Lead Information Security Engineer

InCred Financial Services · Bengaluru

  • Experience8–10 yrs
  • SalaryNot disclosed
  • Work modehybrid
  • Levelexecutive
  • Posted17 Sept 2026

About InCred Financial Services

InCred Financial Services is hiring in Bengaluru in financial services. This role looks for around 8+ years of experience.

Skills

  • Network Security
  • Data Loss Prevention
  • Zero Trust Network Access
  • Security Operations
  • Incident Response
  • Endpoint Security
  • EDR/XDR
  • SIEM
  • SOAR
  • Security Information and Event Management
  • Security Orchestration, Automation and Response
  • Firewalls
  • Intrusion Prevention Systems
  • Vulnerability Management
  • Information Security Governance
  • RBI Cybersecurity Framework
  • SEBI Cybersecurity & Cyber Resilience Framework
  • CERT-In directives
  • DPDP Act

The role

A security engineer at a financial services company designs cyber defense controls and manages Security Operations, incident response, and regulatory compliance using Network Security, Data Loss Prevention, and Zero Trust Network Access. The role also applies SIEM/SOAR tools and information security governance to protect financial and customer data.

Full job description

Job Title: Lead InfoSec Engineer (Backend Developer)Experience: 8-10 YearsLocation: Bengaluru (Hybrid)

About the Role:We are looking for an experienced Information Security Lead with 8 to 10 years of hands-on expertise to lead our enterprise Cyber Defense, Security Operations, and Regulatory Compliance posture. In this role, the candidate will oversee core security technologies—including Endpoint Security, Data Loss Prevention (DLP), Zero Trust Network Access (ZTNA), and Network Security—while managing Incident Response and SOC operations. The candidate will be directly responsible for aligning security controls with key Regulatory frameworks, specifically guidelines issued by the Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), and other associated bodies (e.g., CERT-In, IRDAI, NCIIPC).

Key Responsibilities:1. Security Operations & Incident Response ● Lead 24/7 Security Operations (SOC) oversight, threat hunting, and incident management workflows.● Manage high-severity incident response (IR) procedures, forensic investigations, root-cause analyses (RCA), and mandatory regulatory notifications (e.g., CERT-In 6-hour incident reporting window).● Design, execute, and evaluate periodic tabletop exercises and Cyber Crisis Management Plans (CCMP).

2. Endpoint Security, DLP & ZTNA ● Manage, configure, and optimize EDR/XDR platforms for host-level protection and threat containment.● Architect and refine enterprise Data Loss Prevention (DLP) strategies across endpoints, email, web gateways, and cloud stores to prevent exposure of sensitive financial/customer data.● Lead implementation and governance of Zero Trust Network Access (ZTNA) solutions to replace legacy VPNs and enforce least-privilege access.

3. Network Security & Infrastructure ● Oversee firewalls (NGFW), Intrusion Prevention Systems (IPS) and secure web gateways (SWG).● Conduct regular network architecture reviews, micro-segmentation governance, and vulnerability management across on-premises and multi-cloud environments.● Perform periodic configuration audits of active directory, network switches, routers, and VPN gateways.

4. Regulatory Compliance & Governance (GRC) ● Maintain continuous alignment with regulatory security frameworks including RBI Cybersecurity Framework for Banks/NBFCs/PPIs, SEBI Cybersecurity & Cyber Resilience Framework (CSCRF), and CERT-In directives. ● Direct internal and external security audits, risk assessments, regulatory reporting, and vulnerability closures requested by statutory auditors or regulators.● Draft, maintain, and enforce enterprise-wide Information Security policies, procedures, and baseline security standards.

Qualifications & Skills: ● Experience: 8–10 years of core Information Security experience with hands-on technical management across Security Operations, Infrastructure Security, and GRC.● Regulatory Expertise: Deep operational familiarity with RBI Cybersecurity Framework, SEBI CSCRF guidelines, CERT-In incident reporting mandates, and DPDP (Digital Personal Data Protection) Act requirements.● Hands-on Tooling Knowledge on EDR/XDR, DLP, ZTNA/Network Security, SIEM/SOAR tools

Certifications (Preferred): ○ ISO 27001:2022 Lead Auditor○ Certified Information Systems Security Professional (CISSP)○ Certified Information Security Manager (CISM)○ Certified Information Systems Auditor (CISA)