28 Sep
|
Ventura
|
Mumbai
About the Company:
n
nVentura is an omnichannel trading and investment platform with a network of branches, sub-brokers and Digital Channels. Founded in 1994, the company is entering the next phase of growth by pivoting to a digital-first approach and strengthening its direct-to-consumer franchise. The company has carved out a separate fintech vertical tasked with digital transformation using cutting-edge technology and bringing in fresh talent.
n
nWhat you'll get:
n
nVulnerability Management & Penetration Testing:
n
n
- Conduct vulnerability assessments and penetration testing (VAPT) for web applications, networks APIs, Mobile, Cloud (AWS) and infrastructure.
n
- Embed security testing in CI/CD (SAST/DAST, dependency/SBOM scans) and track remediation SLAs.
n
- Analyze and mitigate OWASP Top 10, SANS 25 and business-logic flaws; coach developers on secure patterns.
n
- Prioritize vulnerabilities based on risk levels and provide actionable remediation strategies.
n
- Work with development and infrastructure teams to validate and verify vulnerability fixes.
n
n
nSecurity Assessment & Risk Analysis:
n
n
- Perform comprehensive security assessments of client systems, networks, and applications to identify
n
- vulnerabilities and security gaps.
n
- Conduct risk assessments and threat modeling to evaluate potential cyber threats and business
n
- impacts.
n
- Analyze existing security controls and recommend improvements based on industry best practices.
n
- Document findings and present detailed risk assessment reports to stakeholders.
n
n
nSecurity Policies & Governance:
n
n
- Develop, review, and maintain information security policies, standards, and procedures.
n
- Assist organizations in implementing security governance frameworks.
n
- Ensure policies align with industry standards and organizational security objectives.
n
- Support the development of incident response plans and business continuity strategies.
n
n
nCompliance & Security Audits:
n
n
- Conduct security audits and gap assessments against regulatory and compliance frameworks.
n
- Support compliance initiatives related to SEBI CSCRF, ISO 27001, DPDP, GDPR, NIST, and SOC 2.
n
- Prepare audit documentation and assist during internal and external security audits.
n
- Monitor compliance status and recommend corrective actions.
n
n
nIncident Response Support:
n
n
- Assist in investigating security incidents and cyber threats.
n
- Analyze logs and security alerts to identify potential attacks.
n
- Support incident response teams in containment, remediation, and recovery activities.
n
- Provide post-incident analysis and recommend security improvements.
n
n
nWhat you’ll need to bring:
n
n
n
- 3-8 years of relevant experience in Cybersecurity domain
n
- Proven hands-on VAPT for Web/Mobile/API and Network/ Cloud assessments.
n
- Solid knowledge of OWASP Top 10 (attacks and defenses).
n
- Security best practices for AWS, Azure, and Google Cloud
n
- Data protection and encryption in cloud environments
n
- Experienced in security tools such as Burpsuite, Nessus, Qualys, Metasploit, and Nmap, Trivy to identify vulnerabilities.
n
- Ability to review and add WAF rulesets in AWS WAF and Modsecurity according to business requirements.
n
- Working knowledge of cloud security and core components in AWS(e.g., S3, Load Balancers, Kubernetes, Docker).
n
- Experienced in audit planning and execution
n
- Compliance management for frameworks such as SEBI CSCRF, ISO 27001, GDPR, and NIST
n
- Detailed understanding of IT General Controls (ITGCs) and their implementation.
n
- Experience working in BFSI industry (Broking industry candidates will be preferred)
n
- Preferred Certifications: Certified Ethical Hacker (CEH), ISO27001:LA/LI, CISA, CISSP
n
📌 Cybersecurity Engineer (VAPT) (Mumbai)
🏢 Ventura
📍 Mumbai