06 Aug
|
Pay10 India
|
New Delhi
06 Aug
Pay10 India
New Delhi
Role & responsibilities :
Security Operations (SOC)
- Lead end-to-end SOC operations, including monitoring, detection, investigation, and response
- Perform alert triage, incident analysis, and root cause identification
- Ensure compliance with RBI incident reporting timelines and guidelines
2. Network & Infrastructure Security
- Design, implement, and manage network security controls (Firewalls, VPNs, WAF, IDS/IPS)
- Enforce system hardening, patch management, and centralized logging
- Conduct vulnerability assessments and ensure timely remediation
- Maintain network architecture documentation and baseline configurations
- Ensure compliance with data localization requirements
3. Cloud & Application Security
- Implement and monitor security controls across AWS/Azure environments
- Deploy IAM, CSPM, and workload protection solutions
- Integrate DevSecOps practices into CI/CD pipelines (SAST/DAST)
- Conduct application security assessments aligned with OWASP Top 10
- Secure APIs and application integrations
4. Threat & Vulnerability Management
- Manage the complete vulnerability lifecycle (identification to remediation)
- Conduct VAPT and red team exercises
- Maintain centralized vulnerability register and reporting
- Leverage threat intelligence for proactive risk mitigation
5. Identity & Access Management (IAM/PAM)
- Define and enforce IAM and PAM policies
- Implement MFA, least privilege access, and SSO controls
- Conduct periodic access reviews and entitlement audits
- Maintain audit logs for privileged access activities
6. Governance, Risk & Compliance (GRC)
- Ensure compliance with RBI, PCI DSS, and ISO 27001 frameworks
- Perform risk assessments and maintain the risk register
- Conduct vendor risk assessments (TPRM)
- Develop and maintain security policies, procedures, and SOPs
- Track risk mitigation and acceptance timelines
7. Incident Response & Business Continuity
- Maintain and periodically test the Incident Response Plan (IRP)
- Conduct incident simulations and tabletop exercises
- Lead post-incident reviews and corrective actions
- Ensure BCP and DR readiness as per defined RTO/RPO
8. Awareness, Documentation & Reporting
- Conduct security awareness and phishing simulation programs
- Maintain documentation for incidents, risks, vulnerabilities, and audits
- Develop dashboards and KPI/KRI reports for management
Preferred candidate profile :
Required Qualifications
- Bachelors degree in Cybersecurity, Information Technology, or related field
- 4–6 years of experience in cybersecurity operations and GRC
- Experience in RBI-regulated environments (Banking/FinTech mandatory)
- Strong understanding of RBI IT Framework, PCI DSS, and ISO 27001
Preferred Certifications
- CISM / CISA
- Security+ / CEH
- ISO 27001 Lead Implementer / Auditor
Technical Skills
- SIEM, EDR, and SOAR platforms
- Network security technologies (Firewalls, IDS/IPS, WAF)
- Vulnerability management tools
- Cloud security (AWS/Azure)
- Container and API security
Soft Skills
- Strong analytical and problem-solving abilities
- Effective communication and stakeholder management
- Proactive and structured approach to security
- Robust collaboration across cross-functional teams
Key KPIs / Deliverables
- Improved incident detection and response time (MTTD/MTTR)
- Vulnerability remediation within defined SLAs
- Timely closure of audit findings
- Optimization of SIEM alerts and use cases
- Compliance adherence across RBI, PCI DSS, and ISO 27001
📌 Technical Security Lead Information Security (New Delhi)
🏢 Pay10 India
📍 New Delhi