Senior Associate, Cyber/IT Security, Technology and Operations

Posted Yesterday
Be an Early Applicant
Kāṅjūrmārg Īsṭ, Muṃbaī Sabarban, Mahaaraashtra, IND
In-Office
Senior level
Fintech • Information Technology • Software • Financial Services
The Role
Owns application security, vulnerability management, DevSecOps, penetration testing, red teaming, API and cloud security, compliance monitoring, and security project delivery. Leads assessments using SAST, DAST, IAST, SCA, and manual reviews; prioritizes remediation; embeds controls into CI/CD pipelines; supports audits and regulatory reporting; and serves as a senior escalation point for complex security issues.
Summary Generated by Built In

Business Function

Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.

Job Purpose

The purpose of this job role is to manage IT Security with strong hands-on capabilities across Application Security, Vulnerability Management, DevSecOps, and Red Teaming. The role requires end-to-end ownership from security design and troubleshooting to project execution, compliance monitoring, and continuous improvement of the security posture.

Key Accountabilities

  1. Vulnerability management and Penetration Testing
  2. Application security
  3. Virtualization and container technologies (Docker, Kubernetes, OpenShift).
  4. API Security, Red Teaming & Security Testing
  5. CI/CD assessment
  6. IS Related compliance and regulatory reporting

Job Duties & Responsibilities

Application Security

  1. Lead application security assessments including SAST, DAST, IAST, SCA, and manual code reviews.
  2. Identify, validate, and prioritize application security vulnerabilities and guide remediation with development teams.
  3. Ensure secure design and implementation aligned with OWASP Top 10, ASVS, and secure coding standards.
  4. Review application architecture and data flows from a security perspective.

Vulnerability Management

  1. Own the end-to-end vulnerability management lifecycle across applications, infrastructure, cloud, and endpoints.
  2. Perform vulnerability validation, risk-based prioritization, exception handling, and closure tracking.
  3. Coordinate with multiple stakeholders to ensure timely remediation and SLA adherence.
  4. Provide management-level reporting on vulnerability trends, risk exposure, and remediation status.

DevSecOps

  1. Integrate security controls into CI/CD pipelines (e.g., code scanning, dependency scanning, secrets management).
  2. Enable shift-left security by embedding security checkpoints in development and deployment processes.
  3. Work closely with DevOps teams to automate security testing and compliance checks.
  4. Define and enforce secure SDLC and DevSecOps governance.

Red Teaming & Security Testing

  1. Coordinate and manage red team / penetration testing exercises (internal and external).
  2. Validate findings, assess business impact, and track remediation to closure.
  3. Support purple team activities to improve detection and response capabilities.
  4. Conduct root cause analysis and provide improvement recommendations.

Compliance & Governance Monitoring

  1. Monitor and ensure compliance with internal security policies, standards, and regulatory requirements.
  2. Support audits, assessments, and regulatory reviews by providing evidence and technical clarifications.
  3. Track security issues, risk acceptances, and remediation plans across all security domains.

Troubleshooting & Project Ownership

  1. Act as a senior escalation point for complex security issues and incidents.
  2. Lead security initiatives and projects from planning and execution to closure.
  3. Coordinate with cross-functional teams to resolve security gaps without impacting business timelines.

Requirements

  1. 8–12+ years of experience in IT / Information Security, with strong hands-on exposure.
  2. Deep understanding of Application Security, Vulnerability Management, DevSecOps, and Red Teaming.
  3. Strong knowledge of web, API, cloud, and infrastructure security.
  4. Experience working with security tools (SAST/DAST/SCA, vulnerability scanners, CI/CD tools).
  5. Solid understanding of security frameworks and standards (OWASP, NIST, ISO 27001, PCI DSS – preferred).
  6. Ability to translate technical security issues into business and risk impact.
  7. Strong stakeholder management and communication skills.

Education / Preferred Qualifications

  1. Graduation:  BE IT/Computers/Electronics, B.Sc - Computers, M.Sc - Computers
  2. Post-Graduation: PGDIT, MCA, MBA
  3. Certification like CISSP, CISM, SANS, OSCP/OSCE and CREST (Prefered)

Core Competencies

  1. Excellent analytical and decision-making skill sets
  2. Effective in Communication, documentation and report writing skills
  3. Ability to consult and validate solutions to mitigates risks to business and systems

Technical Competencies

  1. VAPT - Rapid7, Nessus, Metasploit, QualysGuard, Burpsuite ,CI/CD tool etc.
  2. Technical working knowledge (WAF, HIDS, IPS, Firewall, Networking
  3. SAST: Checkmarx, Fortify, Veracode, SonarQube , DAST: Burp Suite, OWASP ZAP, AppScan
  4. SCA: Black Duck, Snyk, WhiteSource (Mend)
  5. API Security: Postman, Burp, OWASP API tools.

Location:

I-Think Techno, Kanjurmarg

Job:

Technology

Schedule:

Regular

Employee Status:

Full time

Skills Required

  • 8-12+ years of experience in IT or information security
  • Hands-on expertise in application security, vulnerability management, DevSecOps, and red teaming
  • Strong knowledge of web, API, cloud, and infrastructure security
  • Experience with SAST, DAST, SCA, vulnerability scanners, and CI/CD security tools
  • Knowledge of OWASP, NIST, and ISO 27001 security frameworks and standards
  • PCI DSS knowledge
  • Ability to translate technical security issues into business and risk impact
  • Strong stakeholder management and communication skills
  • Bachelor's degree in IT, Computer Science, Electronics, or a related computer discipline
  • Postgraduate qualification such as PGDIT, MCA, or MBA
  • CISSP, CISM, SANS, OSCP, OSCE, or CREST certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Singapore
41,000 Employees
Year Founded: 1968

What We Do

DBS Bank is a leading financial services group in Asia, headquartered in Singapore. It provides a full range of consumer, SME, and corporate banking services. The bank is recognized for its digital innovation, having been named 'World's Best Digital Bank' and 'World's Best Bank' by various publications. It also operates the DBS Foundation, which supports social enterprises and community initiatives, reflecting its commitment to creating impact beyond traditional banking.

Similar Jobs

Coursera + Udemy  Logo Coursera + Udemy

Accounts Payable Specialist

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
India
1500 Employees

Circle (circle.so) Logo Circle (circle.so)

Lead Engineer, AI Platform

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees

Circle (circle.so) Logo Circle (circle.so)

Senior Quality Engineer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees
120K-130K Annually

Circle (circle.so) Logo Circle (circle.so)

Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees
100K-120K Annually

Similar Companies Hiring

Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account