← All verified jobs

IT Security Engineer

See all open roles at beghou consulting

Ghost-risk verdict

Some ghost-posting signals

  • open for 191 days (90+ without a fill is a strong ghost signal)
  • 88 open roles at this company in 30 days (mass-hiring blitz)
  • no salary disclosed (correlates with ghost postings)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

We'll trust you to:

SOC Audit & Compliance

Support SOC 2 (Type I & Type II) , Future ISO 27001 readiness, and internal security audits as they relate to SOC and IT operations.

Map security and SOC controls to applicable frameworks (AICPA Trust Services Criteria, ITGCs).

Coordinate and manage audit evidence collection from SOC, endpoint, identity, and infrastructure teams.

Perform control design and operating effectiveness reviews for SOC adjacent controls.

Track audit findings, risks, and remediation actions through closure.

Maintain continuous audit readiness rather than point-in-time compliance.

Vulnerability & Remediation Governance

Partner with IT and GRC to support vulnerability management oversight .

Review and validate vulnerability findings from Nessus scans.

Track remediation of SLAs, compensating controls, and risk exceptions.

Perform remediation validation testing post-patching or configuration changes.

Produce vulnerability compliance metrics and audit-ready reports.

Endpoint & Device Security Compliance

Support endpoint security control assurance across corporate devices using Microsoft Intune .

Validate enforcement of:

Device compliance policies

Security baselines

Patch and configuration standards

Support audit evidence related to:

Device enrollment

Configuration compliance

Endpoint protection integration (e.g., Defender ecosystem)

Partner with endpoint teams during audits to explain control design and operation.

Data Governance & Compliance

Support data protection and information governance controls using Microsoft Purview .

Assist in audits related to:

Data classification and labelling

DLP policy enforcement

Retention and records management

Insider risk and audit logging

Validate evidence of operational effectiveness for Purview-based controls.

Maintain compliance documentation related to data security and privacy controls.

Documentation & Stakeholder Coordination

Maintain SOC-related policies, standards, procedures, and control narratives.

Translate technical SOC and security processes into audit-ready documentation .

Collaborate with:

SOC Operations

Endpoint & IAM teams

Internal Audit

Risk & Compliance stakeholders

Prepare audit responses, management action plans, and status reporting.

You'll need to have:

2–6 years of experience in information security, IT audit, SOC governance, or security compliance.

Hands-on exposure to SOC audit or compliance activities .

Working knowledge of:

SOC 2 / ITGC concepts

Control testing and evidence collection

Preferred Skills & Certifications

Familiarity with:

ISO 27001

NIST CSF / 80053

AICPA Trust Services Criteria

Experience working with or supporting:

Nessus (vulnerability scanning & remediation tracking)

Microsoft Intune (device compliance / endpoint security assurance)

Microsoft Purview (DLP, data classification, compliance tooling)

Strong documentation, analytical, and stakeholder communication skills.

Certifications (nice to have, not mandatory):

CISA

ISO 27001 Foundation or LA

CRISC

Microsoft Security fundamentals

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.