Website:
incred.com
Job details:
Job Title: Lead InfoSec Engineer
Experience: 8-10 Years
Location: Bengaluru (Hybrid)
About the Role:
We are looking for an experienced Information Security Lead with 8 to 10 years of hands-on expertise to lead our enterprise Cyber Defense, Security Operations, and Regulatory Compliance posture. In this role, the candidate will oversee core security technologies—including Endpoint Security, Data Loss Prevention (DLP), Zero Trust Network Access (ZTNA), and Network Security—while managing Incident Response and SOC operations. The candidate will be directly responsible for aligning security controls with key Regulatory frameworks, specifically guidelines issued by the Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), and other associated bodies (e.g., CERT-In, IRDAI, NCIIPC).
Key Responsibilities:
1. Security Operations & Incident Response
● Lead 24/7 Security Operations (SOC) oversight, threat hunting, and incident management workflows.
● Manage high-severity incident response (IR) procedures, forensic investigations, root-cause analyses (RCA), and mandatory regulatory notifications (e.g., CERT-In 6-hour incident reporting window).
● Design, execute, and evaluate periodic tabletop exercises and Cyber Crisis Management Plans (CCMP).
2. Endpoint Security, DLP & ZTNA
● Manage, configure, and optimize EDR/XDR platforms for host-level protection and threat containment.
● Architect and refine enterprise Data Loss Prevention (DLP) strategies across endpoints, email, web gateways, and cloud stores to prevent exposure of sensitive financial/customer data.
● Lead implementation and governance of Zero Trust Network Access (ZTNA) solutions to replace legacy VPNs and enforce least-privilege access.
3. Network Security & Infrastructure
● Oversee firewalls (NGFW), Intrusion Prevention Systems (IPS) and secure web gateways (SWG).
● Conduct regular network architecture reviews, micro-segmentation governance, and vulnerability management across on-premises and multi-cloud environments.
● Perform periodic configuration audits of active directory, network switches, routers, and VPN gateways.
4. Regulatory Compliance & Governance (GRC)
● Maintain continuous alignment with regulatory security frameworks including RBI Cybersecurity Framework for Banks/NBFCs/PPIs, SEBI Cybersecurity & Cyber Resilience Framework (CSCRF), and CERT-In directives.
● Direct internal and external security audits, risk assessments, regulatory reporting, and vulnerability closures requested by statutory auditors or regulators.
● Draft, maintain, and enforce enterprise-wide Information Security policies, procedures, and baseline security standards.
Qualifications & Skills:
● Experience: 8–10 years of core Information Security experience with hands-on technical management across Security Operations, Infrastructure Security, and GRC.
● Regulatory Expertise: Deep operational familiarity with RBI Cybersecurity Framework, SEBI CSCRF guidelines, CERT-In incident reporting mandates, and DPDP (Digital Personal Data Protection) Act requirements.
● Hands-on Tooling Knowledge on EDR/XDR, DLP, ZTNA/Network Security, SIEM/SOAR tools
Certifications (Preferred):
○ ISO 27001:2022 Lead Auditor
○ Certified Information Systems Security Professional (CISSP)
○ Certified Information Security Manager (CISM)
○ Certified Information Systems Auditor (CISA)
Click on Apply to know more.