Senior Associate, Cyber Security | VAPT & AppSec | DBS Bank, India

RemoteNest 0

Senior Associate, Cyber/IT Security, Technology and Operations

Posted on: October 1, 2025 | Deadline: November 12, 2025

Job ID: WD76951 | Company Name: DBS Bank

Division: Technology and Operations (T&O)

Location: India - Tamil Nadu - Technology Centre

Schedule: Regular | Full-time | Permanent


Technology and Operations (T&O)

T&O enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and strive to delight our business partners through our multiple banking delivery channels.

Job Purpose

The purpose of this job role is to manage Information Security – Internal & External Vulnerability Assessment, Penetration Testing, Application Security Assessment, Source code review follow-up, Wireless PT, ATM/POS security Assessment, Secure Configuration Review, Vulnerability management domains to enhance threat detection and mitigation capabilities within the Bank. This role is additionally responsible for enhancing cyber assurance and appropriate regulatory reporting of cybersecurity aspects.


Key Accountabilities

  • Vulnerability management and Penetration Testing
  • Application security
  • Virtualization and container technologies (**Docker, Kubernetes, OpenShift**).
  • API Security
  • CI/CD assessment
  • IS Related compliance and regulatory reporting

Job Duties & Responsibilities

Vulnerability Management:

  • Manage periodic internal and external VA scanning for the bank’s production systems.
  • Analyze and report/present the vulnerabilities to multiple stakeholders for remediation and prioritization.
  • Maintain intelligence network to discover any reported exploits, **zero day vulnerabilities** and its applicability to Bank.
  • Experience with tools such as **Rapid7, Nessus, Metasploit, QualysGuard**, etc.

Security Testing & Application Security:

  • Manage annual security testing program for the existing and new production systems.
  • Maintain tools and environment to support security testing, working with internal teams and consultants as required.
  • Collaboratively work with Application Development / Security Mavens and guide them to follow the **Security gates set in the Organization’s SDL**.
  • Evaluate internal Technology Risk Processes as it relates to App Pentest, **FOSS, Fortify SCA** and provide process governance as well as thought leadership concerning adjusting to future needs.
  • Liaison with customer relation and team responsible to address the external requests related to AppSec.
  • Coordinate Security Mavens training and manage monthly meetings.
  • Manage and update Key Performance Indicators (**KPI’s**) for the Application Security Assurance Program.
  • Manage the **application security threat modeling process** and coordinate application threat models against the Organization’s applications.
  • Liaison with various internal teams (Application Development, IT Architecture, Corp. Procurement Services, etc.) for Application security initiatives and automation efforts).
  • Evangelize application security within the firm.
  • Coordinate with ASAP team members to track internal audit and regulatory assessments and address requests related to the Application Pentest, **SAST, DAST and SCR (Source code review)**.
  • Mitigates risk by following established procedures and monitoring controls, spotting key errors and demonstrating strong ethical behaviour.

Requirements

  • Overall 6+ years on experience in Information/Cyber Security.
  • Experience in vulnerability management and application security for 4+ years.
  • Experience in managing 5+ members team which may include vendor teams.
  • Candidate should have worked in BFSI (preferred).

Education / Preferred Qualifications

  • Graduation: BE IT/Computers/Electronics, B.Sc - Computers, M.Sc - Computers.
  • Post-Graduation: PGDIT, MCA, MBA.
  • Certification: CISSP, CISM, SANS, OSCP/OSCE and CREST (Prefered).

Core & Technical Competencies

Core Competencies

  • Excellent analytical and decision-making skill sets.
  • Effective in Communication, documentation and report writing skills.
  • Ability to consult and validate solutions to mitigates risks to business and systems.

Technical Competencies

  • VAPT: Rapid7, Nessus, Metasploit, QualysGuard, Burpsuite, CI/CD tool etc.
  • Technical working knowledge: WAF, HIDS, IPS, Firewall, Networking.


🧠 Key Skills & Tools for Cybersecurity Role

Cyber Threat Analysis Network Security Penetration Testing Incident Response Vulnerability Management SIEM Tools (Splunk, QRadar) Firewall Configuration Endpoint Security Cloud Security (AWS, Azure) Identity & Access Management Ethical Hacking Security Operations Center (SOC) Forensic Investigation Data Privacy & Protection Risk Assessment Security Policy Development Compliance (ISO 27001, GDPR) Threat Intelligence Security Auditing DevSecOps Phishing Detection Zero Trust Architecture Security Awareness Training

Resume Match Score - Cyber Security Analyst Position

Hire Vetted Talent via REZI
"Stop Wasting Time on Bad Hires: Get Vetted Talent Here"
✅ Get Started with Rezi.ai
⚠️ Disclaimer: The job information provided on this page is directly sourced from the employer’s official career site. We do not act as a recruitment agency and are not involved in the hiring process. The resume checker and skill tools are offered solely for user guidance and do not guarantee job selection.

Post a Comment

0 Comments
* Please Don't Spam Here. All the Comments are Reviewed by Admin.

About Us

Joblyst 2025 is your go-to hub for the latest job updates, career tips, and opportunities to shape a brighter future.