Senior Associate, Cyber/IT Security, Technology and Operations
Posted on: October 15, 2025 | Deadline: November 22, 2025
Job ID: WD78374 | Company Name: DBS Bank
Division: Technology and Operations (T&O)
Location: India - Maharashtra - Mumbai
Schedule: Regular | Full-time | Permanent
Job Description
The Senior Associate, Cyber/IT Security, will play a vital role in safeguarding the organisation’s technology ecosystem. This position involves comprehensive responsibility for the planning, execution, and oversight of cyber defence measures — including vulnerability management, application security, penetration testing, and regulatory compliance reporting. The role requires strong coordination across business, development, and risk management teams to ensure robust protection of banking systems and infrastructure.
Core Purpose
To reinforce the Information Security framework through continuous vulnerability assessments, penetration testing, application security governance, and cyber assurance activities — enhancing the organisation’s defence, resilience, and compliance posture.
Key Responsibilities
- Manage and perform periodic internal and external vulnerability assessments across production and critical systems.
- Coordinate penetration testing and document remediation progress with stakeholders across multiple teams.
- Oversee annual security testing for new and existing applications while maintaining relevant tools and testing environments.
- Collaborate with Application Development teams to embed Secure Development Lifecycle (SDL) controls.
- Develop key performance indicators (KPIs) to measure progress of the security assurance program.
- Ensure regulatory and compliance requirements for information security are consistently met and well-documented.
- Track emerging vulnerabilities, zero-day exploits, and ensure appropriate risk mitigation measures are applied.
Vulnerability Management
- Execute and monitor vulnerability scanning using tools such as Rapid7, Nessus, Metasploit, and QualysGuard.
- Analyze scan reports, prioritize risks, and ensure remediation is handled according to established SLAs.
- Maintain awareness of the latest cyber exploits, assess their applicability, and advise internal teams.
- Engage with threat intelligence feeds and integrate insights into security operations and patch management schedules.
Application Security
- Monitor and evaluate the Bank’s Application Security program including source code reviews (SCR), SAST, and DAST processes.
- Collaborate with application developers and architects to implement best practices for API, CI/CD, and containerized (Docker, Kubernetes, OpenShift) environments.
- Organize training workshops and awareness sessions for Security Mavens and related technology teams.
- Maintain policies, control standards, and documentation in alignment with internal governance requirements.
- Lead new AppSec-related initiatives, tools adoption, and automation for continuous improvement.
Skills and Experience Required
- Minimum 6 years of experience in Information or Cyber Security, with at least 4 years in application and vulnerability management roles.
- Hands-on expertise in tools such as Burp Suite, Rapid7, Nessus, Metasploit, and QualysGuard.
- Knowledge of network and system security controls like WAF, IDS/IPS, Firewalls, and HIDS solutions.
- Strong analytical, communication, and documentation skills with the ability to translate risks into actionable insights.
- Experience managing teams of five or more, including vendor or consultant engagement.
Education and Certifications
- Graduation: BE (IT/Computers/Electronics), B.Sc (Computers), or M.Sc (Computers).
- Post-Graduation: PGDIT, MCA, or MBA preferred.
- Professional Certifications: CISSP, CISM, OSCP/OSCE, SANS, or CREST (highly preferred).
Core Competencies
- Analytical thinking and strong decision-making skills.
- Excellent report writing, communication, and presentation capabilities.
- Ability to validate and consult on strategic risk mitigation for systems and business units.
- Ethical approach to information handling and proactive risk identification.
Work Environment
This is a full-time role based in Mumbai, Maharashtra. The individual will collaborate with internal teams within the Technology and Operations group, including Information Security, Development, and Infrastructure Services, ensuring seamless operational security for the Bank’s digital framework.

