking, access control and data transfer controls.
- Experience conducting or supporting security reviews, threat modeling, penetration test remediation, vulnerability triage and control validation.
- Ability to work with engineering teams to convert security requirements into practical implementation guidance.
- Strong documentation skills for security controls, risks, remediation plans and audit/client-review evidence. Education Bachelor of Engineering