Application Security Engineer

SourcingXPress

Company: 5 Exceptions Pvt Ltd

Website: Visit Website

Business Type: Small/Medium Business

Company Type: Service

Business Model: B2B

Funding Stage: Seed

Industry: Information Technology and Services

Salary Range: ₹ 15-18 Lacs PA

Job Description

About the Role

We're building out our security and compliance function, and this role owns the identity, IT, and compliance-evidence backbone the rest of the program runs on. You'll own how people and systems get access, how that access is reviewed and proven, and how we keep our SOC 2 program continuously audit-ready.

If you're the kind of engineer who makes access clean, least-privilege, and defensible — and can produce evidence an auditor trusts without hand-holding — this is your role.

Key Responsibilities

  • Own identity and access management (IAM) end to end, including user and service-account lifecycle (joiner, mover, leaver), least-privilege enforcement, MFA, key and credential hygiene, and access to cloud and SaaS systems.
  • Conduct periodic access reviews across cloud, SaaS, and internal systems, and produce audit-ready evidence demonstrating completion.
  • Own corporate IT, including endpoint management, SSO and identity-provider administration, and secure onboarding/offboarding processes.
  • Maintain SOC 2 compliance by managing control evidence, keeping the compliance automation platform current, and supporting internal and external audits.
  • Maintain the control ownership matrix, ensuring it stays accurate as the environment evolves.
  • Independently review third-party and vendor access, ensuring objective and compliant access governance.
  • Partner with Security and Engineering teams to remediate or document identity- and access-related findings per established processes.

Required Skills & Experience

  • Strong hands-on experience with IAM, including identity lifecycle management, least privilege, MFA, federation, SSO, and key/credential management.
  • Proven experience supporting or maintaining a SOC 2 Type II compliance program, including ownership of control evidence and audit participation.
  • Experience conducting access reviews and recertification cycles, with sound judgment on access approvals and revocations.
  • Hands-on experience managing corporate IT, including endpoints, SSO, and employee onboarding/offboarding.
  • Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
  • Excellent written communication skills, with the ability to produce clear, audit-ready documentation.
  • Strong sense of integrity and objectivity when reviewing access permissions and compliance requirements.

Preferred Qualifications

  • ~4+ years of experience in Identity & Access Management, IT, Security Operations, or Compliance Engineering.
  • Experience with compliance automation platforms such as Vanta, Drata, Secureframe, or similar.
  • Hands-on experience with identity providers such as Okta, Microsoft Entra ID, or AWS IAM Identity Center.
  • Familiarity with AWS IAM and cloud access management models.
  • AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
  • Relevant certifications such as CISA, ISC2 SSCP/CC, or CompTIA Security+.
  • Exposure to GDPR or other privacy and regulatory compliance frameworks.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.