Description review

Information Security Engineer - India

Q4 Inc. · India · back to the listing

HR standards

59/100

needs work

Title ↔ description

70/100

solid

Reads as

Security Engineer

98% confident

What this role officially is

ICT security administrator — ESCO, the EU occupation classification

ICT security administrators plan and carry out security measures to protect information and data from unauthorised access, deliberate attack, theft and corruption.

Also known as: network security administrator, system security administrator, ICT security administrators, IT security administrator

How others title the same work

Large employers

  • Security Risk Management Specialist Canonical Ltd.
  • Security Software Engineer Canonical Ltd.
  • Senior Security Operations Engineer Canonical Ltd.
  • Staff Security Operations Engineer Canonical Ltd.
  • Ubuntu Security Engineer Canonical Ltd.

Startups

  • Security Engineer (Bangalore, India) AiPrise
  • Security & Trust Engineer Alex
  • Elucid | Senior Security Engineer | Boston, MA | ONSITE (hybrid) | $130k–$170k Elucid
  • Factory | Security Engineer | ONSITE, San Francisco, CA | Full-Time Factory
  • Factory | Security Engineer | Onsite in San Francisco | Full-time Factory

What the listing never says

  • No pay range published. Candidates cannot tell whether applying is worth their time. Pay transparency
  • No location or timezone policy stated, so a candidate cannot tell where they may work from. Scope clarity

The listing, marked up

Nothing in the wording of this listing tripped a check. The scores above still judge how complete and coherent it is.

At Q4, we make an impact together, obsess over our customers, operate with integrity, and bring big ideas to life.

Q4 is charting a bold new path for investor relations as the first AI-driven IR Ops Platform, providing everything an IR team needs to succeed on a single, powerful platform. The Q4 Platform enables public companies to attract, manage, and understand investors - all in one place. Over 2,600 customers, including many of the most respected brands in the world, trust Q4 to help drive premium valuations for their companies. Only Q4 offers a tech stack holistically designed to equip IR teams with data, insights, and smart workflows that power remarkable outcomes. Learn more at .

We hire smart, curious, and talented people to push boundaries, reimagine what’s possible, and turn challenges into opportunities. All while keeping the needs of our clients at the heart of everything we do.

Come grow with us!

The Role:Information Security Engineer

Step into a pivotal position as our Information Security Engineer where your expertise directly shapes our security posture, compliance standards, and market trust. You will own complex client due diligence, manage critical framework audits, and execute compliance strategy with precision from day one. If you are looking to bring deep, practical mastery of security operations to a high-velocity team, this is where you can make an immediate impact.

Responsibilities

• Execute client security questionnaire responses, due diligence requests, and policy updates on a daily and weekly basis to drive measurable business outcomes.

• Manage and optimize ISO 27001, SOC 2, and DPIA compliance frameworks utilizing our core documentation and security management tools.

• Partner closely with internal audit teams, external certification bodies, and penetration testing partners, ensuring clear alignment, robust service delivery, and strict adherence to SLAs.

• Translate complex data, technical security constraints, or compliance requirements into highly actionable strategies and audit evidence.

• Drive continuous operational excellence while navigating a high-velocity, resilient work environment.

Required Skills & Qualifications

•
Domain Expertise: 2–5 years of professional experience in information security compliance, with a proven track record of successfully navigating multiple recent audit programs (specifically SOC 2) and maintaining audit readiness. Demonstrated deep fluency in ISO 27001, SOC 2, and Data Privacy frameworks (GDPR/DPIA).

•
Program Management: 2–5 years of hands-on experience managing compliance programs, leading internal audits, and responding to customer security questionnaires.

•
Tech Stack Mastery: Advanced, day-one capability utilizing vulnerability management tracking tools, penetration testing remediation systems, and compliance management platforms. ISO 27001 Lead Auditor or Implementer certification preferred. Experience with automated compliance tools (such as Vanta, Drata, or Secureframe) is a nice-to-have.

•
Communication: Exceptional executive storytelling; proven ability to articulate security controls, ROI, and compliance documentation to external clients, enterprise stakeholders, and audit bodies.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Originally posted on Himalayas

How this was produced

Highlights are found by rule, not by a model: each one is a phrase matched at a known position, and every note is a template we wrote. The two scores come from a typed-decision model (Jev) that reads the listing against the official role definition and real listings for the same role, and returns probabilities rather than prose — it never writes any of the words on this page, and never chooses what to highlight.

Deterministic penalty applied to the HR score: 8 points (from 67 before penalties). Reviewed 21 Sep 2026.