ApplySarthi

Sr. Information Security Engineer

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

248 open information roles across 99 companies are on ApplySarthi right now, most of them in Hyderabad (16), Bengaluru (12), Pune (6).

What information roles keep asking for: AWS (18%), Python (17%), SaaS (15%), GCP (15%), IAM (14%), Stakeholder management (14%), SIEM (12%) — counted across their open postings here.

AWS jobs · Ansible jobs · Azure jobs · CI/CD jobs

Jobgether has 4,220 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for information roles keep coming back to AWS, Python, SaaS, GCP. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with Serverless? Tell me one thing you learned the hard way.
  3. How do you keep secrets and access safe in your infrastructure?
  4. Walk me through how code gets from a commit to production where you work.
  5. Tell me about an outage you handled. What did you learn from it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Sr. Information Security Engineer at Jobgether interview free →

Accountabilities: Design, implement, and maintain secure architectures across AWS, Azure, and GCP, including infrastructure-as-code and policy-as-code security controls. Deploy and manage cloud security capabilities such as Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls. Operate CSPM/CNAPP platforms to identify cloud misconfigurations, exposed data stores, toxic combinations, and other security risks. Secure containerized and serverless environments, including EKS, ECS, Lambda, image scanning, admission controls, runtime protection, and least-privilege access. Establish strong network segmentation, encryption, centralized key management, secrets management, and secure workload configurations. Partner with AI and data teams to secure model development, training, fine-tuning, inference, and retrieval-augmented generation pipelines handling sensitive data. Apply AI security frameworks and threat-modeling practices to address prompt injection, data poisoning, model exfiltration, insecure outputs, excessive agency, and other AI-specific threats. Implement AI gateways, guardrails, content filtering, validation, rate limiting, and logging controls while supporting responsible enterprise use of generative AI. Evaluate third-party and foundation-model providers, including security controls, data residency, retention, contractual protections, and appropriate coverage for sensitive healthcare data. Secure the machine-learning supply chain through artifact provenance, signed models, dependency scanning, and hardened MLOps environments. Embed security into CI/CD pipelines through SAST, DAST, SCA, secrets scanning, infrastructure-as-code scanning, threat modeling, and secure design reviews. Protect APIs and machine-to-machine integrations using secure authorization standards such as OAuth 2.0, OIDC, mTLS, and scoped service tokens. Manage software supply-chain security, including SBOMs, dependency governance, artifact signing, penetration testing, vulnerability remediation, and bug-bounty processes. Strengthen PHI and PII protection through data classification, tokenization, de-identification, DLP, and appropriate access controls. Manage endpoint and identity security using EDR/XDR, Microsoft Entra ID, Conditional Access, privileged identity management, phishing-resistant MFA, and risk-based authentication. Govern service accounts, workload identities, service principals, AI agent credentials, and other non-human identities through least privilege and short-lived credentials. Monitor and investigate security alerts, coordinate incident response, and work with SOC and managed detection and response partners. Develop SIEM detection content, detection-as-code, log coverage, MITRE ATT&CK mappings, SOAR workflows, and automated response capabilities using Python and PowerShell. Develop incident response runbooks and forensic procedures covering both conventional cyber incidents and AI-specific scenarios such as model misuse, prompt-based data leakage, and compromised AI integrations. Participate in tabletop exercises, purple-team activities, post-incident reviews, and continuous security improvement initiatives. Support HIPAA, HITRUST, SOC 2 Type 2, and NIST-related audits, customer security assessments, evidence collection, risk registers, asset inventories, and remediation tracking. Conduct third-party and vendor risk reviews, with particular attention to AI subprocessors, sensitive-data flows, and emerging technology risks. Partner with compliance and other stakeholders to maintain alignment between technical controls, security policies, regulatory requirements, and responsible AI practices. Contribute to security awareness and training initiatives, including guidance on secure and responsible AI use. Requirements Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience. 5+ years of experience in security engineering or comparable technical security roles. Strong knowledge of cloud-native security across AWS, Azure, and GCP, along with modern SaaS architectures. Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, security automation, and incident response technologies. Practical experience securing containerized and serverless workloads such as EKS and Lambda. Familiarity with healthcare and security frameworks including HIPAA, HITRUST, NIST, and SOC 2. Experience with infrastructure-as-code security using technologies such as Terraform, Ansible, or CloudFormation is preferred. Experience integrating security into DevSecOps environments and CI/CD pipelines, including tools such as Jenkins or Bitbucket, is preferred. Strong scripting capabilities in Python, PowerShell, Bash, or similar languages. Experience with AI/LLM security, AI threat modeling, ML security, or securing AI-enabled applications is highly valuable. Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, GSEC, GCIA, or GCIH are preferred. Strong analytical, troubleshooting, and problem-solving capabilities with exceptional attention to detail. Ability to balance business objectives with appropriate risk mitigation and practical security controls. Excellent written and verbal communication skills, including the ability to explain complex technical and security concepts to non-technical stakeholders. Collaborative and proactive approach, with a demonstrated commitment to continuous improvement. Ability to operate effectively in a regulated healthcare technology environment and manage sensitive information responsibly. Benefits Annual salary range of $140,000–$160,000 , with compensation varying according to geographic market, job-related knowledge, skills, and experience. Remote work opportunity within the United States. Medical, dental, and vision insurance benefits. 401(k) matching. Generous paid time off program. Opportunity to work on advanced cloud, cybersecurity, healthcare, and AI security challenges. Environment focused on continuous professional and technical development. Equal opportunity workplace committed to an inclusive and respectful work environment.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-07. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.