Security Analyst
Dmi Finance · Delhi
- Experience2–7 yrs
- SalaryDisclosed
- Work modeonsite
- Levelmid
- Posted22 Sept 2026
About Dmi Finance
Dmi Finance is hiring in Delhi in financial services. This role looks for around 2+ years of experience.
Skills
- penetration testing
- vulnerability assessment
- AWS
- Burp Suite
- Tenable WAS
- Nessus
- Nmap
- Kali Linux
- CVSS v3.1
- OWASP Top 10
- OWASP API Top 10
- OWASP MASVS
- MITRE ATT&CK
- SIEM
- EDR
- WAF
- DLP
- CASB
- NGFW
- incident response
- cloud security
- CSPM
- IAM
- Linux
- Docker
- Python
- SQL
- RBI IT Governance and Cyber Security Framework
- DPDP Act 2023
- CERT-In Directions
- ISO 27001:2022
- PCI-DSS
The role
A security analyst at a financial services company performs penetration testing and cloud security assessments, strengthens information security governance, and manages incident response and security operations. The role applies AWS, Burp Suite, and SIEM expertise to protect applications, APIs, infrastructure, and customer data.
Full job description
JOB DESCRIPTION
Job Title Security Analyst Information Securit- VAPT
Function / Department IT — Information Security
1. JOB PURPOSE
Own and execute the technical security assurance function for DMI Group — identifying, validating and
driving closure of security weaknesses across applications, APIs, cloud, network and endpoint estate before
they can be exploited, and evidencing that control posture to the Board, regulators and auditors.
The role combines offensive assessment (VA/PT of in-house, partner and vendor-hosted systems),
defensive operations (SOC / EDR / SIEM / WAF / DLP oversight and incident response), secure-by-design
review of new platforms and cloud deployments, and the governance work required by the RBI Master
Directions on IT Governance and Cyber Security, the DPDP Act 2023, CERT-In Directions and ISO
27001:2022 — supported by internal automation and tooling that makes the above repeatable and
auditable at NBFC scale.
3. PRINCIPAL ACCOUNTABILITIES
A. Vulnerability Assessment ; Penetration Testing (VAPT)
Plan and execute VA/PT across web applications, mobile applications, REST/API layers, internal
and internet-facing network segments, servers, endpoints and cloud workloads — for in-house
platforms (loan origination and servicing, KYC, collections, partner portals) as well as group
entities and partner-hosted systems.
Perform authenticated and unauthenticated assessments; establish authorisation test coverage
(IDOR / BOLA / privilege escalation), business-logic abuse cases, injection and session-
management testing aligned to OWASP Top 10, OWASP API Top 10, OWASP MASVS and MITRE
.
Score every finding using CVSS v3.1 with a defensible vector; capture reproducible proof-of-
concept evidence and steps to reproduce; maintain a negative-findings register recording vectors
tested and confirmed non-exploitable.
Operate and tune assessment tooling — Tenable WAS / VM, Nessus, Burp Suite, Nmap, Kali
toolchain, mobile and API testing utilities — and validate scanner output to eliminate false
positives before publication.
Conduct pre-go-live security testing for new applications, releases and third-party integrations;
issue formal sign-off or hold recommendations.
Perform retesting and closure verification; findings are closed only on evidence, not on assertion.
B. Finding Management, Remediation Advisory & SLA Governance
Maintain the consolidated VAPT finding register across all assessments and scanning platforms,
with normalised severity, status, ownership and ageing fields.
Track remediation against defined SLAs by severity; report ageing, breached SLAs, resurfaced (re-
opened) findings and repeat root causes to management.
Issue precise, directive remediation guidance to engineering teams — including object-level
authorisation scoping, server-enforced pagination and rate limiting, PII field-level masking and
tokenisation, secrets handling, and secure configuration baselines — in language that is directly
actionable and defensible to stakeholders.
Define and defend data-exposure standards for API responses, including which customer
attributes must never be returned in full to a client under any circumstance.
Run remediation review forums with development, infrastructure and vendor teams; arbitrate
risk-acceptance requests and record compensating controls.
C. Security Operations, Monitoring & Incident Response
Oversee day-to-day SOC output — alert triage, escalation and closure quality — across SIEM, EDR,
WAF, DLP, CASB, email security and NGFW telemetry, operating within the maker / checker /
approver control workflow.
Investigate incidents and suspected compromise; establish scope and impact; document root
cause analysis, corrective and preventive actions, and maintain the RCA register with action-plan
tracking to closure.
Maintain and periodically test the incident response and disaster recovery playbooks; ensure
statutory and regulatory notification timelines are met, including CERT-In six-hour incident
reporting and applicable RBI and DPDP Board notification obligations.
Monitor threat intelligence, advisories and open-source / OSINT exposure relating to the Group's
brands, domains and data; convert relevant intelligence into detection or remediation actions.
Track and report operational security metrics — attack volumes, blocked events, detection
coverage, MTTD/MTTR and control effectiveness.
D. Cloud, Infrastructure & Network Security
Review and design security architecture for AWS-hosted workloads — VPC segmentation, security
Security Analyst (InfoSec & VAPT) |
groups, IAM least privilege, KMS and Secrets Manager usage, ALB/WAF placement, private
connectivity, logging and backup — including production-ready deployment runbooks for new
platforms.
Operate cloud security posture management (CSPM); drive misconfiguration closure and maintain
baseline hardening standards for EC2, RDS, S3 and container workloads.
Support Zero Trust Network Access rollout and secure remote-access architecture (Netskope
Private Access / publishers, steering configuration, private application definitions and access
policy), replacing broad network-level access with per-application authorisation.
Review firewall, WAF and proxy policy — rule hygiene, tiered logging strategy, bandwidth and
licence utilisation, tuning of blocking policy — and manage the technical relationship with the
platform vendors on the same.
Ensure encryption in transit and at rest, certificate lifecycle management, and data residency
requirements applicable to a regulated NBFC are met by design.
E. Governance, Risk, Audit & Regulatory Compliance
Map the control environment to RBI Master Directions on IT Governance, Risk and Controls and
the Cyber Security Framework, DPDP Act 2023, CERT-In Directions, ISO 27001:2022 and PCI-DSS
where applicable.
Author and maintain information security policies, standards, SOPs and framework documents —
including acceptable-use and emerging-technology governance (e.g. Generative AI usage) — and
take them through management and Board-level approval.
Maintain data-protection artefacts: Record of Processing Activities, DPIA register, third-party
processor register, data-principal rights and breach-response procedures.
Build and run the annual security audit and assessment calendar; maintain evidence trails and
control-testing artefacts for internal audit, statutory / Big-4 audit, ISO certification cycles and RBI
inspection.
Prepare and present periodic security reporting to the CISO, Information Security Committee, IT
Strategy Committee and Board — including posture dashboards, VAPT status, audit action-tracker
(ATR) closure and budget utilisation.
F. Third-Party, Vendor & Partner Security
Perform security due diligence and periodic reassessment of vendors, fintech partners and service
providers handling Group systems or customer data.
Define security requirements, technical questionnaires and control obligations for inclusion in
contracts, SOWs and renewals; track vendor SLA and contractual security commitments to closure.
Review and challenge vendor assessment reports, attestations and remediation claims; escalate
residual risk formally.
G. Security Automation, Tooling & Engineering
Design and build internal security tooling to automate assessment, tracking, orchestration and
reporting workflows — reducing manual effort and producing consistent, audit-ready output.
Automate the control-monitoring and finding-orchestration pipeline (intake, enrichment,
assignment, approval, escalation and reporting) across SOC, VAPT, EDR and CSPM streams.
Integrate security data sources and ticketing systems; maintain dashboards and management
reporting packs.
Apply the Group's own data-handling and AI-usage controls when using automation or AI-assisted
tooling in security workflows.
H. Awareness, Culture & Advisory
Run security awareness initiatives — training content, phishing simulations, targeted briefings for
high-risk functions — and report participation and outcome metrics.
Act as the security advisory point for product, engineering, credit, operations and compliance
teams during design and change; embed security requirements early rather than at release.
Educational Qualifications
Minimum qualification: Any Graduate (B.E. / B.Tech / BCA / B.Sc. in Computer Science or
Information Technology preferred).
Preferred certifications: CEH, OSCP, eWPTX / eMAPT, CompTIA Security+, AWS Certified Security
— Specialty, ISO 27001 Lead Auditor / Lead Implementer, CISA or CISM for the governance
component.
Work Experience
Minimum 2-5 years of hands-on information security experience; BFSI, NBFC or security-consulting
exposure strongly preferred.
Demonstrated delivery of web, mobile, API and network VA/PT with independently written,
evidence-backed reports.
Working knowledge of AWS security services and cloud architecture review.
Exposure to SOC operations and the SIEM / EDR / WAF / DLP / CASB / NGFW control stack.
Familiarity with the RBI IT Governance and Cyber Security Frameworks, DPDP Act 2023, CERT-In
Directions, ISO 27001:2022 and PCI-DSS.
Forensics and incident investigation fundamentals; OSINT and open-source monitoring.
Technical Skills
Assessment: Burp Suite, Tenable WAS/VM, Nessus, Nmap, Kali toolchain, mobile and API testing
tooling, CVSS v3.1.
Cloud & infrastructure: AWS (EC2, VPC, IAM, RDS, S3, KMS, Secrets Manager, ALB/WAF,
CloudTrail), Linux, Docker, network fundamentals.
Security platforms: SIEM, EDR, WAF, DLP, CASB, NGFW, ZTNA / SASE, email security.
Automation & reporting: Python, scripting, SQL, Excel-based analysis and dashboarding; API
integration with security and ticketing platforms.
Documentation: audit-grade report writing, policy and SOP authoring, management and Board-
level reporting.
Behavioural Skills
Precise, directive written communication — able to state a control requirement a developer can
act on and a stakeholder can defend.
Evidence discipline: claims are supported, findings are reproducible, closures are verified.
Cross-functional collaboration with engineering, infrastructure, product, compliance, audit and
external vendors.
Ownership and escalation judgement — knows what to resolve, what to flag, and when.