603,101open jobs
31,403companies
86,475added this week
Browse all
Salary
$25k – $58k per year (Estimated)
Location
In office (Noida)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

About Us:

At apexanalytix, we’re lifelong innovators! Since the date of our founding nearly four decades ago we’ve been consistently growing, profitable, and delivering the best procure-to-pay solutions to the world. We’re the perfect balance of established company and start-up. You will find a unique home here.

And you’ll recognize the names of our clients. Most of them are on The Global 2000. They trust us to give them the latest in controls, audit and analytics software every day. Industry analysts consistently rank us as a top supplier management solution, and you’ll be helping build that reputation.

Read more about apexanalytix - https://www.apexanalytix.com/about/

Job Details

The Role:

The Manager - Information Security and Compliance operate and matures our company-wide security, risk, and compliance program across the US and Europe. You'll lead a small team, own the security budget, drive cloud and Kubernetes security, run our audit and certification programs, and bring innovative ideas that move our posture forward year over year.

The Work :

  • Lead the information security and IT risk program; report posture, KPIs, and incidents to the CIO and senior leadership.
  • Own Azure security - Defender for Cloud, Entra ID with Conditional Access policies (risk-based sign-in, device compliance, phishing-resistant MFA / FIDO2 / passkeys, session controls, break-glass hygiene) and PIM, Key Vault, and Azure Policy.
  • Drive the Microsoft 365 Defender suite (MDE, MDO, MDI, MDCA), Microsoft Purview (DLP, Information Protection), and Microsoft Sentinel (SIEM/SOAR).
  • Own Kubernetes and container security - admission control, image signing, runtime protection, secrets management - plus DevSecOps (SAST/DAST/SCA, IaC scanning, secure SDLC).
  • Run a comprehensive SBOM program (SPDX / CycloneDX, VEX) and supply-chain controls aligned to SLSA and NIST SSDF.
  • Own vulnerability management on Tenable (Tenable.io / sc / WAS) - scan coverage, SLA-driven remediation, EPSS / KEV-based prioritization, exception workflow.
  • Drive web application security testing with Burp Suite Professional / Enterprise - authenticated scans, manual exploitation, API testing, and CI/CD integration; oversee external penetration testing engagements end-to-end (scoping, vendor management, finding triage, retesting, reporting).
  • Run SOC 1 / SOC 2 Type II programs end-to-end with external auditors.
  • Lead US regulatory compliance - SOX ITGC, HIPAA / HITECH, GLBA, CCPA / CPRA + state privacy laws, NYDFS Part 500; track FedRAMP / StateRAMP readiness.
  • Lead European compliance - EU and UK GDPR (DPIAs, ROPAs, SCCs / UK IDTA), NIS2, and DORA readiness for in-scope clients.
  • Maintain alignment with NIST CSF 2.0, NIST 800-53, CIS Controls v8, and PCI DSS v4.0 where relevant.
  • Own the vendor and client assurance function - TPRM, security questionnaires, RFPs, customer audits, and contract security clauses.
  • Lead incident response and manage breach-notification timelines (SEC 8-K Item 1.05, HIPAA, NYDFS 72-hour, GDPR Article 33, NIS2).
  • Own the annual security budget - CapEx/OpEx planning, vendor negotiation, ROI tracking, and 12/24/36-month capability roadmaps.
  • Champion innovation - pilot AI-assisted SOC, autonomous pen testing, deception, ITDR, and CNAPP consolidation; run purple-team and tabletop exercises.
  • Lead, coach, and grow a team of security and compliance analysts.

The Must-Haves :

  • 8+ years across information security, risk, and IT, with direct people-management experience.
  • Deep hands-on Azure security (Defender for Cloud, Entra ID Conditional Access design and tuning, PIM, Sentinel) and Microsoft 365 Defender / Purview.
  • Practical Kubernetes / container security and DevSecOps experience.
  • Hands-on Tenable vulnerability management at scale, plus Burp Suite Professional for web app and API penetration testing.
  • SBOM and supply-chain security experience (SPDX / CycloneDX, SLSA, NIST SSDF).
  • Track record leading SOC 1 / SOC 2 Type II and ISO 27001 cycles end-to-end.
  • Working command of US (SOX, HIPAA, GLBA, CCPA/CPRA, NYDFS Part 500) and EU/UK (GDPR, NIS2, DORA) frameworks.
  • Solid grounding in NIST CSF 2.0, NIST 800-53, CIS v8, and MITRE ATT&CK.
  • Experience owning a security budget and negotiating with vendors.
  • Incident response leadership across multiple US and EU jurisdictions.
  • Strong executive communication - translating risk into business language.
  • Bachelor's degree in CS, InfoSec, or related field (or equivalent experience), plus CISSP, CISM, or CISA.

Preferred to Have:

  • Cisco Umbrella DNS-layer security experience.
  • FedRAMP / StateRAMP or HITRUST CSF program experience.
  • Azure Security Engineer (AZ-500), Microsoft Cybersecurity Architect (SC-100), CCSP, or ISO 27001 Lead Auditor.
  • CNAPP, ITDR, or deception technology experience.
  • Familiarity with AI/ML governance (NIST AI RMF, ISO 42001, EU AI Act).
  • Exposure to procure-to-pay, fintech, or supplier-data environments.

Over the years, we’ve discovered that the most effective and successful associates at apexanalytix are people who have a specific combination of values, skills, and behaviors that we call “The apex Way”. Read more about The apex Way - https://www.apexanalytix.com/careers/

Benefits

At apexanalytix we know that our associates are the reason behind our successes. We truly value you as an associate and part of our professional family. Our goal is to offer the very best benefits possible to you and your loved ones. When it comes to benefits, whether for yourself or your family the most important aspect is choice. And we get that. apexanalytix offers competitive benefits for the countries that we serve, in addition to our BeWell@apex initiative that encourages employees’ growth in six key wellness areas: Emotional, Physical, Community, Financial, Social, and Intelligence.

With resources such as a strong Mentor Program, Internal Training Portal, plus Education, Tuition, and Certification Assistance, we provide tools for our associates to grow and develop.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
603,101 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Noida
$82k per year (net) • In office • 4+ years exp • Master's Degree
Python
JavaScript
Java
Rust
TypeScript
SQL
Python
FastAPI
Django
Java
Maven
Gradle
Databases
Databricks
Apache Iceberg
Apache Kafka
Trino
AI/ML
Copilot
Hadoop
Spark
Airflow
Flink
Frontend
Angular
npm
DevOps
CI/CD
Git
Kubernetes
Cybersecurity
Zero Trust
Analytics
ETL/ELT
Management
Agile
Scrum
Kanban
Apply
In office • 5+ years exp
JavaScript
Java
TypeScript
SQL
Node JS
Java
Spring Boot
Node JS
Nest.JS
AI/ML
Copilot
Claude Code
Model Context Protocol
Prompt Engineering
OpenAI Codex
Frontend
Angular
React.js
DevOps
Azure
CI/CD
Git
AWS
Management
Agile
Apply
In office • 6+ years exp • Master's Degree
Python
JavaScript
SQL
Databases
Databricks
AI/ML
Copilot
Claude Code
MLFlow
Time Series Forecasting
OpenAI Codex
Frontend
React.js
DevOps
CI/CD
AWS
Docker
Kubernetes
Amazon ECS
Management
Agile
Apply
$135k – $153k per year • In office • 5+ years exp • Bachelor's Degree
Python
SQL
AI/ML
AI Agents
LLM Guardrails
DevOps
Terraform
CloudFormation
CI/CD
AWS
Management
Agile
Apply
In office • Contractor • 7+ years exp
JavaScript
C#
C#
ASP.NET Core
WPF
Frontend
npm
Mobile
MVVM
DevOps
Azure
Git
AWS
Apply
Senior Cloud Engineer 12 days ago
$22k – $53k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Noida
Python
PowerShell
Bash
DevOps
Terraform
Ansible
GCP
Red Hat
Helm
Cilium
Loki
OpenTofu
VMWare
cert-manager
etcd
Kustomize
Prometheus
Velero
Azure
GitOps
Windows Server
ArgoCD
Git
AWS
Kubernetes
Ubuntu
Grafana
Harbor
Thanos
kubeadm
Gateway API
Amazon EKS
Azure AKS
KVM
KubeVirt
eBPF
Cybersecurity
Keycloak
HashiCorp Vault
SOC 2
FedRAMP
Microsoft Entra ID
Apply
Cloud Engineer 12 days ago
$22k – $53k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Noida
Python
PowerShell
Bash
DevOps
Terraform
Ansible
GCP
Red Hat
Helm
Cilium
Loki
OpenTofu
VMWare
cert-manager
etcd
Kustomize
Prometheus
Velero
Azure
GitOps
Windows Server
ArgoCD
Git
AWS
Kubernetes
Ubuntu
Grafana
Harbor
Thanos
kubeadm
Gateway API
Amazon EKS
Azure AKS
KVM
KubeVirt
eBPF
Cybersecurity
Keycloak
HashiCorp Vault
SOC 2
FedRAMP
Microsoft Entra ID
Apply
Director- Architect 17 days ago
$38k – $77k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Noida
Python
Go
SQL
C#
Bash
C#
ASP.NET Core
gRPC for .NET
Databases
PostgreSQL
Snowflake
ClickHouse
CockroachDB
MariaDB
ElasticSearch
TiDB
YugabyteDB
Google Cloud Spanner
DevOps
gRPC
Terraform
Ansible
Helm
Cilium
Loki
OpenTofu
FluxCD
Kustomize
Prometheus
CI/CD
GitOps
ArgoCD
Git
Kubernetes
Ubuntu
Grafana
Platform Engineering
Service Mesh
Thanos
KubeVirt
eBPF
Cybersecurity
SOC 2
FedRAMP
Apply
$38k – $78k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Noida
Go
JavaScript
SQL
C#
Node JS
C#
ASP.NET Core
gRPC for .NET
Databases
PostgreSQL
Snowflake
ClickHouse
CockroachDB
MariaDB
ElasticSearch
AI/ML
AI Agents
LLM Guardrails
Frontend
React.js
DevOps
gRPC
GitOps
Kubernetes
SLI/SLO/SLA
Cybersecurity
SOC 2
FedRAMP
Management
Agile
Scrum
Apply
Head of Product 19 days ago
$162k – $324k per year (Estimated) • In office • Full-Time • 10+ years exp • Greensboro
Go
Cybersecurity
SOC 2
FedRAMP
Apply
$33k – $74k per year (Estimated) • Remote • Full-Time • 10+ years exp • Bengaluru • Noida • Chennai • Gurgaon • Hyderabad
Python
Go
DevOps
Terraform
GCP
GitHub Actions
OpenTelemetry
Prometheus
GitLab CI
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Grafana
Platform Engineering
Amazon EKS
Google GKE
Azure AKS
Apply
$13k – $29k per year (Estimated) • In office • Full-Time • 1+ year exp • Noida
Apply
$16k – $36k per year (Estimated) • In office • Full-Time • 3+ years exp • Noida
Apply
In office • Full-Time • Noida
Apply
$24k – $63k per year (Estimated) • In office • Noida
Apply
See all jobs
This is one of many
603,101 more open roles from verified company boards, updated every day.