28 Aug
|
Deutsche Borse Group
|
Hyderabad
28 Aug
Deutsche Borse Group
Hyderabad
About Deutsche Börse Group:
Headquartered in Frankfurt, Germany, Deutsche Börse Group is a leading international exchange organization and market infrastructure provider. They empower investors, financial institutions, and companies by facilitating access to global capital markets.
Their India centre is located in Hyderabad, serves as a key strategic hub and comprises Indias top-tier tech talent. They focus on crafting advanced IT solutions that elevate market infrastructure and services. Deutsche Börse Group in India is composed of a team of capital market engineers forming the backbone of financial markets worldwide.
Job Description
AI Security Specialist Vulnerability Management
Your area of work:
The Group Security department directly contributes to execution of the Deutsche Börse Group information security strategy. As a central service provider for the Group entities, Group Security is responsible to protect information assets, incl. suppliers, in terms of safety, integrity, confidentiality, authenticity and availability by enforcing information security controls based on the relevant regulatory requirements and follows the international standard ISO/IEC 27000-series on the Information Security Management System.
Your responsibilities:
In your position, you will provide AI security expertise in support to the business and in line with the key responsibilities:
- AI-Driven Prioritization: Implement and refine AI/ML models to analyse vulnerability data alongside business context, threat intelligence, and runtime data to dynamically prioritize risks (moving beyond basic CVSS scores).
- Build AI Security Tooling: Develop and deploy AI-assisted vulnerability discovery tools and autonomous agents (using LLMs, custom models,
and APIs) to scan codebases, identify complex vulnerability patterns, and validate findings.
- Automated Remediation: Create AI-powered remediation workflows that automatically generate fix recommendations, secure code patches, and pull requests for developers, accelerating the path from "finding" to "fixing".
- Integrate AI into the Security Stack: Adapt and upgrade existing vulnerability management processes by integrating emerging AI capabilities into standard scanning tools (e.g., Tenable/Nessus, GitLab, Fortify, Snyk).
- Reduce False Positives: Train and utilize machine learning models to filter out noise and false positives from traditional security scanners, ensuring engineering teams only receive high-fidelity, actionable tickets.
- CI/CD & Developer Guardrails: Build automated guardrails within CI/CD pipelines that leverage AI to prevent common security issues from reaching production in the first place.
- Lead DBG System Security initiatives (Vulnerability and Compliance checks for system hardening, Vulnerability Notification, Source Code Scan, quality checks of reported results, Tracking and Monitoring of remediation of open findings in IT and regular Reporting)
- Provide guidance to the IT for re-engineering of processes and procedures required for remediation, recommend, and track corresponding actions.
Cooperate at the resolution of critical audit findings.
- Expertise in Cloud principles and risks associated with Public and Hybrid cloud.
- Perform Risk Assessments of Security Architecture and solution mitigation of identified risks.
- Developing expertise in Cloud through CNAPP solution for GS
Your profile:
- Education:Bachelors degree in Computer Science, Cybersecurity, Data Science, or equivalent practical experience.
- Experience:
- 1+ years of hands-on experience in vulnerability management, application security, or infrastructure security.
- 1+ years of experience building security automation, scripting, or integrating AI/LLM APIs (e.g., OpenAI, Claude, LangChain) into engineering workflows.
- Technical Skills:
- Robust proficiency inPythonand building API integrations.
- Deep familiarity with traditional vulnerability scanners and AST tools (e.g., Nessus, Rapid7, Fortify, Jfrog, GitHub Advanced Security).
- Experience with cloud environments (AWS, Azure, or GCP) and modern CI/CD pipelines.
- Understanding of how to apply LLMs and prompt engineering to analyze code and structured security data.
- Soft Skills:A builder mindset. You prefer writing code and building automation to solve problems rather than manually managing tickets. Strong collaboration skills to work with developer teams on automated patching workflows.
Highly desirable:
- Experience building autonomous security agents or using agentic AI frameworks.
- Familiarity with risk-prioritization frameworks like EPSS (Exploit Prediction Scoring System) and threat intelligence feeds.
- Experience with infrastructure-as-code (IaC) security and container security.
📌 Senior Associate - Lead Security Engineer (Hyderabad)
🏢 Deutsche Borse Group
📍 Hyderabad