Photon Interactive UK Limited

Security and Compliance Engineer_Offshore

India full-time Mid Salary not listed
full-time Mid level Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

About the Role
We're seeking a hands-on and detail-oriented Security and Compliance Engineer to drive security across our applications, infrastructure, and compliance programs-especially in a healthcare environment. This role combines security engineering, DevSecOps, and risk management with a strong focus on application, cloud, AI, and data security.
You will work closely with engineering, DevOps, and compliance teams to embed security into the development lifecycle, support regulatory frameworks, and ensure cloud-native environments and AI technologies are secure by design.
Responsibilities

Conduct web and mobile application penetration testing, vulnerability scanning, and remediation support across our platforms.

Integrate DevSecOps practices into CI/CD pipelines, using tools like Snyk, Terraform, and container security scanners.

Implement and monitor Cloud Security Posture Management (CSPM) tools such as Wiz to secure cloud configurations and infrastructure.

Partner with DevOps to enforce secure provisioning via Infrastructure as Code (IaC).

Lead and support compliance initiatives (HIPAA, SOC 2, HITRUST) using platforms like Drata (Compliance-as-a-Service).

Design and enhance email gateway security (e.g., Barracuda) and bot protection (e.g., WatchGuard) to defend against phishing and automated threats.

Evaluate and secure chatbots and AI systems, addressing risks like prompt injection, data leakage, and model integrity.

Drive data security best practices including encryption, data loss prevention (DLP), and classification strategies.

Collaborate with engineering to embed security controls in product design and conduct threat modeling, secure code reviews, and architecture reviews.

Participate in incident detection, response, and root cause analysis, while ensuring effective logging and monitoring are in place.

Maintain security documentation and support audits and third-party assessments.

Required Skills & Qualifications

4-6 years of experience in security engineering, compliance, and DevSecOps.

Proficiency in web and mobile application security, including OWASP Top 10, SAST/DAST tools, and manual testing with Burp Suite, etc.

Strong exposure to DevSecOps workflows, with hands-on experience using tools like Snyk, Terraform, and container security.

Deep understanding of HIPAA, SOC 2, and healthcare compliance requirements.

Experience with cloud security, preferably on Microsoft Azure, and familiarity with CSPM tools like Wiz.

Working knowledge of Drata or similar compliance automation platforms.

Exposure to email security gateways, bot protection, and threat detection tools.

Familiarity with AI and chatbot security concepts and current risks in the generative AI space.

Strong grasp of data security principles-encryption, access controls, data classification, and DLP.

Scripting or automation skills in Python, Bash, or equivalent are a plus.

Strong written and verbal communication, documentation, and collaboration skills.

Nice to Have

Certifications like OSCP, CEH, CCSK, CISSP, HCISPP, or similar.

Familiarity with tools like KnowBe4, Intune, or Azure AD for identity and endpoint security.

Understanding of Zero Trust Architecture, RBAC, and endpoint detection and response (EDR) strategies.

Previous experience in a health tech, SaaS, or AI-focused organization.

Why Join Us

Make a real impact in securing healthcare and AI systems at scale.

Collaborate in a high-ownership environment with modern tools and cloud-native practices.

Work in a security-forward company that values both innovation and compliance.

Flexible work environment and growth opportunities in a fast-paced tech culture.

Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Mid
Technology & IT Figma Python Writing Security Compliance Mid level

Likely questions

  1. Tell us about work you have done that is close to the Security and Compliance Engineer_Offshore role.
  2. How would you approach your first 30 days at Photon Interactive UK Limited?
  3. Which of Figma, Python and Writing have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Figma, Python and Writing.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Security and Compliance Engineer_Offshore role because I can bring practical experience in Figma, Python and Writing, learn the team quickly, and contribute to the outcomes Photon Interactive UK Limited needs from this hire.

Related jobs.

More roles from this company or category.