Epoch International Enterprises Inc.
Website:
epoch-int.com
Job details:
Senior IT & Cybersecurity Engineer
Location: Epoch Tech (India), Bangalore
Department: Information Technology / Information Security
Reports To: IT Director / CISO / VP of Infrastructure
Job Type: Full-time
Position Overview
We are seeking an experienced Senior IT & Cybersecurity Engineer to architect, secure, and maintain our enterprise IT infrastructure. In this dual-impact role, you will be a key driver of our system reliability, security, and scalability, you will be responsible for ensuring high availability and performance while actively defending our organization against security threats. You will bridge the gap between traditional IT operations and modern cybersecurity practices—designing secure cloud architectures, managing threat detection systems, and enforcing zero-trust policies.
If you are a systems expert who views every architecture decision through a security lens and thrives on automating security workflows, we want to hear from you.
Key Responsibilities
Cybersecurity & Threat Management
• Security Architecture & Zero Trust: Design, enforce, and optimize Zero Trust Architecture across corporate network, endpoint, and cloud environments.
• Threat Detection & Incident Response (IR): Configure and monitor SIEM, EDR/MDR, and XDR platforms; lead Tier 3 incident response, forensics, and root-cause analyses for security events.
• Vulnerability & Patch Management: Own company-wide vulnerability scanning (e.g., Nessus, Qualys), prioritize remediation schedules, and automate system patching.
• Identity & Access Security (IAM): Oversee identity governance using Microsoft Entra ID, Okta, SAML/SSO, Privileged Access Management (PAM), and strict Least Privilege principles.
Infrastructure & Cloud Operations
• Design, deploy, and manage scalable enterprise systems, including hybrid cloud (AWS/Azure/GCP) and on-premise infrastructure.
• Oversee identity and access management systems (Active Directory, Microsoft Entra ID, Okta, SAML/SSO).
• Evaluate emerging technologies and propose architecture upgrades to drive operational efficiency.
• Design and maintain robust networking environments (VPNs, VLANs, firewalls, routers, switches, SD-WAN).
• Participate in vulnerability assessments, incident response, and disaster recovery planning/testing.
• Secure Cloud & Hybrid Systems: Architect and manage resilient systems across hybrid environments (AWS, OCI, Azure, M365, and on-prem infrastructure) following CIS Benchmarks and cloud security best practices.
• Network Defense: Administer firewalls (Palo Alto, Fortinet, Cisco), secure VPNs, SD-WAN, micro-segmentation, and intrusion prevention systems (IPS/IDS).
• Data Protection & Compliance: Implement DLP (Data Loss Prevention), full-disk encryption, and secure backup policies to support business continuity and regulatory frameworks (SOC 2, ISO 27001, HIPAA, or GDPR).
Automation, Governance & Leadership
• Security Automation: Build infrastructure-as-code and automated workflows (PowerShell, Python, Bash, Terraform) to handle threat remediation, onboarding/offboarding, and security compliance audits.
• Policy & Security Awareness: Help draft and enforce IT Security Policies (AUP, Incident Response Plans, Password Policies) and oversee technical controls for employee security awareness/phishing campaigns.
• Technical Escalation & Mentorship: Serve as the senior technical lead for escalated IT/Security incidents and mentor junior engineers on secure system administration practices.
Qualifications & Skills
Required Experience
• Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
• Experience: 6+ years in IT infrastructure engineering or system administration, with at least 3+ years dedicated to hands-on cybersecurity operations (SOC, threat hunting, or security engineering).
Technical Proficiencies
• Identity & Endpoint: Advanced expertise in Entra ID/Active Directory, Conditional Access, Intune/Jamf, and EDR platforms (CrowdStrike, Defender for Endpoint, SentinelOne).
• Security & Network Engineering: Deep knowledge of firewalls, VLANs, Zero Trust Network Access (ZTNA), DNS security, and TLS/PKI certificate management.
• Cloud Security: Hands-on experience securing Microsoft 365, Azure, or AWS environments (CSPM, GuardDuty, Defender for Cloud).
• Scripting & IaC: Proficiency in PowerShell or Python for automating security tasks and system checks.
Soft Skills
• Calm under pressure with a strong tactical mindset during security incidents.
• Strong communication skills—ability to articulate security risks and trade-offs to non-technical business leaders.
• Pragmatic mindset that balances tight security controls with employee usability and productivity.
Preferred Qualifications & Certifications
• Relevant Security Certifications: CISSP, CCSP, Certified Ethical Hacker (CEH), CompTIA Security+/CySA+, or GIAC certifications.
• Vendor Certifications: Microsoft Certified: Cybersecurity Architect Expert, AWS Certified Security - Specialty, or Palo Alto PCNSA/PCNSE.
• Compliance: Experience preparing IT systems for SOC 2 Type II or ISO 27001 audits.
Click on Apply to know more.