Senior Manager - Information Security And Governance

HDB Financial Services Ltd.

Mumbai

On-site

INR 800,000 - 1,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading financial services company in Mumbai seeks an experienced Red Team Assessment expert. You will conduct red team exercises, simulate attacks and evaluate security controls. The ideal candidate will possess a background in cybersecurity and familiarity with regulatory frameworks. Certifications such as OSCP are preferred. Join us to strengthen our security posture and collaborate with our Cyber Security Team.

Qualifications

  • Strong understanding of regulatory frameworks (RBI, ISO 27001).
  • Certifications such as OSCP, OSCE, CEH, GPEN are highly preferred.
  • Ability to analyze complex security issues and communicate them.

Responsibilities

  • Conduct red team exercises to mimic sophisticated cyberattacks.
  • Develop and execute complex attack scenarios.
  • Document attack paths and provide remediation recommendations.

Skills

Analytical mindset
Excellent communication skills
Proficiency in Python
Familiarity with cloud platforms

Education

Bachelor's degree in Information Security, Computer Science, or related field

Tools

Metasploit
Cobalt Strike
Burp Suite
Nmap

Job description

Overview

HDB Financial Services Ltd is looking for an experienced Red Team Assessment expert to join our Cyber Security Team. This role is responsible for simulating real-world attacks to test the effectiveness of our security controls, detection capabilities, and incident response processes. The ideal candidate will have a strong background in offensive security, a deep understanding of adversary tactics, and the ability to provide actionable insights to strengthen our overall security posture. The role also includes technical configuration audit based assessment to strengthen our IT and cyber security posture, reviewing, assessing and auditing systems, networks and security configurations to ensure policy, regulatory, and industry best practices compliance.

Responsibilities
  • Conduct red team exercises to mimic sophisticated cyberattacks and evaluate the effectiveness of security controls.
  • Develop and execute complex attack scenarios using tactics, techniques, and procedures (TTPs) aligned with real-world threat actors.
  • Perform internal Red Team Assessments across networks, applications, endpoints, and cloud environments.
  • Develop and deploy custom attack tools and payloads (e.g., backdoors, phishing kits, webshells).
  • Use frameworks like MITRE ATT&CK to guide threat simulation strategies.
  • Emulate advanced persistent threat (APTs) using industry-recognized TTPs.
  • Document attack paths, vulnerabilities exploited, and lateral movement techniques, including remediation recommendations.
  • Develop custom scripts, tools and methodologies.
  • Hands-on experience with Active Directory attacks, exploitation frameworks and scripting (Python, PowerShell, Bash etc.).
  • Assist SOC team to simulate the SOC Use Case and Breach Attack Simulation (BAS) posture improvements.
  • Identify and exploit vulnerabilities across infrastructure, applications, cloud environments and physical security.
  • Provide detailed reports with remediation strategies and executive summaries.
  • Collaborate with Blue Teams to improve detection capabilities and incident response.
  • Track remediation efforts and perform follow-up to confirm closure of findings.
  • Conduct technical configuration audits across servers, databases, endpoints, network devices, cloud platforms and security solutions.
  • Review system and security settings to ensure alignment with secure configuration standards (CIS, NIST, ISO) and regulatory requirements.
  • Identify configuration gaps, control weaknesses and recommend remediation steps; validate configuration compliance with IT, Infrastructure and Security Operations teams.
  • Document audit findings, prepare reports and present results to stakeholders in a clear manner; support risk assessments and audits with configuration evidence.
Qualifications
  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
  • MITRE ATT&CK mapping and threat modelling.
  • Strong understanding of regulatory frameworks (RBI, ISO 27001).
  • Excellent communication, stakeholder management, and leadership skills.
  • Certifications such as OSCP, OSCE, CEH, GPEN are highly preferred; OSCP, CRTP, CISSP are desirable.
  • Understanding of secure network architecture, segmentation and defence in depth; ability to design and implement security controls across systems, networks and applications.
  • Ability to analyze complex security issues and communicate them to non-technical stakeholders.
  • Proficiency in scripting languages (Python, Bash, PowerShell).
  • Experience with security tools (Metasploit, Cobalt Strike, Burp Suite, Nmap).
  • Familiarity with cloud platforms (AWS, Azure, GCP) and their security configurations.
  • Knowledge of regulatory frameworks and audit standards; ability to write clear, actionable technical and executive-level reports.
  • Familiarity with secure configuration frameworks such as CIS Benchmarks, NIST Framework, ISO 27001.
Preferred Traits
  • Analytical mindset with attention to detail.
  • Excellent communication and collaboration skills.
  • Passion for cybersecurity and continuous learning.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Network Security
Network Security

Sisainfosec • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Cyber Security Senior Advisor_97092
Cyber Security Senior Advisor_97092

MyCareernet • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Security Lead- Red Teaming and Application Security
Security Lead- Red Teaming and Application Security

Security Brigade • Navi Mumbai

On-site
INR 4,000,000 - 7,000,000
SISA Information Security - Network Security Engineer
SISA Information Security - Network Security Engineer

SISA • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Mumbai

On-site
INR 1,200,000 - 2,000,000
Senior [Red Team] Security Consultant
Senior [Red Team] Security Consultant

ILLUME Intelligence India Pvt. Ltd. • Karnataka

On-site
INR 1,800,000 - 3,000,000
239939-Manager
239939-Manager

EXL • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Security Consultant - Red Team
Security Consultant - Red Team

Payatu • Bengaluru

On-site
INR 800,000 - 1,200,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000