Security Analyst

Dmi Finance · Delhi

  • Experience2–7 yrs
  • SalaryDisclosed
  • Work modeonsite
  • Levelmid
  • Posted22 Sept 2026

About Dmi Finance

Dmi Finance is hiring in Delhi in financial services. This role looks for around 2+ years of experience.

Skills

  • penetration testing
  • vulnerability assessment
  • AWS
  • Burp Suite
  • Tenable WAS
  • Nessus
  • Nmap
  • Kali Linux
  • CVSS v3.1
  • OWASP Top 10
  • OWASP API Top 10
  • OWASP MASVS
  • MITRE ATT&CK
  • SIEM
  • EDR
  • WAF
  • DLP
  • CASB
  • NGFW
  • incident response
  • cloud security
  • CSPM
  • IAM
  • Linux
  • Docker
  • Python
  • SQL
  • RBI IT Governance and Cyber Security Framework
  • DPDP Act 2023
  • CERT-In Directions
  • ISO 27001:2022
  • PCI-DSS

The role

A security analyst at a financial services company performs penetration testing and cloud security assessments, strengthens information security governance, and manages incident response and security operations. The role applies AWS, Burp Suite, and SIEM expertise to protect applications, APIs, infrastructure, and customer data.

Full job description

JOB DESCRIPTION

Job Title Security Analyst Information Securit- VAPT

Function / Department IT — Information Security

1. JOB PURPOSE

Own and execute the technical security assurance function for DMI Group — identifying, validating and

driving closure of security weaknesses across applications, APIs, cloud, network and endpoint estate before

they can be exploited, and evidencing that control posture to the Board, regulators and auditors.

The role combines offensive assessment (VA/PT of in-house, partner and vendor-hosted systems),

defensive operations (SOC / EDR / SIEM / WAF / DLP oversight and incident response), secure-by-design

review of new platforms and cloud deployments, and the governance work required by the RBI Master

Directions on IT Governance and Cyber Security, the DPDP Act 2023, CERT-In Directions and ISO

27001:2022 — supported by internal automation and tooling that makes the above repeatable and

auditable at NBFC scale.

3. PRINCIPAL ACCOUNTABILITIES

A. Vulnerability Assessment ; Penetration Testing (VAPT)

Plan and execute VA/PT across web applications, mobile applications, REST/API layers, internal

and internet-facing network segments, servers, endpoints and cloud workloads — for in-house

platforms (loan origination and servicing, KYC, collections, partner portals) as well as group

entities and partner-hosted systems.

Perform authenticated and unauthenticated assessments; establish authorisation test coverage

(IDOR / BOLA / privilege escalation), business-logic abuse cases, injection and session-

management testing aligned to OWASP Top 10, OWASP API Top 10, OWASP MASVS and MITRE

.

Score every finding using CVSS v3.1 with a defensible vector; capture reproducible proof-of-

concept evidence and steps to reproduce; maintain a negative-findings register recording vectors

tested and confirmed non-exploitable.

Operate and tune assessment tooling — Tenable WAS / VM, Nessus, Burp Suite, Nmap, Kali

toolchain, mobile and API testing utilities — and validate scanner output to eliminate false

positives before publication.

Conduct pre-go-live security testing for new applications, releases and third-party integrations;

issue formal sign-off or hold recommendations.

Perform retesting and closure verification; findings are closed only on evidence, not on assertion.

B. Finding Management, Remediation Advisory & SLA Governance

Maintain the consolidated VAPT finding register across all assessments and scanning platforms,

with normalised severity, status, ownership and ageing fields.

Track remediation against defined SLAs by severity; report ageing, breached SLAs, resurfaced (re-

opened) findings and repeat root causes to management.

Issue precise, directive remediation guidance to engineering teams — including object-level

authorisation scoping, server-enforced pagination and rate limiting, PII field-level masking and

tokenisation, secrets handling, and secure configuration baselines — in language that is directly

actionable and defensible to stakeholders.

Define and defend data-exposure standards for API responses, including which customer

attributes must never be returned in full to a client under any circumstance.

Run remediation review forums with development, infrastructure and vendor teams; arbitrate

risk-acceptance requests and record compensating controls.

C. Security Operations, Monitoring & Incident Response

Oversee day-to-day SOC output — alert triage, escalation and closure quality — across SIEM, EDR,

WAF, DLP, CASB, email security and NGFW telemetry, operating within the maker / checker /

approver control workflow.

Investigate incidents and suspected compromise; establish scope and impact; document root

cause analysis, corrective and preventive actions, and maintain the RCA register with action-plan

tracking to closure.

Maintain and periodically test the incident response and disaster recovery playbooks; ensure

statutory and regulatory notification timelines are met, including CERT-In six-hour incident

reporting and applicable RBI and DPDP Board notification obligations.

Monitor threat intelligence, advisories and open-source / OSINT exposure relating to the Group's

brands, domains and data; convert relevant intelligence into detection or remediation actions.

Track and report operational security metrics — attack volumes, blocked events, detection

coverage, MTTD/MTTR and control effectiveness.

D. Cloud, Infrastructure & Network Security

Review and design security architecture for AWS-hosted workloads — VPC segmentation, security

Security Analyst (InfoSec & VAPT) |

groups, IAM least privilege, KMS and Secrets Manager usage, ALB/WAF placement, private

connectivity, logging and backup — including production-ready deployment runbooks for new

platforms.

Operate cloud security posture management (CSPM); drive misconfiguration closure and maintain

baseline hardening standards for EC2, RDS, S3 and container workloads.

Support Zero Trust Network Access rollout and secure remote-access architecture (Netskope

Private Access / publishers, steering configuration, private application definitions and access

policy), replacing broad network-level access with per-application authorisation.

Review firewall, WAF and proxy policy — rule hygiene, tiered logging strategy, bandwidth and

licence utilisation, tuning of blocking policy — and manage the technical relationship with the

platform vendors on the same.

Ensure encryption in transit and at rest, certificate lifecycle management, and data residency

requirements applicable to a regulated NBFC are met by design.

E. Governance, Risk, Audit & Regulatory Compliance

Map the control environment to RBI Master Directions on IT Governance, Risk and Controls and

the Cyber Security Framework, DPDP Act 2023, CERT-In Directions, ISO 27001:2022 and PCI-DSS

where applicable.

Author and maintain information security policies, standards, SOPs and framework documents —

including acceptable-use and emerging-technology governance (e.g. Generative AI usage) — and

take them through management and Board-level approval.

Maintain data-protection artefacts: Record of Processing Activities, DPIA register, third-party

processor register, data-principal rights and breach-response procedures.

Build and run the annual security audit and assessment calendar; maintain evidence trails and

control-testing artefacts for internal audit, statutory / Big-4 audit, ISO certification cycles and RBI

inspection.

Prepare and present periodic security reporting to the CISO, Information Security Committee, IT

Strategy Committee and Board — including posture dashboards, VAPT status, audit action-tracker

(ATR) closure and budget utilisation.

F. Third-Party, Vendor & Partner Security

Perform security due diligence and periodic reassessment of vendors, fintech partners and service

providers handling Group systems or customer data.

Define security requirements, technical questionnaires and control obligations for inclusion in

contracts, SOWs and renewals; track vendor SLA and contractual security commitments to closure.

Review and challenge vendor assessment reports, attestations and remediation claims; escalate

residual risk formally.

G. Security Automation, Tooling & Engineering

Design and build internal security tooling to automate assessment, tracking, orchestration and

reporting workflows — reducing manual effort and producing consistent, audit-ready output.

Automate the control-monitoring and finding-orchestration pipeline (intake, enrichment,

assignment, approval, escalation and reporting) across SOC, VAPT, EDR and CSPM streams.

Integrate security data sources and ticketing systems; maintain dashboards and management

reporting packs.

Apply the Group's own data-handling and AI-usage controls when using automation or AI-assisted

tooling in security workflows.

H. Awareness, Culture & Advisory

Run security awareness initiatives — training content, phishing simulations, targeted briefings for

high-risk functions — and report participation and outcome metrics.

Act as the security advisory point for product, engineering, credit, operations and compliance

teams during design and change; embed security requirements early rather than at release.

Educational Qualifications

Minimum qualification: Any Graduate (B.E. / B.Tech / BCA / B.Sc. in Computer Science or

Information Technology preferred).

Preferred certifications: CEH, OSCP, eWPTX / eMAPT, CompTIA Security+, AWS Certified Security

— Specialty, ISO 27001 Lead Auditor / Lead Implementer, CISA or CISM for the governance

component.

Work Experience

Minimum 2-5 years of hands-on information security experience; BFSI, NBFC or security-consulting

exposure strongly preferred.

Demonstrated delivery of web, mobile, API and network VA/PT with independently written,

evidence-backed reports.

Working knowledge of AWS security services and cloud architecture review.

Exposure to SOC operations and the SIEM / EDR / WAF / DLP / CASB / NGFW control stack.

Familiarity with the RBI IT Governance and Cyber Security Frameworks, DPDP Act 2023, CERT-In

Directions, ISO 27001:2022 and PCI-DSS.

Forensics and incident investigation fundamentals; OSINT and open-source monitoring.

Technical Skills

Assessment: Burp Suite, Tenable WAS/VM, Nessus, Nmap, Kali toolchain, mobile and API testing

tooling, CVSS v3.1.

Cloud & infrastructure: AWS (EC2, VPC, IAM, RDS, S3, KMS, Secrets Manager, ALB/WAF,

CloudTrail), Linux, Docker, network fundamentals.

Security platforms: SIEM, EDR, WAF, DLP, CASB, NGFW, ZTNA / SASE, email security.

Automation & reporting: Python, scripting, SQL, Excel-based analysis and dashboarding; API

integration with security and ticketing platforms.

Documentation: audit-grade report writing, policy and SOP authoring, management and Board-

level reporting.

Behavioural Skills

Precise, directive written communication — able to state a control requirement a developer can

act on and a stakeholder can defend.

Evidence discipline: claims are supported, findings are reproducible, closures are verified.

Cross-functional collaboration with engineering, infrastructure, product, compliance, audit and

external vendors.

Ownership and escalation judgement — knows what to resolve, what to flag, and when.