Security Analyst

Dmi Finance

Dadri, Delhi

On-site

INR 1,800,000 - 2,400,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

DMI Group is seeking a Security Analyst Information Security – VAPT to own and execute the security assurance function across applications, APIs, cloud, network and endpoints. The role includes offensive VA/PT and defensive SOC/EDR/WAF oversight with governance under RBI/DPDP/ISO frameworks.

The candidate will perform authenticated/unauthenticated assessments, manage remediation guidance, and ensure evidence-backed closures with reliable proof-of-concept.

Qualifications

  • Minimum qualification: Any Graduate (B.E. / B.Tech / BCA / B.Sc. in Computer Science or Information Technology preferred).
  • Preferred certifications: CEH, OSCP, eWPTX / eMAPT, CompTIA Security+, AWS Certified Security — Specialty, ISO 27001 Lead Auditor / Lead Implementer, CISA or CISM for governance component.
  • Minimum 2-5 years of hands-on information security experience; BFSI, NBFC or security-consulting exposure strongly preferred.

Responsibilities

  • Plan and execute VA/PT across web applications, mobile applications, REST/API layers, internal and internet-facing networks.
  • Maintain consolidated VAPT findings; apply remediation guidance to engineering teams.
  • Oversee day-to-day SOC output — alert triage, escalation and closure quality across SIEM, EDR, WAF, DLP.
  • Review security architecture for AWS-hosted workloads; drive CSPM closures and baseline hardening.
  • Governance, risk, audit & regulatory compliance mapping to RBI Master Directions, DPDP Act, CERT-In, ISO 27001.
  • Security automation, tooling & engineering to automate assessment, tracking and reporting workflows.

Skills

Information security
VA/PT
Incident response
Cloud security
AWS security

Education

Bachelor’s degree in CS/IT
CEH
OSCP
eWPTX / eMAPT
CompTIA Security+
ISO 27001 Lead Auditor/Lead Implementer
CISA
CISM

Tools

Burp Suite
Tenable WAS/VM
Nessus
Nmap
Kali

Job description

JOB DESCRIPTION

Job Title Security Analyst Information Securit- VAPT

Function / Department IT — Information Security

1. JOB PURPOSE

Own and execute the technical security assurance function for DMI Group — identifying, validating and

driving closure of security weaknesses across applications, APIs, cloud, network and endpoint estate before

they can be exploited, and evidencing that control posture to the Board, regulators and auditors.

The role combines offensive assessment (VA/PT of in-house, partner and vendor-hosted systems),

defensive operations (SOC / EDR / SIEM / WAF / DLP oversight and incident response), secure-by-design

review of new platforms and cloud deployments, and the governance work required by the RBI Master

Directions on IT Governance and Cyber Security, the DPDP Act 2023, CERT-In Directions and ISO

27001:2022 — supported by internal automation and tooling that makes the above repeatable and

auditable at NBFC scale.

3. PRINCIPAL ACCOUNTABILITIES
A. Vulnerability Assessment ; Penetration Testing (VAPT)
  • Plan and execute VA/PT across web applications, mobile applications, REST/API layers, internal

and internet-facing network segments, servers, endpoints and cloud workloads — for in-house

platforms (loan origination and servicing, KYC, collections, partner portals) as well as group

entities and partner-hosted systems.

  • Perform authenticated and unauthenticated assessments; establish authorisation test coverage

(IDOR / BOLA / privilege escalation), business-logic abuse cases, injection and session-

management testing aligned to OWASP Top 10, OWASP API Top 10, OWASP MASVS and MITRE

.

  • Score every finding using CVSS v3.1 with a defensible vector; capture reproducible proof-of-

concept evidence and steps to reproduce; maintain a negative-findings register recording vectors

tested and confirmed non-exploitable.

  • Operate and tune assessment tooling — Tenable WAS / VM, Nessus, Burp Suite, Nmap, Kali

toolchain, mobile and API testing utilities — and validate scanner output to eliminate false

positives before publication.

  • Conduct pre-go-live security testing for new applications, releases and third-party integrations;

issue formal sign-off or hold recommendations.

  • Perform retesting and closure verification; findings are closed only on evidence, not on assertion.
B. Finding Management, Remediation Advisory & SLA Governance
  • Maintain the consolidated VAPT finding register across all assessments and scanning platforms,

with normalised severity, status, ownership and ageing fields.

  • Track remediation against defined SLAs by severity; report ageing, breached SLAs, resurfaced (re-

opened) findings and repeat root causes to management.

  • Issue precise, directive remediation guidance to engineering teams — including object-level

authorisation scoping, server-enforced pagination and rate limiting, PII field-level masking and

tokenisation, secrets handling, and secure configuration baselines — in language that is directly

actionable and defensible to stakeholders.

  • Define and defend data-exposure standards for API responses, including which customer

attributes must never be returned in full to a client under any circumstance.

  • Run remediation review forums with development, infrastructure and vendor teams; arbitrate

risk-acceptance requests and record compensating controls.

C. Security Operations, Monitoring & Incident Response
  • Oversee day-to-day SOC output — alert triage, escalation and closure quality — across SIEM, EDR,

WAF, DLP, CASB, email security and NGFW telemetry, operating within the maker / checker /

approver control workflow.

  • Investigate incidents and suspected compromise; establish scope and impact; document root

cause analysis, corrective and preventive actions, and maintain the RCA register with action-plan

tracking to closure.

  • Maintain and periodically test the incident response and disaster recovery playbooks; ensure

statutory and regulatory notification timelines are met, including CERT-In six-hour incident

reporting and applicable RBI and DPDP Board notification obligations.

  • Monitor threat intelligence, advisories and open-source / OSINT exposure relating to the Group's

brands, domains and data; convert relevant intelligence into detection or remediation actions.

  • Track and report operational security metrics — attack volumes, blocked events, detection
  • coverage, MTTD/MTTR and control effectiveness.
D. Cloud, Infrastructure & Network Security
  • Review and design security architecture for AWS-hosted workloads — VPC segmentation, security

Analyst (InfoSec & VAPT) |

groups, IAM least privilege, KMS and Secrets Manager usage, ALB/WAF placement, private

connectivity, logging and backup — including production-ready deployment runbooks for new

platforms.

  • Operate cloud security posture management (CSPM); drive misconfiguration closure and maintain

baseline hardening standards for EC2, RDS, S3 and container workloads.

  • Support Zero Trust Network Access rollout and secure remote-access architecture (Netskope

Private Access / publishers, steering configuration, private application definitions and access

policy), replacing broad network-level access with per-application authorisation.

  • Review firewall, WAF and proxy policy — rule hygiene, tiered logging strategy, bandwidth and
  • licence utilisation, tuning of blocking policy — and manage the technical relationship with the

    platform vendors on the same.

    • Ensure encryption in transit and at rest, certificate lifecycle management, and data residency
    • requirements applicable to a regulated NBFC are met by design.

    E. Governance, Risk, Audit & Regulatory Compliance
    • Map the control environment to RBI Master Directions on IT Governance, Risk and Controls and

    the Cyber Security Framework, DPDP Act 2023, CERT-In Directions, ISO 27001:2022 and PCI-DSS

    where applicable.

    • Author and maintain information security policies, standards, SOPs and framework documents —

    including acceptable-use and emerging-technology governance (e.g. Generative AI usage) — and

    take them through management and Board-level approval.

    • Maintain data-protection artefacts: Record of Processing Activities, DPIA register, third-party

    processor register, data-principal rights and breach-response procedures.

    • Build and run the annual security audit and assessment calendar; maintain evidence trails and

    control-testing artefacts for internal audit, statutory / Big-4 audit, ISO certification cycles and RBI

    inspection.

    • Prepare and present periodic security reporting to the CISO, Information Security Committee, IT

    Strategy Committee and Board — including posture dashboards, VAPT status, audit action-tracker

    (ATR) closure and budget utilisation.

    F. Third-Party, Vendor & Partner Security
    • Perform security due diligence and periodic reassessment of vendors, fintech partners and service

    providers handling Group systems or customer data.

    • Define security requirements, technical questionnaires and control obligations for inclusion in

    contracts, SOWs and renewals; track vendor SLA and contractual security commitments to closure.

    • Review and challenge vendor assessment reports, attestations and remediation claims; elevate
    • residual risk formally.

    G. Security Automation, Tooling & Engineering
    • Design and build internal security tooling to automate assessment, tracking, orchestration and

    reporting workflows — reducing manual effort and producing consistent, audit-ready output.

    • Automate the control-monitoring and finding-orchestration pipeline (intake, enrichment,
    • assignment, approval, escalation and reporting) across SOC, VAPT, EDR and CSPM streams.

      • Integrate security data sources and ticketing systems; maintain dashboards and management
      • reporting packs.

      • Apply the Group's own data-handling and AI-usage controls when using automation or AI-assisted
      • tooling in security workflows.

        H. Awareness, Culture & Advisory
        • Run security awareness initiatives — training content, phishing simulations, targeted briefings for

        high-risk functions — and report participation and outcome metrics.

        • Act as the security advisory point for product, engineering, credit, operations and compliance
        • teams during design and change; embed security requirements early rather than at release.

          Educational Qualifications
          • Minimum qualification: Any Graduate (B.E. / B.Tech / BCA / B.Sc. in Computer Science or

          Information Technology preferred).

          • Preferred certifications: CEH, OSCP, eWPTX / eMAPT, CompTIA Security+, AWS Certified Security

          — Specialty, ISO 27001 Lead Auditor / Lead Implementer, CISA or CISM for the governance

          component.

          Work Experience
          • Minimum 2-5 years of hands-on information security experience; BFSI, NBFC or security-consulting

          exposure strongly preferred.

          • Demonstrated delivery of web, mobile, API and network VA/PT with independently written,

          evidence-backed reports.

          • Working knowledge of AWS security services and cloud architecture review.
          • Exposure to SOC operations and the SIEM / EDR / WAF / DLP / CASB / NGFW control stack.
          • Familiarity with the RBI IT Governance and Cyber Security Frameworks, DPDP Act 2023, CERT-In

          Directions, ISO 27001:2022 and PCI-DSS.

          • Forensics and incident investigation fundamentals; OSINT and open-source monitoring.
          Technical Skills
          • Assessment: Burp Suite, Tenable WAS/VM, Nessus, Nmap, Kali toolchain, mobile and API testing

          tooling, CVSS v3.1.

          • Cloud & infrastructure: AWS (EC2, VPC, IAM, RDS, S3, KMS, Secrets Manager, ALB/WAF,

          CloudTrail), Linux, Docker, network fundamentals.

          • Security platforms: SIEM, EDR, WAF, DLP, CASB, NGFW, ZTNA / SASE, email security.
          • Automation & reporting: Python, scripting, SQL, Excel-based analysis and dashboarding; API

          integration with security and ticketing platforms.

          • Documentation: audit-grade report writing, policy and SOP authoring, management and Board-

          level reporting.

          Behavioural Skills
          • Precise, directive written communication — able to state a control requirement a developer can

          act on and a stakeholder can defend.

          • Evidence discipline: claims are supported, findings are reproducible, closures are verified.
          • Cross-functional collaboration with engineering, infrastructure, product, compliance, audit and

          external vendors.

          • Ownership and escalation judgement — knows what to resolve, what to flag, and when.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - Information Security
Manager - Information Security

Findi India • Mumbai

On-site
INR 1,500,000 - 2,100,000
Information Technology Security Manager
Information Technology Security Manager

Accops • Pune District

On-site
INR 4,000,000 - 6,500,000
Security Lead / Architect
Security Lead / Architect

Digital India Corporation • Delhi

On-site
INR 4,200,000 - 6,200,000
Information Security Manager
Information Security Manager

Dmi Finance • Dadri, Delhi

On-site
INR 1,200,000 - 1,800,000
Security Engineer
Security Engineer

Hackajob • Hyderabad, Pune District, Bengaluru

Hybrid
INR 900,000 - 1,300,000
SOC / Security Operations Lead
SOC / Security Operations Lead

One97 Communications Limited • Dadri

On-site
INR 3,000,000 - 6,000,000
Security Architect
Security Architect

Skillventory • Mumbai

On-site
INR 4,000,000 - 7,000,000
Security Engineering Lead
Security Engineering Lead

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 3,500,000 - 6,500,000
Assistant Vice President – Information Security
Assistant Vice President – Information Security

IndiaFirst Life • Mumbai

On-site
INR 1,000,000 - 1,500,000
SOC / Security Operations Lead
SOC / Security Operations Lead

Paytm • Dadri

On-site
INR 3,500,000 - 7,000,000