Principal Engineer- Info Sec
Job Description
Job description
Acuity Analytics (the trading name of Acuity Knowledge Partners) is a global, tech-first organisation helping financial institutions and corporates make better decisions through research, data, analytics and AI-enabled solutions. We combine deep financial services expertise with strong engineering, digital and AI capabilities to solve complex, real-world problems.
With a team of 7,200+ analysts, data specialists and technologists across 28 locations, we work with more than 800 organisations worldwide to drive efficiency, unlock insight and deliver measurable impact. Our success is built on the strength of our peopleby investing in talent, encouraging collaboration and creating room to grow, we enable our teams to do their best work for clients.
Acuity became an independent business in 2019 following its acquisition from Moodys Corporation by Equistone Partners Europe. In 2023, funds advised by global private equity firm Permira acquired a majority stake, with Equistone remaining a minority investorsupporting our continued growth and innovation.
For more information, visit www.acuityanalytics.com
Position Title-Information Security Specialist (Principal Engineer)
Experience Level-5-7 years
Department-Information Security
Location-Pune/Bengaluru
Job purpose
Perform hands-on cloud security assessments, security architecture reviews and technical risk evaluations for projects assigned to Information Security.
Support DLP implementation, policy refinement, incident review, exception handling and operational improvement of data protection controls.
Translate ISO 27001, SOC 2, CIS, CSA, NIST and internal security policy expectations into practical technical controls and project-level recommendations.
Act as a pragmatic technical risk evaluator who can identify material security risks, propose compensating controls and track remediation to closure.
Role Design and Expected Capability Mix
Capability Area
Primary Expectations
Indicative Weight
Technical Security
Cloud security assessment, secure architecture review, DLP implementation and tuning, Microsoft 365 / SaaS controls, IAM, logging, monitoring, vulnerability and configuration review.-70%
Standards and Process Alignment
Map findings and recommendations to ISO 27001, SOC 2, CIS, CSA, NIST, client requirements and internal security policies.-20%
Stakeholder Execution
Coordinate with project, IT, delivery and compliance teams to validate risks, agree action plans, support exceptions and drive closure.-10%
Key responsibilities
A. Cloud Security Assessment and Architecture Review
Review cloud and SaaS deployments across Azure, AWS, Microsoft 365 and other business platforms for secure configuration, identity, access, monitoring, logging, encryption, network segmentation and data protection controls.
Assess project architecture, application onboarding requests, infrastructure changes and cloud service usage from security, privacy, client contractual and operational risk perspectives.
Recommend pragmatic remediation actions, compensating controls and secure design improvements that can be implemented by engineering, IT operations or delivery teams.
Review IAM, privileged access, service accounts, conditional access, secrets handling, key management, storage security, backup, resilience and security baseline adherence.
Review and audit Security Operations Centre monitoring practices, including log-source coverage, detection use cases, alert logic, alert thresholds, triage procedures, escalation paths, incident hand-offs, evidence retention and closure tracking.
Assess Web Application Firewall controls and network firewall rules, including business justification, least-privilege alignment, exposed services, source and destination restrictions, ports and protocols, logging, alerting, periodic recertification, exceptions, and removal of obsolete or overly permissive rules.
Validate that relevant cloud, application, WAF, firewall, identity, endpoint and data-protection events are integrated with SOC monitoring and escalated in line with incident-management, risk and client requirements.
Review SOC performance and control effectiveness through sampling of alerts and incidents, detection coverage, response timelines, escalation quality, root-cause analysis, remediation evidence and closure records.
Support secure cloud governance by tracking deviations, exceptions, control gaps and remediation status across assigned engagements.
B. DLP Implementation, Refinement and Operations
Support implementation, refinement and day-to-day management of DLP policies across email, endpoint, cloud storage, SaaS platforms and collaboration tools as applicable.
Review DLP alerts, violations and policy matches to identify true risks, false positives, noisy rules and opportunities for policy tuning.
Work with business, delivery and technology teams to refine DLP rules, sensitivity labels, data handling controls and exception handling practices.
Document DLP risk decisions, recurring patterns, policy exceptions, false-positive rationale and corrective actions in the approved tracker or system of record.
Contribute to awareness and adoption by converting DLP observations into practical guidance for users and project teams.
C. Technical Risk Review and Policy Exception Management
Serve as the Information Security reviewer for assigned project engagements, technical change reviews, production onboarding, client delivery initiatives and risk assessments.
Evaluate security risks pragmatically by considering likelihood, impact, data sensitivity, client exposure, compensating controls, operational feasibility and implementation timelines.
Manage policy exceptions by validating business justification, risk exposure, compensating controls, expiry dates, accountable owner, approval status and periodic review requirements.
Track remediation actions and exception closure with project owners, IT operations, del
Never pay to get work. If a listing asks for a fee, it is a scam. The ten signs →