24 Sep
|
DMI Finance
|
New Delhi
24 Sep
DMI Finance
New Delhi
Job Title Security Analyst Information Securit- VAPT
Function / Department IT — Information Security
1. JOB PURPOSE
Own and execute the technical security assurance function for DMI Group — identifying, validating and driving closure of security weaknesses across applications, APIs, cloud, network and endpoint estate before they can be exploited, and evidencing that control posture to the Board, regulators and auditors. The role combines offensive assessment (VA/PT of in-house, partner and vendor-hosted systems),
defensive operations (SOC / EDR / SIEM / WAF / DLP oversight and incident response), secure-by-design review of new platforms and cloud deployments, and the governance work required by the RBI Master
Directions on IT Governance and Cyber Security, the DPDP Act 2023, CERT-In Directions and ISO
27001:2022 — supported by internal automation and tooling that makes the above repeatable and auditable at NBFC scale.
1. PRINCIPAL ACCOUNTABILITIES
A. Vulnerability Assessment ; Penetration Testing (VAPT)
- Plan and execute VA/PT across web applications, mobile applications, REST/API layers, internal
and internet-facing network segments, servers, endpoints and cloud workloads — for in-house platforms (loan origination and servicing, KYC, collections, partner portals) as well as group entities and partner-hosted systems.
- Perform authenticated and unauthenticated assessments; establish authorisation test coverage
(IDOR / BOLA / privilege escalation), business-logic abuse cases, injection and session- management testing aligned to OWASP Top 10, OWASP API Top 10, OWASP MASVS and MITRE
.
- Score every finding using CVSS v3.1 with a defensible vector; capture reproducible proof-of-
concept evidence and steps to reproduce; maintain a negative-findings register recording vectors tested and confirmed non-exploitable.
- Operate and tune assessment tooling — Tenable WAS / VM, Nessus, Burp Suite, Nmap, Kali
toolchain, mobile and API testing utilities — and validate scanner output to eliminate false positives before publication.
- Conduct pre-go-live security testing for new applications, releases and third-party integrations;
issue formal sign-off or hold recommendations.
- Perform retesting and closure verification; findings are closed only on evidence, not on assertion.
B. Finding Management, Remediation Advisory & SLA Governance
- Maintain the consolidated VAPT finding register across all assessments and scanning platforms,
with normalised severity, status, ownership and ageing fields.
- Track remediation against defined SLAs by severity; report ageing, breached SLAs, resurfaced (re-
opened) findings and repeat root causes to management.
- Issue precise, directive remediation guidance to engineering teams — including object-level
authorisation scoping, server-enforced pagination and rate limiting, PII field-level masking and tokenisation, secrets handling, and secure configuration baselines — in language that is directly actionable and defensible to stakeholders.
- Define and defend data-exposure standards for API responses, including which customer
attributes must never be returned in full to a client under any circumstance.
- Run remediation review forums with development, infrastructure and vendor teams; arbitrate
risk-acceptance requests and record compensating controls. C. Security Operations, Monitoring & Incident Response
- Oversee day-to-day SOC output — alert triage, escalation and closure quality — across SIEM, EDR,
WAF, DLP, CASB, email security and NGFW telemetry,
operating within the maker / checker / approver control workflow.
- Investigate incidents and suspected compromise; establish scope and impact; document root
cause analysis, corrective and preventive actions, and maintain the RCA register with action-plan tracking to closure.
- Maintain and periodically test the incident response and disaster recovery playbooks; ensure
statutory and regulatory notification timelines are met, including CERT-In six-hour incident reporting and applicable RBI and DPDP Board notification obligations.
- Monitor threat intelligence, advisories and open-source / OSINT exposure relating to the Group's
brands, domains and data; convert relevant intelligence into detection or remediation actions.
- Track and report operational security metrics — attack volumes, blocked events, detection
coverage, MTTD/MTTR and control effectiveness. D. Cloud, Infrastructure & Network Security
- Review and design security architecture for AWS-hosted workloads — VPC segmentation, security
Security Analyst (InfoSec & VAPT) | groups, IAM least privilege, KMS and Secrets Manager usage, ALB/WAF placement, private connectivity, logging and backup — including production-ready deployment runbooks for new platforms.
- Operate cloud security posture management (CSPM); drive misconfiguration closure and maintain
baseline hardening standards for EC2, RDS, S3 and container workloads.
- Support Zero Trust Network Access rollout and secure remote-access architecture (Netskope
Private Access / publishers, steering configuration, private application definitions and access policy), replacing broad network-level access with per-application authorisation.
- Review firewall, WAF and proxy policy — rule hygiene, tiered logging strategy, bandwidth and
licence utilisation, tuning of blocking policy — and manage the technical relationship with the platform vendors on the same.
- Ensure encryption in transit and at rest, certificate lifecycle management, and data residency
requirements applicable to a regulated NBFC are met by design. E. Governance, Risk, Audit & Regulatory Compliance
- Map the control environment to RBI Master Directions on IT Governance, Risk and Controls and
the Cyber Security Framework, DPDP Act 2023, CERT-In Directions, ISO 27001:2022 and PCI-DSS where applicable.
- Author and maintain information security policies, standards, SOPs and framework documents —
including acceptable-use and emerging-technology governance (e.g. Generative AI usage) — and take them through management and Board-level approval.
- Maintain data-protection artefacts: Record of Processing Activities, DPIA register, third-party
processor register, data-principal rights and breach-response procedures.
- Build and run the annual security audit and assessment calendar; maintain evidence trails and
control-testing artefacts for internal audit, statutory / Big-4 audit, ISO certification cycles and RBI inspection.
- Prepare and present periodic security reporting to the CISO, Information Security Committee, IT
Strategy Committee and Board — including posture dashboards, VAPT status, audit action-tracker (ATR) closure and budget utilisation.
F. Third-Party, Vendor & Partner Security
- Perform security due diligence and periodic reassessment of vendors, fintech partners and service
providers handling Group systems or customer data.
- Define security requirements, technical questionnaires and control obligations for inclusion in
contracts, SOWs and renewals; track vendor SLA and contractual security commitments to closure.
- Review and challenge vendor assessment reports, attestations and remediation claims; escalate
residual risk formally. G. Security Automation, Tooling & Engineering
- Design and build internal security tooling to automate assessment, tracking, orchestration and
reporting workflows — reducing manual effort and producing consistent, audit-ready output.
- Automate the control-monitoring and finding-orchestration pipeline (intake, enrichment,
assignment, approval, escalation and reporting) across SOC, VAPT, EDR and CSPM streams.
- Integrate security data sources and ticketing systems; maintain dashboards and management
reporting packs.
- Apply the Group's own data-handling and AI-usage controls when using automation or AI-assisted
tooling in security workflows. H. Awareness, Culture & Advisory
- Run security awareness initiatives — training content, phishing simulations, targeted briefings for
high-risk functions — and report participation and outcome metrics.
- Act as the security advisory point for product, engineering, credit, operations and compliance
teams during design and change; embed security requirements early rather than at release.
Educational Qualifications
- Minimum qualification: Any Graduate (B.E. / B.Tech / BCA / B.Sc. in Computer Science or
Information Technology preferred).
- Preferred certifications: CEH, OSCP, eWPTX / eMAPT, CompTIA Security+, AWS Certified Security
— Specialty, ISO 27001 Lead Auditor / Lead Implementer, CISA or CISM for the governance component.
Work Experience
- Minimum 2-5 years of hands-on information security experience; BFSI, NBFC or security-consulting
exposure strongly preferred.
- Demonstrated delivery of web, mobile, API and network VA/PT with independently written,
evidence-backed reports.
- Working knowledge of AWS security services and cloud architecture review.
- Exposure to SOC operations and the SIEM / EDR / WAF / DLP / CASB / NGFW control stack.
- Familiarity with the RBI IT Governance and Cyber Security Frameworks, DPDP Act 2023, CERT-In
Directions, ISO 27001:2022 and PCI-DSS.
- Forensics and incident investigation fundamentals; OSINT and open-source monitoring.
Technical Skills
- Assessment: Burp Suite, Tenable WAS/VM, Nessus, Nmap, Kali toolchain, mobile and API testing
tooling, CVSS v3.1.
- Cloud & infrastructure: AWS (EC2, VPC, IAM, RDS, S3, KMS, Secrets Manager, ALB/WAF,
CloudTrail), Linux, Docker, network fundamentals.
- Security platforms: SIEM, EDR, WAF, DLP, CASB, NGFW, ZTNA / SASE, email security.
- Automation & reporting: Python, scripting, SQL, Excel-based analysis and dashboarding; API
integration with security and ticketing platforms.
- Documentation: audit-grade report writing, policy and SOP authoring, management and Board-
level reporting.
Behavioural Skills
- Accurate, directive written communication — able to state a control requirement a developer can
act on and a stakeholder can defend.
- Evidence discipline: claims are supported, findings are reproducible, closures are verified.
- Cross-functional collaboration with engineering, infrastructure, product, compliance, audit and
external vendors.
- Ownership and escalation judgement — knows what to resolve, what to flag, and when.
📌 Security Analyst (New Delhi)
🏢 DMI Finance
📍 New Delhi