Security Engineer
2 days ago
About Groww We are a passionate group of people focused on making financial services accessible to every Indian through a multi-product platform. Each day, we help millions of customers take charge of their financial journey. Customer obsession is in our DNA. Every product, every design, every algorithm down to the tiniest detail is executed keeping the customers’ needs and convenience in mind. Our people are our greatest strength. Everyone at Groww is driven by ownership, customer-centricity, integrity and the passion to constantly challenge the status quo. Are you as passionate about defying conventions and creating something extraordinary as we are? Let’s chat. Our Vision Every individual deserves the knowledge, tools, and confidence to make informed financial decisions. At Groww, we are making sure every Indian feels empowered to do so through a cutting-edge multi-product platform offering a variety of financial services. Our long-term vision is to become the trusted financial partner for millions of Indians. Our Values Our culture enables us to be what we are — India’s fastest-growing financial services company. It fosters an environment where collaboration, transparency, and open communication take center-stage and hierarchies fade away. There is space for every individual to be themselves and feel motivated to bring their best to the table, as well as craft a promising career for themselves. The values that form our foundation are: Radical customer centricity Ownership-driven culture Keeping everything simple Long-term thinking Complete transparency EXPERTISE AND QUALIFICATIONS What you’ll do: Policy Development and Enforcement: Develop, implement, and maintain policies, procedures, standards, and associated plans based on industry best practices such as ISO 27001, NIST, ITGC, PCI-DSS, etc. Ensure rigorous enforcement of these policies. Risk Assessment and Management: Conduct technology-based gap risk assessments, third-party risk assessments, and M&A security governance. Manage exceptions against Groww standards to maintain risk at an acceptable level. Compliance Checks: Perform compliance checks for user access management on network, servers, and applications. Additionally, ensure compliance with security and hardening standards for network, servers, applications, and workstations. Compliance Reporting: Prepare compliance reports and remediation plans based on periodic reviews of application, workstation, server, and network device configurations. Data Loss Prevention (DLP) and CASB: Monitor and maintain compliance of Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) for all applications, infrastructure, and systems supporting Groww operations to prevent data leakage. SDLC Risk Assessment: Conduct risk assessments on applications during the Software Development Life Cycle (SDLC) and perform compliance checks related to access control and data sanitization. Risk Register Management: Identify, document, and maintain an information security risk register. Regularly report to the security lead and other stakeholders. Third-Party Risk Management: Provide monitoring, independent oversight, and facilitate the execution and continuous improvement of third-party risk management and M&A programs and processes. Security Control Automation: Influence security control automation efforts to enhance security and compliance at scale. Audit Representation: Represent Groww's security posture in both internal and external audits. Security Awareness: Drive security awareness initiatives and conduct regular training on Groww’s security policies and standard requirements through training sessions, communication, and workshops. What we're looking for: A bachelor’s degree in information technology or a related field provides a strong foundation. A minimum of 1-3 years of professional experience in information security practices, with at least 1 year specializing in Governance, Risk, and Compliance (GRC) domains. Previous experience in managing SEBI, RBI, and IRDAI compliance and audits is highly valuable. Proficiency in security policy management and a deep understanding of security standards and frameworks, including CSA CCM, ISO 27001:2013, NIST CSF, PCI-DSS, SOX, and SOC2. Solid grasp of operational and organizational structures, including experience in global, matrix organizations, and third-party risk management. Strong knowledge of core security principles such as least privilege access, defense in depth, preventative vs. detective controls, network security, cloud security, application security, endpoint security, data protection, and incident response. Familiarity with agile methodologies and experience in DevOps or DevSecOps practices, along with an understanding of how they impact risk management and compliance. Possession of information security certifications, such as CISSP, CISM, CRISC, CEH, or ISO 27001, demonstrates expertise and will be an added benefit. Experience in reviewing High-Level Design (HLD) and Low-Level Design (LLD) and driving cross-functional programs is a plus.
-
TAC Security
3 weeks ago
Delhi Division, India TAC Security Full timeJob Description :As a Security Engineer VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems...
-
Senior Security Engineer – AI, Cloud
1 day ago
bangalore, India Symosis Security Full timeLocation: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our MSSP...
-
Security Engineer
1 day ago
Bangalore Division, India Talentiser Full time🚀 We’re Hiring: Traffic Security Engineer | Bengaluru, India 📍 Location: Bengaluru | 💼 Experience: 5+ years | 🕒 Full-time About the Role We’re looking for a highly skilled Traffic Security Engineer to design and implement scalable, secure, and high-performance networking solutions. The ideal candidate will have deep technical expertise in...
-
Security Engineer
1 day ago
Bangalore Division, India Elucidata Full timeBusiness Unit- General & Administration Job Title- Security Engineer Location- Delhi/ Bangalore (3 days in office) About the Company: Elucidata is an AI Solutions Tech Data-centric AI company on a mission to make life sciences AI-ready. Headquartered in San Francisco with a 120+ member team across the US and India, we’re building the future of data-centric...
-
Cyber Security Engineer
2 weeks ago
Bangalore Division, India Nexoria Techworks Inc. Full timeJob Description: Cybersecurity Engineer Location : Remote / Bangalore Employment Type : Full-time Department : Security & Risk Management Industry : IT Services & Consulting Role Category : Cybersecurity, Information Security, Threat Management Role & Responsibilities : As a Cybersecurity Engineer , you will play a critical role in safeguarding our systems,...
-
Cyber Security Engineer
2 weeks ago
Bangalore Division, India Nexoria Techworks Inc. Full timeJob Description: Cybersecurity Engineer Location : Remote / Bangalore Employment Type : Full-time Department : Security & Risk Management Industry : IT Services & Consulting Role Category : Cybersecurity, Information Security, Threat Management Role & Responsibilities : As a Cybersecurity Engineer , you will play a critical role in safeguarding our systems,...
-
Security Researcher
2 weeks ago
Bangalore Division, India Vehere Full timeJob Summary: We are seeking a seasoned Security Researcher with deep expertise in malware analysis, reverse engineering, and cloud threat research. The ideal candidate will have extensive hands-on experience analyzing advanced malware, uncovering TTPs (Techniques, Tactics, and Procedures) used by threat actors, and aligning their findings with the MITRE...
-
Product Security Specialist
1 day ago
Bangalore Division, India Insight Global Full timeJOB DESCRIPTION We are hiring Product Security Specialists to strengthen our product security capability across penetration testing, AI security, MCP security, mobile app security, web application security, support secure Product development and CIAM. You will drive immediate pen test needs, support global DAS pen test initiatives, help operationalize AI /...
-
Principal Quality Assurance Engineer
2 days ago
Bangalore, India Skyhigh Security Full timeAbout Skyhigh Security: Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world’s data, and because of this, we live and breathe security. Since 2011, organizations have trusted us to provide them with a complete, market-leading security platform built on a modern cloud stack....
-
Principal Quality Assurance Engineer
2 days ago
Bangalore, India Skyhigh Security Full timeAbout Skyhigh Security: Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world’s data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency. Since 2011, organizations have trusted us to provide them with a...