Назад
Company hidden
5 дней назад

Compliance Research Analyst (Cybersecurity)

Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
India
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Compliance Research Analyst (Cybersecurity): Researching security hardening standards and developing compliance controls for Linux, Windows, macOS, databases, applications, and network devices with an accent on CIS Benchmarks, DISA STIG, and major security frameworks. Focus on analyzing technical configurations, maintaining compliance content, troubleshooting Bash/Shell scripts, and validating controls through technical testing.

Location: Pune, India

Company

hirify.global develops cybersecurity and compliance solutions for managing security risks and technical controls.

What you will do

  • Research security configuration requirements for Linux, Windows, macOS, databases, applications, and network devices.
  • Study CIS Benchmarks and DISA STIG requirements and help create technical compliance controls.
  • Map controls to NIST, MITRE ATT&CK, PCI-DSS, ISO 27001, and other security frameworks.
  • Document control descriptions, rationale, risks, and remediation guidance.
  • Review and update compliance content as benchmarks and frameworks evolve.
  • Collaborate with Product, Development, QA, and Infrastructure teams to analyze compliance gaps and validate controls.

Requirements

  • 0–3 years of experience in Linux administration, cybersecurity, technical support, system administration, or compliance.
  • Strong Linux knowledge, including filesystem hierarchy, users and permissions, SSH, sudo, PAM, cron, logging, filesystems, mounts, and sysctl.
  • Hands-on experience with at least one RHEL-based distribution and familiarity with Ubuntu or Debian.
  • Basic understanding of operating system security, networking, CIS Benchmarks, DISA STIG, NIST, ISO 27001, PCI-DSS, and MITRE ATT&CK.
  • Ability to read, understand, troubleshoot, and make small modifications to Bash/Shell scripts.
  • Strong analytical, research, communication, collaboration, and attention-to-detail skills.

Nice to have

  • Knowledge of SELinux, auditd, audit rules, ausearch, and aureport.
  • Exposure to Windows administration, macOS, databases, APIs, Postman, or Microsoft Security Compliance Toolkit.
  • Regular expressions, Linux certifications such as RHCSA, LFCS, or Linux+, and security certifications such as Security+.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.

Culture & Benefits

  • Collaborative work across Product, Development, QA, and Infrastructure functions.
  • Opportunities to research emerging technologies and learn evolving security standards.
  • Ownership of assigned compliance research and content-maintenance activities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →