Skip to content

Information Security Engineer - India

Q4 IncIndiaSeptember 6, 2026
On-site
Full-time
GRC
Mid · 2–5 yrs

At Q4, we make an impact together, obsess over our customers, operate with integrity, and bring big ideas to life. 

Q4 is charting a bold new path for investor relations as the first AI-driven IR Ops Platform, providing everything an IR team needs to succeed on a single, powerful platform. The Q4 Platform enables public companies to attract, manage, and understand investors - all in one place. Over 2,600 customers, including many of the most respected brands in the world, trust Q4 to help drive premium valuations for their companies. Only Q4 offers a tech stack holistically designed to equip IR teams with data, insights, and smart workflows that power remarkable outcomes. Learn more at q4inc.com.

We hire smart, curious, and talented people to push boundaries, reimagine what’s possible, and turn challenges into opportunities. All while keeping the needs of our clients at the heart of everything we do.

Come grow with us!

The Role: Information Security Engineer

Step into a pivotal position as our Information Security Engineer where your expertise directly shapes our security posture, compliance standards, and market trust. You will own complex client due diligence, manage critical framework audits, and execute compliance strategy with precision from day one. If you are looking to bring deep, practical mastery of security operations to a high-velocity team, this is where you can make an immediate impact.

Responsibilities

  • Execute client security questionnaire responses, due diligence requests, and policy updates on a daily and weekly basis to drive measurable business outcomes.
  • Manage and optimize ISO 27001, SOC 2, and DPIA compliance frameworks utilizing our core documentation and security management tools.
  • Partner closely with internal audit teams, external certification bodies, and penetration testing partners, ensuring clear alignment, robust service delivery, and strict adherence to SLAs.
  • Translate complex data, technical security constraints, or compliance requirements into highly actionable strategies and audit evidence.
  • Drive continuous operational excellence while navigating a high-velocity, resilient work environment.

Required Skills & Qualifications

  • Domain Expertise: 2–5 years of professional experience in information security compliance, with a proven track record of successfully navigating multiple recent audit programs (specifically SOC 2) and maintaining audit readiness. Demonstrated deep fluency in ISO 27001, SOC 2, and Data Privacy frameworks (GDPR/DPIA).
  • Program Management: 2–5 years of hands-on experience managing compliance programs, leading internal audits, and responding to customer security questionnaires.
  • Tech Stack Mastery: Advanced, day-one capability utilizing vulnerability management tracking tools, penetration testing remediation systems, and compliance management platforms. ISO 27001 Lead Auditor or Implementer certification preferred. Experience with automated compliance tools (such as Vanta, Drata, or Secureframe) is a nice-to-have.
  • Communication: Exceptional executive storytelling; proven ability to articulate security controls, ROI, and compliance documentation to external clients, enterprise stakeholders, and audit bodies.

__We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please con__tact us.

Job Details

Experience

Mid · 2–5 yrs

Tools & Tech

Drata
Vanta