Senior Associate, Cyber/IT Security, Technology and Operations
1 day ago
Business Function\:
Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.
Job Purpose:
The purpose of this job role is to manage Information Security – Internal & External Vulnerability Assessment, Penetration Testing, Application Security Assessment, Source code review follow up, Wireless PT, ATM/POS security Assessment, Secure Configuration Review, Vulnerability management domains to enhance threat detection and mitigation capabilities within the Bank. This role is additionally responsible for enhancing cyber assurance and appropriate regulatory reporting of cyber security aspects.
Key Accountabilities
Vulnerability management and Penetration Testing
Application security
Virtualization and container technologies (Docker, Kubernetes, OpenShift).
API Security
CI/CD assessment
IS Related compliance and regulatory reporting
Job Duties & responsibilities
Vulnerability Management:
Manage periodic internal and external VA scanning for the bank's production systems.
Analyze and report/present the vulnerabilities to multiple stakeholders for remediation and prioritization
Maintain intelligence network to discover any reported exploits, zero day vulnerabilities and its applicability to Bank.
Experience with tools such as Rapid7, Nessus, Metasploit, QualysGuard, etc.
Security Testing & Application Security:
Manage annual security testing program for the existing and new production systems.
Maintain tools and environment to support security testing, working with internal teams and consultants as required
Collaboratively work with Application Development / Security Mavens and guide them to follow the Security gates set in the Organization's SDL.
Evaluate internal Technology Risk Processes as it relates to App Pentest, FOSS, Fortify SCA and provide process governance as well as though leadership concerning adjusting to future needs
Liaison with customer relation and team responsible to address the external requests related to AppSec
Coordinate Security Mavens training and manage monthly meetings
Manage and update Key Performance Indicators (KPI's) for the Application Security Assurance Program
Coordinate with team members and TRM policy management to ensure control standards and policies are up to date
Manage the application security threat modeling process and coordinate application threat models against the Organization's applications
Liaison with various internal teams (Application Development, IT Architecture, Corp. Procurement Services, Source Code Management, IT Asset Management) for Application security initiatives and automation efforts).
Manage new projects and initiatives related to application security as needs arise
Evangelize application security within the firm and work with Application Development Security Mavens to incorporate new program direction into applications
Coordinate with ASAP team members to track internal audit and regulatory assessments and address requests related to the Application Pentest, SAST ,DAST and SCR (Source code review)
Conduct presentations on application security topics for TRM and AD management
Provides regular status updates on all assigned tasks and deliverables.
Maintains issue logs, tracks/follows up on problems.
Mitigates risk by following established procedures and monitoring controls, spotting key errors and demonstrating strong ethical behaviour.
Requirements
Overall 6+ years on experience in Information/Cyber Security
Experience in vulnerability management and application security for 4+ years
Experience in managing 5+ members team which may include vendor teams
Candidate should have worked in BFSI (preferred)
Education / Preferred Qualifications
Graduation\: BE IT/Computers/Electronics, B.Sc - Computers, M.Sc - Computers
Post-Graduation\: PGDIT, MCA, MBA
Certification like CISSP, CISM, SANS, OSCP/OSCE and CREST (Prefered)
Core Competencies
Excellent analytical and decision-making skill sets
Effective in Communication, documentation and report writing skills
Ability to consult and validate solutions to mitigates risks to business and systems
Technical Competencies
VAPT - Rapid7, Nessus, Metasploit, QualysGuard, Burpsuite ,CI/CD tool etc.
Technical working knowledge (WAF, HIDS, IPS, Firewall, Networking
-
Mumbai, Maharashtra, India DBS Bank Full time ₹ 12,00,000 - ₹ 36,00,000 per yearBusiness FunctionTechnology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners...
-
Cyber Security Intern
3 days ago
Mumbai, Maharashtra, India IBI Security Alliances Pvt. Ltd. Full time ₹ 96,000 per yearAbout the RoleWe are looking for a motivated and technically skilled Cyber Security Intern to join our IT & Security team. This internship is ideal for students pursuing degrees in Information Technology, Computer Science, Cyber Security, or related fields who want hands-on experience in real-time security operations, compliance, and threat management.Key...
-
Director of Cyber Security
4 days ago
Mumbai, Maharashtra, India Wenger & Watson Full time ₹ 20,00,000 - ₹ 50,00,000 per yearDirector – Cyber Security (BFSI)Our client is seeking an experiencedDirector – Cyber Securityto lead and grow their BFSI cyber portfolio across the Indian domestic market. This client-facing role demands strong cyber advisory expertise, deep understanding of RBI/SEBI regulations, and proven leadership in delivering security transformation for banks,...
-
Cyber Security Associate
5 days ago
Mumbai, Maharashtra, India ServQual Full time ₹ 12,00,000 - ₹ 36,00,000 per yearLocation: Mumbai, IndiaCompany: ServQual LimitedEmployment Type: Full-time, OnsiteServQual is a global cybersecurity and technology company with offices in the UK, USA, and India, operating on a "Follow-the-Sun" model. We specialize in simplifying cybersecurity and privacy compliance through our AI-driven GRC platform – SUSAN (ServQual Unicorn Security...
-
Cyber Security Engineer
2 weeks ago
Navi Mumbai, Maharashtra, India ReBIT | Reserve Bank Information Technology Pvt. Ltd. Full time ₹ 15,00,000 - ₹ 25,00,000 per yearCompany DescriptionReBIT (Reserve Bank Information Technology Pvt. Ltd.) is a wholly owned subsidiary of the Reserve Bank of India (RBI). Established to cater to the IT needs and cyber security requirements of RBI and its regulated entities, ReBIT focuses on IT and cybersecurity, including related research. ReBIT assists in IT systems audit and assessment...
-
Senior Cyber Security Engineer
1 week ago
Mumbai, Maharashtra, India Quantiphi Full time ₹ 15,00,000 - ₹ 25,00,000 per yearWhile technology is the heart of our business, a global and diverse culture is the heart of our success. We love our people and we take pride in catering them to a culture built on transparency, diversity, integrity, learning and growth. If working in an environment that encourages you to innovate and excel, not just in professional but personal life,...
-
Cyber Security Analyst
6 days ago
Mumbai, Maharashtra, India Wipro Full time ₹ 8,00,000 - ₹ 12,00,000 per yearRole PurposeThe purpose of this role is to analyse, identify, rectify & recommend specific improvement measures that help in the security posture of the organization by protecting the sensitive information*Do* *Ensuring customer centricity by providing apt cybersecurity*Monitoring and safeguarding the log sources and security accessPlanning for disaster...
-
Cyber Security Specialist
4 days ago
Mumbai, Maharashtra, India Reliance Infrastructure Full time ₹ 8,00,000 - ₹ 24,00,000 per yearWe are seeking an experienced and proactive Cyber Security professional to strengthen the organization's information security posture. The ideal candidate will be responsible for implementing, monitoring, and maintaining security measures to protect systems, networks, and data from cyber threats. This role requires hands-on technical expertise, a strong...
-
Cyber Security Trainer
1 week ago
Mumbai, Maharashtra, India L&T Technology Services Ltd. Full time ₹ 12,00,000 - ₹ 36,00,000 per yearLTTS IndiaMumbaiJob Description3.5.1 Cyber Security TrainerDesired ProfileQualification Bachelors or Masters in Computer Science / Electronics / Information Technology /Information Security / Cyber Security / Digital Forensics / Computer Applications,or equivalent - greater qualification and experience shall be given due weightage. Bug bounty program...
-
Senior Cyber Security Analyst
1 week ago
Navi Mumbai, Maharashtra, India Esds Software Solutions Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWe are seeking a seasoned cybersecurity professional to be a part of our security operations and product management function. This role involves managing a team of security engineers and analysts who handle a wide range of security technologies including AV, EDR, XDR, PIM, PAM, DLP, DAM, WAF, and more.You will be responsible for end-to-end security delivery...