Information Security Engineer
HSP Group
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
222 open information roles across 105 companies are on ApplySarthi right now, most of them in Hyderabad (15), Bengaluru (14), Pune (7).
- Quantum Information Software Intern 2027IBM
- Italian Medical Information Customer Experience Specialist (Temporary 6M)Pfizer
- Sr. Program Manager, Information SecurityIntuitive
- Head of Information SecurityFiserv
- National Workforce Information RepresentativeJobgether
What information roles keep asking for: SaaS (18%), GCP (12%), Python (12%) — counted across their open postings here.
Azure jobs · IAM jobs · Kubernetes jobs · Observability jobs
HSP Group has 13 open roles listed here.
- Director of Sales
- Director of Sales
- Customer Success Associate 1
- Global Service Manager, HR Administration & Service Delivery
- Global Service Manager, HR Administration & Service Delivery
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for information roles keep coming back to SaaS, GCP, Python. Practise those questions before you sit with HSP Group.
Questions you are likely to be asked
- Why do you want to join HSP Group?
- What is your experience with SaaS? Tell me one thing you learned the hard way.
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Information Security Engineer at HSP Group interview free →HSP Group is the premier provider of global expansion services, helping companies simplify the complex challenges of operating internationally. We deliver a seamless experience across legal entity setup, global HR, payroll, compliance, tax, and advisory, enabling our clients to scale faster, stay compliant, and reduce risk in every market they enter.
With scale-up organizations and innovative technology firms expanding at unprecedented speed, HSP is uniquely positioned to become their trusted global partner.
Job Description
This is a remote role.
We are seeking a hands-on, mid-level Information Security Engineer to help protect our SaaS products, harden our cloud and endpoint environments, and mature our overall security program. This role sits at the intersection of technical security operations and governance. You will manage vulnerabilities across our products and infrastructure, contribute to corporate security policies, lead SOC 2 efforts, and serve as a key voice in customer and vendor security conversations.
Our entire technology stack runs in Microsoft Azure, and we leverage the broader Microsoft security ecosystem (Intune, Defender, Purview) alongside best-in-class tooling like Datadog, GitHub, and Snyk. You will work closely with Engineering, IT, Legal, and Product teams to drive measurable improvements to our security posture.
Responsibilities:
Vulnerability & Product Security- Lead the company’s SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit.
- Lead the vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.
- Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.
- Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
- Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
- Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.
- Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.
- Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.
- Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
- Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.
- Support vendor risk assessments and third-party security reviews.
- Assist with internal and external audits, evidence collection, and remediation of findings.
- Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.
- Contribute to security awareness training, phishing simulations, and a strong security culture across the company.
- Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.
Requirements:
- 4–6 years of professional experience in information security, application security, cloud security, or a closely related role.
- Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
- Hands-on experience securing SaaS applications and workloads running in Microsoft Azure.
- Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams.
- Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk.
- Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design.
- Experience writing or substantially contributing to security policies, standards, or procedures.
- Experience in responding to customer security questionnaires and supporting compliance efforts.
- Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders.
Nice to Have:
- Industry certifications such as CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent.
- Experience with container and Kubernetes security.
- Exposure to threat modeling, secure code review, or penetration testing.
- Prior experience in a SaaS company or regulated industry.
If you’re a driven individual who wants to make your mark in the heart of the innovation economy, we’d love to meet you. Join our #HSPGlobalSolutionTeam and help us power the next wave of global growth.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Director of Project ManagementHSP Group
- Director of Project ManagementHSP Group
- Director of Project ManagementHSP Group
- Global Service Manager, HR Administration & Service DeliveryHSP Group
- Global Service Manager, HR Administration & Service DeliveryHSP Group
- Information Security Engineer HSP Group
- Senior Global Service Associate - Legal Entity Management HSP Group
- Senior Global Service Associate - Legal Entity Management HSP Group
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-08-14. ApplySarthi collects openings and links to application pages; the role is advertised by HSP Group, not by us.