Get more replies from employers
Send a job-specific resume in minutes.
DMI Group is seeking a Security Analyst Information Security – VAPT to own and execute the security assurance function across applications, APIs, cloud, network and endpoints. The role includes offensive VA/PT and defensive SOC/EDR/WAF oversight with governance under RBI/DPDP/ISO frameworks.
The candidate will perform authenticated/unauthenticated assessments, manage remediation guidance, and ensure evidence-backed closures with reliable proof-of-concept.
JOB DESCRIPTION
Job Title Security Analyst Information Securit- VAPT
Function / Department IT — Information Security
Own and execute the technical security assurance function for DMI Group — identifying, validating and
driving closure of security weaknesses across applications, APIs, cloud, network and endpoint estate before
they can be exploited, and evidencing that control posture to the Board, regulators and auditors.
The role combines offensive assessment (VA/PT of in-house, partner and vendor-hosted systems),
defensive operations (SOC / EDR / SIEM / WAF / DLP oversight and incident response), secure-by-design
review of new platforms and cloud deployments, and the governance work required by the RBI Master
Directions on IT Governance and Cyber Security, the DPDP Act 2023, CERT-In Directions and ISO
27001:2022 — supported by internal automation and tooling that makes the above repeatable and
auditable at NBFC scale.
and internet-facing network segments, servers, endpoints and cloud workloads — for in-house
platforms (loan origination and servicing, KYC, collections, partner portals) as well as group
entities and partner-hosted systems.
(IDOR / BOLA / privilege escalation), business-logic abuse cases, injection and session-
management testing aligned to OWASP Top 10, OWASP API Top 10, OWASP MASVS and MITRE
.
concept evidence and steps to reproduce; maintain a negative-findings register recording vectors
tested and confirmed non-exploitable.
toolchain, mobile and API testing utilities — and validate scanner output to eliminate false
positives before publication.
issue formal sign-off or hold recommendations.
with normalised severity, status, ownership and ageing fields.
opened) findings and repeat root causes to management.
authorisation scoping, server-enforced pagination and rate limiting, PII field-level masking and
tokenisation, secrets handling, and secure configuration baselines — in language that is directly
actionable and defensible to stakeholders.
attributes must never be returned in full to a client under any circumstance.
risk-acceptance requests and record compensating controls.
WAF, DLP, CASB, email security and NGFW telemetry, operating within the maker / checker /
approver control workflow.
cause analysis, corrective and preventive actions, and maintain the RCA register with action-plan
tracking to closure.
statutory and regulatory notification timelines are met, including CERT-In six-hour incident
reporting and applicable RBI and DPDP Board notification obligations.
brands, domains and data; convert relevant intelligence into detection or remediation actions.
Analyst (InfoSec & VAPT) |
groups, IAM least privilege, KMS and Secrets Manager usage, ALB/WAF placement, private
connectivity, logging and backup — including production-ready deployment runbooks for new
platforms.
baseline hardening standards for EC2, RDS, S3 and container workloads.
Private Access / publishers, steering configuration, private application definitions and access
policy), replacing broad network-level access with per-application authorisation.
licence utilisation, tuning of blocking policy — and manage the technical relationship with the
platform vendors on the same.
requirements applicable to a regulated NBFC are met by design.
the Cyber Security Framework, DPDP Act 2023, CERT-In Directions, ISO 27001:2022 and PCI-DSS
where applicable.
including acceptable-use and emerging-technology governance (e.g. Generative AI usage) — and
take them through management and Board-level approval.
processor register, data-principal rights and breach-response procedures.
control-testing artefacts for internal audit, statutory / Big-4 audit, ISO certification cycles and RBI
inspection.
Strategy Committee and Board — including posture dashboards, VAPT status, audit action-tracker
(ATR) closure and budget utilisation.
providers handling Group systems or customer data.
contracts, SOWs and renewals; track vendor SLA and contractual security commitments to closure.
residual risk formally.
reporting workflows — reducing manual effort and producing consistent, audit-ready output.
assignment, approval, escalation and reporting) across SOC, VAPT, EDR and CSPM streams.
reporting packs.
tooling in security workflows.
high-risk functions — and report participation and outcome metrics.
teams during design and change; embed security requirements early rather than at release.
Information Technology preferred).
— Specialty, ISO 27001 Lead Auditor / Lead Implementer, CISA or CISM for the governance
component.
exposure strongly preferred.
evidence-backed reports.
Directions, ISO 27001:2022 and PCI-DSS.
tooling, CVSS v3.1.
CloudTrail), Linux, Docker, network fundamentals.
integration with security and ticketing platforms.
level reporting.
act on and a stakeholder can defend.
external vendors.