
Cybersecurity and Data privacy Engineer - RegTech
About the role
As a Cybersecurity and Data Privacy Engineer, you will help design and validate security and privacy controls for a cloud-native enterprise platform used in regulated business workflows.
You will work with architects, DevOps, engineering, product and QA teams to build security, access control, privacy and client-trust requirements into the platform from the start.
-
Define and review security requirements across authentication, authorization, RBAC, tenant isolation, encryption, secrets management, API security and secure deployment.
-
Design and validate data privacy controls for sensitive data, PII handling, retention, masking, deletion, access logging and secure data movement.
-
Support threat modeling, secure architecture review, security test planning, vulnerability management and remediation tracking.
-
Work with DevOps teams to implement security controls around cloud configuration, Key Vault, managed identities, private networking, security monitoring and policy guardrails.
-
Review application security patterns including input validation, access control, session handling, secure logging, audit events and data leakage prevention.
-
Support readiness for external certifications and client security reviews such as SOC 2, ISO 27001, ISO 27701, ISO 42001, SOC 1 and CSA STAR where applicable.
-
Contribute to security documentation, control mappings, privacy impact inputs, security questionnaires and audit evidence.
-
Partner with AI engineers to design AI usage controls, prompt/data privacy rules, AI output logging and responsible AI guardrails.
-
Minimum 7 years of experience in cybersecurity, application security, cloud security, data privacy, security engineering or risk/control roles.
-
Strong understanding of IAM, RBAC, encryption, secrets management, API security, secure SDLC, vulnerability management and cloud security controls.
-
Experience with Azure or other cloud security services, including identity, Key Vault, logging, monitoring, private networking and security posture management.
-
Understanding of privacy principles including PII handling, minimization, retention, masking, access control and data transfer controls.
-
Experience conducting or supporting security reviews, threat modeling, penetration test remediation, vulnerability triage and control validation.
-
Ability to work with engineering teams to convert security requirements into practical implementation guidance.
-
Strong documentation skills for security controls, risks, remediation plans and audit/client-review evidence.
Education: Bachelor of Engineering
- Preferred skills: Foundational->Cybersecurity Competency Development->Cyber Workforce Skill Development & Position Qualification Standards,Foundational ->Data privacy->Privacy by design,Technology->Application Security->Application Security
- ALL,Technology->Infrastructure Security->Cloud Security
About Infosys
BANGALORE
Headquarters