IT Security Engineer
See all open roles at beghou consulting →
Some ghost-posting signals
- open for 191 days (90+ without a fill is a strong ghost signal)
- 88 open roles at this company in 30 days (mass-hiring blitz)
- no salary disclosed (correlates with ghost postings)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
We'll trust you to:
SOC Audit & Compliance
Support SOC 2 (Type I & Type II) , Future ISO 27001 readiness, and internal security audits as they relate to SOC and IT operations.
Map security and SOC controls to applicable frameworks (AICPA Trust Services Criteria, ITGCs).
Coordinate and manage audit evidence collection from SOC, endpoint, identity, and infrastructure teams.
Perform control design and operating effectiveness reviews for SOC adjacent controls.
Track audit findings, risks, and remediation actions through closure.
Maintain continuous audit readiness rather than point-in-time compliance.
Vulnerability & Remediation Governance
Partner with IT and GRC to support vulnerability management oversight .
Review and validate vulnerability findings from Nessus scans.
Track remediation of SLAs, compensating controls, and risk exceptions.
Perform remediation validation testing post-patching or configuration changes.
Produce vulnerability compliance metrics and audit-ready reports.
Endpoint & Device Security Compliance
Support endpoint security control assurance across corporate devices using Microsoft Intune .
Validate enforcement of:
Device compliance policies
Security baselines
Patch and configuration standards
Support audit evidence related to:
Device enrollment
Configuration compliance
Endpoint protection integration (e.g., Defender ecosystem)
Partner with endpoint teams during audits to explain control design and operation.
Data Governance & Compliance
Support data protection and information governance controls using Microsoft Purview .
Assist in audits related to:
Data classification and labelling
DLP policy enforcement
Retention and records management
Insider risk and audit logging
Validate evidence of operational effectiveness for Purview-based controls.
Maintain compliance documentation related to data security and privacy controls.
Documentation & Stakeholder Coordination
Maintain SOC-related policies, standards, procedures, and control narratives.
Translate technical SOC and security processes into audit-ready documentation .
Collaborate with:
SOC Operations
Endpoint & IAM teams
Internal Audit
Risk & Compliance stakeholders
Prepare audit responses, management action plans, and status reporting.
You'll need to have:
2–6 years of experience in information security, IT audit, SOC governance, or security compliance.
Hands-on exposure to SOC audit or compliance activities .
Working knowledge of:
SOC 2 / ITGC concepts
Control testing and evidence collection
Preferred Skills & Certifications
Familiarity with:
ISO 27001
NIST CSF / 80053
AICPA Trust Services Criteria
Experience working with or supporting:
Nessus (vulnerability scanning & remediation tracking)
Microsoft Intune (device compliance / endpoint security assurance)
Microsoft Purview (DLP, data classification, compliance tooling)
Strong documentation, analytical, and stakeholder communication skills.
Certifications (nice to have, not mandatory):
CISA
ISO 27001 Foundation or LA
CRISC
Microsoft Security fundamentals
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot