Cyber Security Lead Analys

Societe Generale Global Solution Centre

Bengaluru

On-site

INR 800,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Societe Generale Global Solution Centre seeks an experienced Cyber Security Analyst to manage security aspects of banking service platforms, ensuring compliance with GDPR, NIST, and ECB standards. You will collaborate with cross-functional teams to deploy security controls, conduct ASA and risk reviews, and promote secure by design across the SDLC.

The role requires hands-on expertise in application security, vulnerability management, and cloud security, with the ability to communicate

Qualifications

  • 3 to 6 years of experience in the IT security field with good knowledge in information security.
  • Able to understand architecture issues to develop security policies or recommendations and discuss with architects/project managers.
  • Good knowledge of SDLC and hands-on security environments/activities.
  • Knowledge on Application Security/Vulnerability Management/ Cloud Security/ Threat modeling.
  • Awareness of digital technologies and understanding of business processes.
  • Ability to propose process improvements, document and consolidate security subject matter.
  • Knowledge on Cloud, Infra, Firewalls, Routers and Wifi.
  • Experience with Java, API, ASP.Net, Spark, Python, React.js.
  • Exposure to security tools like Qualys, Nessus, Nmap, Burp Suite, SonarQube, Netsparker, OWASP and related security tests.

Responsibilities

  • Perform security aspects of a portfolio of banking service platforms and applications by implementing/completing compliance projects with functional/technical teams.
  • Assist teams through major evolutions on platforms and applications, understanding architecture, functionalities, and security policies.
  • Ensure compliance with ECB Audit, NIST, GDPR, NYDFS, SECAIA and SG group security criteria.
  • Improve and maintain security levels of applications and platforms in line with regulatory requirements.
  • Collaborate with application and technical teams to deploy, troubleshoot and maintain security solutions.
  • Prepare BAU and key program reports and communicate with project stakeholders.
  • Plan and organize follow-up actions; autonomy is required.
  • Independently perform ASA, security control assessments, and provide recommendations.
  • Conduct risk reviews and manage derogation/ad-hoc validations; maintain risk acceptance documents per guidelines.
  • Drive Secure by Design throughout SDLC and train teams on secure design and latest technologies.

Skills

Application Security
Vulnerability assessment
Penetration testing
Risk Management
Cloud Security
API Security
Vulnerability management
DevSecOps
Customer interactions
Communication skills

Tools

Qualys
Nessus
Nmap
Burp suite
SonarQube
netspaker
OWSAP
Open-Source tool for Security Tests

Job description

  • Performing security aspects of a portfolio of banking service platforms and applications by implementing/contributing compliance projects to the functional and technical team.
  • Assisting functional and technical teams throughout the major evolutions on platforms and applications. This focus will be a big part of the scope of work and requires understanding of the architecture, functionalities, and security policies.
  • Follow compliance level of Applications adhering to global audit and regulatory programs (ECB Audit, NIST, GDPR Compliance, NYDFS & SECAIA).
  • Improve and maintain the level of security of applications and platforms, in compliance with regulatory requirement and SG group security criteria.
  • Collaborate with application team and technical teams, to deploy, troubleshoot and maintain required security solutions with compliancy to security criteria.
  • Responsible for report preparation on BAU, key programs and maintain a good level of communication with different stakeholders of the projects.
  • Plan, organize and insure follow up actions and action plans, therefore being autonomous is a must for this role.
  • Independently perform Application Security Assessment (ASA), Security control assessment and provide security recommendations.
  • Perform risk review and work on derogation// ad-hoc request validations. Also maintain risk acceptance documents as per the group guidelines.
  • Drive Secure by design throughout SDLC of the applications.
  • Demonstrate and train teams on Secure by design and latest security technologies.

Reference 26000EHP

Responsibilities
Cyber Security Analyst –
  • Performing security aspects of a portfolio of banking service platforms and applications by implementing/contributing compliance projects to the functional and technical team.
  • Assisting functional and technical teams throughout the major evolutions on platforms and applications. This focus will be a big part of the scope of work and requires understanding of the architecture, functionalities, and security policies.
  • Follow compliance level of Applications adhering to global audit and regulatory programs (ECB Audit, NIST, GDPR Compliance, NYDFS & SECAIA).
  • Improve and maintain the level of security of applications and platforms, in compliance with regulatory requirement and SG group security criteria.
  • Collaborate with application team and technical teams, to deploy, troubleshoot and maintain required security solutions with compliancy to security criteria.
  • Responsible for report preparation on BAU, key programs and maintain a good level of communication with different stakeholders of the projects.
  • Plan, organize and insure follow up actions and action plans, therefore being autonomous is a must for this role.
  • Independently perform Application Security Assessment (ASA), Security control assessment and provide security recommendations.
  • Perform risk review and work on derogation// ad-hoc request validations. Also maintain risk acceptance documents as per the group guidelines.
  • Drive Secure by design throughout SDLC of the applications.
  • Demonstrate and train teams on Secure by design and latest security technologies.
Profile Required
  • 3 to 6 years of experience in the field of IT security with good Knowledge in information security.
  • Able to understand architecture issues in order to develop security policies or relevant recommendations on applications and projects. Also, should be able to discuss on an equal footing with the community of architects and project managers of the applications concerned.
  • Good knowledge on SDLC and hands-on experience in Security Environments and activities.
  • Knowledge on Application Security/ Vulnerability Management/ Cloud Security/ Thread modeling.
  • Awareness of digital technologies and understanding of functional domain and business processes.
  • Good in identifying & proposing process improvements, documentation preparation and consolidation on process/technical subject related to Security.
  • Knowledge on Cloud an network Security,IAM, Data encryption, SIEM.
  • Understanding on regulatory programs like GDPR, NYDFS, SCHREMS, DORA etc...
  • Knowledge on Cloud, Infra, Firewalls, Routers and Wifi
  • Exposure to JAVA, API, ASP.Net, Spark, Python, react.js languages and technologies respectively.
  • Exposer on security Tools – Qualys, Nessus, Nmap, Burp suite, SonarQube, netspaker, OWSAP, Open-Source tool for Security Tests.
  • Proper Work Ethics, Adaptability, Interpersonal skills and Problem-Solving Capabilities.
Mandatory Skills
  • Application Security/ Vulnerability assessment and penetration testing/ Risk Management/ Cloud Security/ API Security/ Vulnerability management/DevSecOps
  • Customer/ Business interactions
  • Good communication skills with negotiation and influencing skills. Especially the ability to persuade and influence others.
Why join us

At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious.

Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating and taking action are part of our DNA.

If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!

Still hesitating?

You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices and sharing their skills with charities. There are many ways to get involved.

We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection

Business insight

At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious.

Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating and taking action are part of our DNA.

If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!

Still hesitating?

You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices and sharing their skills with charities. There are many ways to get involved.

We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Lead Analyst
Cyber Security Lead Analyst

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Security Architect
Security Architect

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 3,000,000 - 4,200,000
Cyber Security Senior Analyst - Pentesting
Cyber Security Senior Analyst - Pentesting

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Cyber Security Senior Analyst
Cyber Security Senior Analyst

SGS Société Générale de Surveillance SA • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Senior Analyst - Market Risk/PNL
Senior Analyst - Market Risk/PNL

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 800,000 - 1,200,000
Cyber Security Senior Analyst
Cyber Security Senior Analyst

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,200,000 - 1,600,000
Lead Systems Engineer - Network Security
Lead Systems Engineer - Network Security

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Analyst - Market Risk/PNL
Senior Analyst - Market Risk/PNL

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 700,000 - 900,000
Lead Devops Engineer - IBM Urban Code & AWX - IT (Information Technology) - Bangalore, India
Lead Devops Engineer - IBM Urban Code & AWX - IT (Information Technology) - Bangalore, India

SGS Société Générale de Surveillance SA • Bengaluru

On-site
INR 2,000,000 - 2,900,000
Lead Software Engineer – IT Infrastructure
Lead Software Engineer – IT Infrastructure

SGS Société Générale de Surveillance SA • Bengaluru

On-site
INR 700,000 - 1,100,000