Lead Information Security Engineer

InCred Financial Services

Bengaluru

On-site

INR 3,500,000 - 6,500,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

InCred Financial Services is seeking an Information Security Lead with 8–10 years of hands-on experience to steer enterprise cyber defense, SOC operations, and regulatory compliance. You will oversee endpoint security, DLP, ZTNA, and network security while aligning controls with RBI/SEBI directives.

Responsibilities include 24/7 SOC oversight, incident response, DRM/RCA, tabletop exercises, and governance across GRC requirements. Strong tooling, such as EDR/XDR, DLP, and SIEM/SOAR, is essential.

Qualifications

  • 8–10 years of core Information Security experience with hands-on management across Security Operations, Infrastructure Security, and GRC.
  • Deep familiarity with RBI Cybersecurity Framework, SEBI CSCRF guidelines, CERT-In directives, and DPDP Act requirements.
  • Hands-on tooling knowledge on EDR/XDR, DLP, ZTNA/Network Security, SIEM/SOAR tools.

Responsibilities

  • Lead 24/7 Security Operations (SOC) oversight, threat hunting, and incident management workflows.
  • Manage high-severity incident response procedures, forensic investigations, RCA, and regulatory notifications (CERT-In 6-hour window).
  • Design, execute, and evaluate tabletop exercises and Cyber Crisis Management Plans (CCMP).
  • Oversee network security infrastructure, including NGFW, IPS, and secure web gateways; conduct architecture reviews and vulnerability management.

Skills

Security Operations
GRC & Compliance
EDR/XDR & DLP
ZTNA & Network Security
SIEM/SOAR

Tools

EDR/XDR
SIEM/SOAR
NGFW/IPS/SWG

Job description

We are looking for an experienced Information Security Lead with 8-10 years of hands-on expertise to lead our enterprise Cyber Defense, Security Operations, and Regulatory Compliance posture. In this role, the candidate will oversee core security technologies—including Endpoint Security, Data Loss Prevention (DLP), Zero Trust Network Access (ZTNA), and Network Security—while managing Incident Response and SOC operations. The candidate will be directly responsible for aligning security controls with key Regulatory frameworks, specifically guidelines issued by the Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), and other associated bodies (e.g., CERT-In, IRDAI, NCIIPC).

Key Responsibilities
1. Security Operations & Incident Response
  • Lead 24/7 Security Operations (SOC) oversight, threat hunting, and incident management workflows.
  • Manage high-severity incident response (IR) procedures, forensic investigations, root-cause analyses (RCA), and mandatory regulatory notifications (e.g., CERT-In 6-hour incident reporting window).
  • Design, execute, and evaluate periodic tabletop exercises and Cyber Crisis Management Plans (CCMP).
2. Endpoint Security, DLP & ZTNA
  • Manage, configure, and optimize EDR/XDR platforms for host-level protection and threat containment.
  • Architect and refine enterprise Data Loss Prevention (DLP) strategies across endpoints, email, web gateways, and cloud stores to prevent exposure of sensitive financial/customer data.
  • Lead implementation and governance of Zero Trust Network Access (ZTNA) solutions to replace legacy VPNs and enforce least-privilege access.
3. Network Security & Infrastructure
  • Oversee firewalls (NGFW), Intrusion Prevention Systems (IPS) and secure web gateways (SWG).
  • Conduct regular network architecture reviews, micro-segmentation governance, and vulnerability management across on-premises and multi-cloud environments.
  • Perform periodic configuration audits of active directory, network switches, routers, and VPN gateways.
4. Regulatory Compliance & Governance (GRC)
  • Maintain continuous alignment with regulatory security frameworks including RBI Cybersecurity Framework for Banks/NBFCs/PPIs, SEBI Cybersecurity & Cyber Resilience Framework (CSCRF), and CERT-In directives.
  • Direct internal and external security audits, risk assessments, regulatory reporting, and vulnerability closures requested by statutory auditors or regulators.
  • Draft, maintain, and enforce enterprise-wide Information Security policies, procedures, and baseline security standards.
Qualifications & Skills
  • Experience: 8-10 years of core Information Security experience with hands-on technical management across Security Operations, Infrastructure Security, and GRC.
  • Regulatory Expertise: Deep operational familiarity with RBI Cybersecurity Framework, SEBI CSCRF guidelines, CERT-In incident reporting mandates, and DPDP (Digital Personal Data Protection) Act requirements.
  • Hands-on Tooling Knowledge on EDR/XDR, DLP, ZTNA/Network Security, SIEM/SOAR tools
Certifications (Preferred)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Information Security Officer
Chief Information Security Officer

Equirus Wealth • Mumbai

On-site
INR 6,000,000 - 9,000,000
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
Lead Information Security Analyst_SecOps
Lead Information Security Analyst_SecOps

InMobi Advertising • Lucknow

On-site
INR 1,500,000 - 2,500,000
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)

KreditBee • Bengaluru

On-site
INR 800,000 - 1,500,000
Cyber Security Technical Delivery Manager
Cyber Security Technical Delivery Manager

AVENIRDIGITAL SOLUTIONS PRIVATE LIMITED • Mumbai

On-site
INR 250,000 - 500,000
Chief Information Security Officer
Chief Information Security Officer

FundsIndia • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Executive Information Security
Senior Executive Information Security

SBI Payment Services Pvt. Ltd. • Mumbai City

On-site
INR 600,000 - 900,000
AVP Information Security
AVP Information Security

JITO • Mumbai

On-site
INR 4,500,000 - 7,000,000
AVP Information Security
AVP Information Security

Jain International Trade Organisation - India • Mumbai

On-site
INR 3,000,000 - 4,500,000
Security Risk and Regulatory Tech Compliance
Security Risk and Regulatory Tech Compliance

KreditBee • Bengaluru

On-site
INR 1,000,000 - 1,500,000