Posted on: 18/05/2026
Description :
A valued client of Innoquest Consulting, specializing in Digital Marketing and IT operations, is looking for a System Administrator to be based in Pune.
Job Responsibilities :
- Develop, implement, and continuously manage the client's information security strategy, policies, and procedures, covering both technical controls and organizational practices
- Monitor the environment for security incidents, vulnerabilities, and anomalous activity; lead investigation and response efforts with clear escalation and documentation protocols
- Conduct regular security audits, penetration test reviews, and risk assessments to proactively identify and remediate gaps before they become incidents
- Own the patch and update management lifecycle, ensuring timely deployment of security patches across all endpoints, applications, and infrastructure components
- Manage and configure firewalls, endpoint antivirus, email security, and intrusion detection/prevention systems, ensuring all security tooling is current, tuned, and effective
- Lead threat intelligence review, staying current on emerging vulnerabilities and attack vectors relevant to a SaaS company handling business video communications data.
- Own the full lifecycle of the client's endpoint estate, including procurement coordination, configuration, deployment, and decommissioning of laptops and other endpoint devices in collaboration with Lenovo and Microsoft
- Define and maintain Standard Operating Environments (SOEs) for all endpoint devices, including OS baseline configurations, software deployment, and security hardening standards.
- Own the client's IT compliance posture, ensuring all systems, practices, and vendors meet requirements under relevant frameworks, including SOC 2 Type II, GDPR, CCPA, and HIPAA, where applicable
- Lead and manage SOC 2 audit preparation and coordination, working directly with external auditors, collecting and curating evidence, tracking remediation items, and maintaining audit readiness year-round
- Oversee the implementation and ongoing management of Vanta (or equivalent GRC tooling) for continuous compliance monitoring, control mapping, and evidence collection
- Develop, maintain, and enforce IT security policies, access control procedures, and acceptable use standards across the organization
- Design and deliver security awareness and IT compliance training programs for employees, ensuring a culture of security consciousness across the client's distributed team
- Prepare for and facilitate both internal and external compliance audits, serving as the primary IT point of contact throughout the audit lifecycle.
Skills and Qualification :
- 5- 7 years of hands-on experience in IT systems administration, information security, or a combined IT/security role, with demonstrated ownership of security and compliance in a fast-moving technology or SaaS environment.
- Direct, hands-on experience with SOC 2 Type II audit preparation and management, including evidence collection, control implementation, auditor coordination, and year-round readiness maintenance.
- Proficiency with MDM platforms, Hexnode strongly preferred; Jamf, Intune, or equivalent will be considered, including device policy configuration, enrolment management, and remote administration.
- Strong command of Google Workspace administration, user management, group policies, SSO configuration, security settings, and audit log review.
- Working proficiency with Microsoft 365 administration and Microsoft Defender, including endpoint security policy management, threat protection configuration, and alerting.
- Hands-on experience with GRC and compliance monitoring tools, Vanta, Drata, or equivalent, including control mapping, evidence management, and compliance dashboard oversight.
- Solid understanding of firewall management, network security principles, antivirus and EDR solutions, and intrusion detection/prevention systems, with the ability to manage and tune these tools independently.
- Practical knowledge of GDPR, CCPA, HIPAA, and their implications for a US-based SaaS company managing business communications data.
- Strong documentation and communication skills, able to write clear security policies, produce audit-ready evidence packages, and communicate risk clearly to non-technical stakeholders.
- Self-directed and proactive, comfortable operating as the sole IT/security resource for an organization, managing priorities independently and escalating appropriately
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1636791