Talent.com
Cimpress India
Senior Information Security EngineerCimpress India • Ghaziabad, IN
Senior Information Security Engineer

Senior Information Security Engineer

Cimpress India • Ghaziabad, IN
8 days ago
Job description

About Cimpress:

Led by founder and CEO Robert Keane, Cimpress invests in and helps build customer-focused, entrepreneurial mass customization businesses. Through the personalized physical (and digital) products these companies create,we empower over 17 million global customers to make an impression. Last year, Cimpress generated $3.5B in revenue through customized print products, signage, apparel, packaging and more. The Cimpress family includes a dynamic, international group of businesses and central teams, all working to solve problems, build businesses, innovate and improve.

As a National Pen brand, Pens.com provides custom marketing solutions to 22 countries worldwide, fostering global connections between businesses and their customers. We specialize in personalized promotional products, including writing instruments, stationery, drinkware, bags, gifts, and trade show accessories. Our operations are supported by a network of 9 facilities across North America, Europe, Africa, and India. This global presence underscores our commitment to the timely delivery of our products and services to customers across the markets we serve.


About the Role:

We are looking for a Senior Information Security Engineer who is hands-on, takes full ownership, and delivers results independently. This is not a role where you wait for instructions. You will be expected to lead security initiatives across cloud environments, drive incident response from detection to resolution, manage vulnerabilities end to end, and provide practical security architecture guidance that teams can actually implement. You will work across multiple InfoSec domains and coordinate with cross-functional stakeholders, and be the go-to person the organisation relies on when security matters. You will be part of a lean security team that collectively owns and operates across all of these domains, so the ability to wear multiple hats, switch context quickly, and contribute wherever needed is essential.

The ideal candidate brings deep technical expertise across cloud security, SOC operations, incident response, digital forensics, vulnerability management, and threat intelligence. You should be equally comfortable investigating a P1 incident whenever such situation arises. If you thrive in environments that demand ownership, independent execution, and practical problem-solving over checkbox compliance, this role is built for you.


Mandatory Skills & Requirements:

All of the following are mandatory requirements for this role. Candidates must demonstrate hands-on, practical experience in each of these areas. Theoretical knowledge alone is not sufficient.


Cloud Security and Security Architecture

  • Perform hands-on security architecture reviews for workloads deployed across AWS, OCI, Azure, and GCP, ensuring alignment with CIS Benchmarks, CSA Cloud Controls Matrix (CCM), and the NIST Cybersecurity Framework (CSF).
  • Evaluate and provide actionable security recommendations for IaaS, PaaS, and SaaS environments, covering but not limited to network segmentation, identity and access management (IAM), encryption, logging, and data protection.
  • Review cloud & application resource configurations, threat modelling, infrastructure-as-code templates, and deployment pipelines to identify security gaps before they reach production.
  • Collaborate with engineering and DevOps teams to embed security controls into the software development lifecycle (SDLC) and cloud deployment workflows, following the principles of the AWS Well-Architected Framework Security Pillar and Azure Security Benchmark.


Vulnerability Management

  • Own the end-to-end vulnerability management lifecycle: identification, assessment, prioritisation, tracking, remediation coordination, and stakeholder reporting.
  • Operate and manage vulnerability assessment tools, specifically Orca Security, Microsoft Defender Security Posture Management, and Azure Security Posture Management, to maintain continuous visibility across the cloud estate.
  • Coordinate remediation of findings from annual external penetration tests, working directly with application and infrastructure teams to drive timely closure within agreed SLAs, and independently validate fixes through retesting.
  • Produce vulnerability trend reports, communicate remediation progress and residual risk to technical and non-technical stakeholders.
  • Apply CVSS, EPSS, and risk-based prioritisation methodologies (aligned with frameworks such as NIST SP 800-40 and OWASP Risk Rating) to ensure remediation efforts are focused on what matters most.


SOC, Incident Response, and Digital Forensics

  • Perform Security Operations Center (SOC) activities, including alert triage, threat hunting, and investigation of security events across the environment.
  • Lead and coordinate end-to-end incident response for security incidents, following the NIST SP 800-61 Incident Handling framework and the SANS Incident Response Process (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).
  • Conduct hands-on digital forensics investigations, including evidence collection, analysis, timeline reconstruction, and root cause determination.
  • Operate and manage CrowdStrike EDR for endpoint detection, threat hunting, SOAR Automation, use case implementation and response actions across the endpoint fleet.
  • Utilise Hunters.io/Splunk/QRadar SIEM for log correlation, alert management, use case implementation and building detection rules to improve SOC detection coverage.
  • Prepare detailed incident reports, conduct post-incident reviews, and drive remediation actions to prevent recurrence.
  • Map adversary tactics and techniques to the MITRE ATT&CK Framework to strengthen detection engineering and improve threat visibility.


Threat Intelligence

  • Leverage Dark & Deep Web Monitoring tool like Google Threat Intelligence (GTI)/Cyble/Flare.io, CloudSek etc. to proactively identify, analyse, and contextualise threats relevant to the organisation.
  • Monitor and assess emerging threats, vulnerabilities, and attack trends, incorporating intelligence from open-source threat feeds, ISAC reports, and vendor advisories alongside GTI findings.
  • Contribute to the development of threat-informed defence strategies using the MITRE ATT&CK Framework, the Cyber Kill Chain model, and the Diamond Model of Intrusion Analysis.


Secure Code and Supply Chain Security

  • Operate SAST tooling and Snyk/SonarQube (SCA) to help development teams identify and remediate code-level and dependency vulnerabilities across the SDLC.


Cross-Functional Collaboration and Stakeholder Management

  • Serve as the point of contact for internal teams, providing clear and practical guidance on security-related queries and decisions. Translating complex technical findings into clear, understandable language for non-technical stakeholder, ensuring security outcomes drive informed business decisions.
  • Coordinate and communicate effectively with engineering, IT operations, and compliance teams during security incidents, reviews, and project engagements.
  • Drive security awareness and best practices across the organisation through documentation, knowledge sharing, and advisory support.


Preferred Certifications

  • CompTIA Security+, CEH, CCNA Security
  • Cloud security certifications such as AWS Certified Security – Specialty, AZ-500 (Azure Security Engineer Associate), Google Professional Cloud Security Engineer, or CCSP (Certified Cloud Security Professional).


Good to Have

  • CISM, CISSP, CISA


Experience required:

  • Minimum 4+ years of hands-on experience in Information Security or Cybersecurity roles, with demonstrated depth across the mandatory skill domains listed above.
  • Candidates with a strong progression from roles like Cloud Security, Endpoint Security, Network Security, SOC, Security Architect, Threat Intelligence, Application Security, Data Security, Perimeter Security into Senior Security Engineering positions are encouraged to apply.
  • Experience working in multi-cloud environments and coordinating security operations across distributed teams is strongly valued.


Why You'll Love Working Here:

Being at Cimpress means that you don’t see work as just a building, a desk or a manufacturing floor. You see it as a chance to take a step forward in your career journey – and your life. We strive to give you everything you need to learn, grow, and succeed. Through innovation, collaboration, and perpetual exposure to what’s next, we’re always pushing boundaries and broadening our horizons. We embrace the chance to operate outside of our comfort zone to discover what we’re capable of. Some might call that a challenge; we just call it another great day at work.


Equal Opportunity Employer:

Cimpress, is an Equal Employment Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, sex, national or ethnic origin, nationality, age, religion, citizenship, disability, medical condition, sexual orientation, gender identity, gender presentation, legal or preferred name, marital status, pregnancy, family structure, veteran status or any other basis protected by human rights laws or regulations. This list is not exhaustive and, in fact, in many cases, we strive to do more than the law requires.


We're Remote-First:

In 2020, Cimpress adopted a Remote-First operating model and culture. We heard from our team members that having the freedom, autonomy and trust in each other to work from home and, the ability to operate when they are most productive, empowers them to be their best. Vista also provides collaboration spaces for team members to work physically together when it's safe to do so and when in-person collaboration will deliver the best results. Currently we are enabled to hire remote team members in over 30 US States as well as several countries in Europe, including Spain, Germany, UK, Czech Republic, the Netherlands and Switzerland.

Create a job alert for this search

Senior Information Security Engineer • Ghaziabad, IN

Similar jobs

Enterprise Security Lead

Confidential Careersnoida, delhi, in

Reporting directly to the CISO, the Enterprise Security Lead will play a critical role in shaping and operating the organisation’s global cyber security capability across a rapidly growing internat... Show more

 • Promoted

Security Architect

BluOcean Cybernoida, delhi, in

This role is for a senior technical leader who can define architecture, guide implementation, lead programs, and elevate the work of others without necessarily serving as a people manager.You will ... Show more

 • Promoted

Senior AI/ML Engineer

Egnyteghaziabad, uttar pradesh, in

Egnyte is a place where we spark opportunities for amazing people.We believe that every role has meaning, and every Egnyter should be respected.With 23,000 customers worldwide and growing, you can ... Show more

 • Promoted

Cyber Security Engineer

SENTIENT - An Ascend Companydelhi, delhi, in

Shift Time: 7:00 PM to 4:00 AM IST.Building Effective Teams—Creates strong morale and spirit in his/her team; fosters open.Customer Focus—Is dedicated to meeting the expectations and requirements o... Show more

 • Promoted

Senior Syslog Engineer

Securonixnoida, delhi, in

Securonix is leading the transformation of cybersecurity by helping organizations stay ahead of modern threats.Security teams are no longer constrained by data or tools.They are constrained by spee... Show more

 • Promoted

Senior Information Security Engineer

Cimpress Indianew delhi, delhi, in

Led by founder and CEO Robert Keane, Cimpress invests in and helps build customer-focused, entrepreneurial mass customization businesses.Through the personalized physical (and digital) products the... Show more

 • Promoted

Senior Security Engineer

BKN301delhi, delhi, in

At BKN301, we build fintech solutions that enable banks, fintechs, and merchants to grow and innovate across emerging markets.We’re a London-based financial technology group, with offices in Milan ... Show more

 • Promoted

Cloud Security Engineer

TECEZEnoida, delhi, in

The Cloud Security Platform Engineer is responsible for supporting the deployment, configuration, and operationalization of CrowdStrike Falcon Platform cloud security modules within customer enviro... Show more

 • Promoted

Senior AI Engineer

TAC Securitynew delhi, delhi, in

AI Vision and Enterprise Strategy.Define TAC’s multi-year AI roadmap aligned with the 2030 Vision.Identify high-impact AI opportunities across vulnerability management, application security, SOC 2 ... Show more

 • Promoted

Cyber Security Lead

TAC Securitydelhi, India

We are seeking an experienced and highly motivated Information Security professional to lead enterprise-wide cyber security initiatives, strengthen cyber defence operations, and drive information s... Show more

 • Promoted

EntraID Senior Security Engineer

MajorKey Technologiesnoida, delhi, in

We are seeking a highly skilled.Senior Identity Security Engineer.Active Directory (AD) migration, consolidation,.This individual will serve as the primary technical lead responsible for technical ... Show more

 • Promoted

Security Operations Engineer

Internsetnoida, delhi, in

Internset is building AI-powered infrastructure for internships, employability systems, workforce intelligence, digital credentials, and large-scale verification ecosystems.As our platforms continu... Show more

 • Promoted

Information Technology Infrastructure Engineer

FinacPlusghaziabad, uttar pradesh, in

FinacPlus is a Great Place to Work® Certified organization — a recognition of our people first culture, collaborative environment, and focus on professional growth.We provide high-end virtual busin... Show more

 • Promoted

Security Analyst

Confidential Startup SaaS Companynew delhi, delhi, in

We are looking for a hands-on Security Analyst who takes complete ownership of our security posture — across every device, every server, every application, and every user in our environment.This is... Show more

 • Promoted

HCL AppScan Professional Services _Cyber Security Analyst (DAST, SAST, IAST, SCA)

HCLSoftwaredelhi, delhi, in

Greetings from \"HCL Software\".Is a Product Development Division of HCL Tech: That operates its primary Software Business.At HCL Software we Develop, Market, Sell and Support over 20 Product famil... Show more

 • Promoted

Security Engineer – Cortex XDR Operations

Krish Services Groupnew delhi, India

Founded in 2011, Krish Services Group is a global leader in software development and cloud solutions with a strong focus on empowering businesses in the digital age.With expertise in full-stack dev... Show more

 • Promoted

Senior Security Engineer

BluOcean Cyberghaziabad, uttar pradesh, in

This role is ideal for a security professional with strong foundational experience across modern cloud and application security who can own processes end-to-end, drive accountability, and grow into... Show more

 • Promoted

Senior Security Engineer – Blue Team

BKN301noida, delhi, in

At BKN301, we build fintech solutions that enable banks, fintechs, and merchants to grow and innovate across emerging markets.We’re a London-based financial technology group, with offices in Milan ... Show more

 • Promoted

Security Professional

SISL Globalnoida, delhi, in

We are seeking a highly experienced End User Computing (EUC) Subject Matter Expert with 10+ years of enterprise experience, specializing in endpoint vulnerability management and third‑party applica... Show more

 • Promoted

SOC Manager

C3iHub, IIT Kanpurdelhi, delhi, in

We are seeking an experienced and technically strong SOC Manager to lead and enhance enterprise Security Operations capabilities.The role requires deep expertise in SOC technologies, security monit... Show more