25 Aug
|
Open financial technologies
|
Bengaluru
25 Aug
Open financial technologies
Bengaluru
– Senior Security Analyst
About Open
Open is an AI-native Corporate Internet Banking platform built for modern finance teams. It brings together banking, treasury, payments, collections, reconciliation, compliance and financial controls into a single intelligent workspace. By connecting with 40+ banks and 1,000+ finance systems, Open enables businesses to manage cash, automate finance operations and move money with complete visibility and control—without replacing their existing banking relationships.
Founded in 2017, Open is a billion-dollar fintech enterprise backed by Google, Visa, Temasek, Tiger Global, ICICI Bank, 3one4 Capital, Beenext, Unicorn India Ventures, Speedinvest, IIFL Finance and SBI Group Japan. In 2022, Open became India's 100th Unicorn and is licensed by the RBI for PA/PG services.
Open has been recognised as Best Workplace 2024 by IEEE, featured among Forbes India's Top 10 Companies and D Globalist's Top 200 Companies, while also winning Best Digital Banking Solution at Global Fintech Fest 2022, Most Innovative Neo Bank in 2021 and Most Innovative Digital Bank by IAMAI.
To build and strengthen our superpower, we're looking for an exceptional Senior Security Analyst who will play a pivotal role in scaling the finance function and partnering with leadership to drive Open's next phase of growth.
Experience:- 5-8 Years
Location:- Bangalore
Responsibilities
Vulnerability Management & VAPT
- Own quarterly network VAPT execution and reporting: internal vulnerability assessment (IVA), external vulnerability assessment (EVA), ASV scans, and card data (PCI) scans.
- Manage the AWS patching cycle across UAT and Prod, producing the monthly patching report.
- Run vulnerability assessments on cloud instances and public IPs; track remediation and validate fixes.
Application Security
- Run on-demand AppSec activities: secure code review (SCR), SAST (including SBOM/CBOM reporting),and DAST,
raising and tracking remediation tickets with development teams.
- Perform containerized application security assessments.
- Validate bug bounty submissions and drive valid findings to closure with engineering.
- Monitor and follow up on GitHub secret-scanning alerts.
- Prepare AppSec findings reports and drive remediation to closure with dev teams.
- Manage Jira AppSec tickets end-to-end for internally raised issues.
Cloud Security
- Monitor cloud security alerts and investigate misconfigurations or exposure risks.
- Run POCs and evaluate CSPM tooling (e.g., AccuKnox, Orca, Wiz) to strengthen cloud posture.
- Security Operations & Detection
- Monitor, triage, and investigate SOC alerts (EDR/CrowdStrike, SIEM) and cloud security alerts across production environments.
- Fine-tune SIEM detection/correlation rules in partnership with the MSS/SOC team; maintain log ingestion pipelines (including manual log pushes where automation is pending).
- Investigate phishing emails and lead technical incident response for confirmed threats.
- Perform malware analysis and forensic investigation using tools such as FTK Imager, Volatility,Wireshark, and CAINE.
Data Loss Prevention
- Monitor DLP alerts, troubleshoot user-reported DLP issues, and fine-tune DLP rules and server-level configuration.
Other
- Ad-hoc activities: log ingestion troubleshooting, periodic detection-rule verification, automation
- feasibility assessments.
Requirements
- Bachelor's degree (or higher) in Computer Science or a related discipline.
- 5 years of relevant,
hands-on security experience.
- Proven experience in a Security Operations Center (SOC), with strong grounding in incident
- response methodology.
- Hands-on experience with an EDR/endpoint security tool and associated incident response
- workflows (e.g., CrowdStrike).
- Experience with SIEM platforms: log ingestion, parsing, correlation rule creation, use-case
- development, and regex.
- Hands-on experience with at least one CSPM platform (e.g., Wiz, Orca, AccuKnox, or similar),
- including running assessments and evaluating findings.'
- Experience in malware analysis, incident investigation, and forensic tooling (FTK Imager,
- Volatility, Wireshark, CAINE).
- Experience with vulnerability management: assessment, remediation tracking, validation,
- and patch management.
- Working knowledge of firewalls, IDS/IPS, and network security controls.
- Familiarity with threat hunting concepts and the ability to identify IOCs and IOAs.
- Experience with containerized application security assessments.
- Understanding of the software development lifecycle and DevOps practices.
- Valuable verbal and written communication skills for working with engineering teams.
Why Work at Open?
- Be part of the tribe that's redefining the future of corporate banking and finance.
- Build finance systems and processes that power millions of businesses.
- Work directly with founders, leadership, investors and some of the brightest minds in fintech.
- Own high-impact initiatives with the freedom to drive meaningful change.
- Experience a culture where ownership, innovation, growth and fun go hand in hand.
- Collaborate in an AI-first company that is shaping the next generation of financial infrastructure.
- Competitive compensation, ESOPs and the opportunity to create long-term value while building one of India's most exciting fintech companies.
📌 Senior Security Analyst (Bengaluru)
🏢 Open financial technologies
📍 Bengaluru