Senior Information Security Engineer

Company Introduction-

iServeU is a modern banking infrastructure provider in APAC region, empowering financial enterprises with embedded fintech solutions for their customers. iServeU is one of the few certified partners with National Payment Corporation of India (NPCI), VISA for various products.
iServeU also provides a cloud-native, micro services-enabled, distributed platform with over 5000 possible product configurations with a low code/no code interface to banks, NBFCs, Fintech, and other regulated entities.
• We process around 2500 transactions per second by levering distributed & auto scale technology like K8.
• Our core platform combines of 1200+ micro services.
• Our customer list includes Fintech start-ups, top tier private banks to PSU bank. We operate in five countries and help customers constantly change the way financial institutions operate and innovate.
• Our solutions currently empowers over 20 banks and 250+ enterprises across India and abroad.
• Our platform seamlessly manages the entire transaction lifecycle, including withdrawals, deposits, transfers, payments, and lending through various channels like digital, branch, agents.
Our team of 500+ employees, with over 80% in technology roles is spread across offices in Bhubaneswar, Bangalore and Delhi. We have raised $8 million in funding to support our growth and innovation.
For more details visit:


Job Summary

We are looking for a Senior Information Security Engineer to join our InfoSec team. In this role, you will be responsible for designing, implementing, and maintaining security controls across our infrastructure, applications, and cloud environments, while protecting company data, systems, and networks from evolving cyber threats and responding to security incidents.
You will act as a security engineering, incident response, and risk management, working closely with IT, DevOps, Engineering, and other stakeholders to strengthen the organization's overall security posture. The ideal candidate should have experience in SOC, VAPT, GRC, security audits, risk assessments, and compliance, along with a strong combination of hands-on technical cybersecurity knowledge and governance and compliance expertise.

Overall Responsibilities:

The candidate is required to have an overall understanding, broad conceptual snapshot of the following subject matters with understanding of rules, structural principles, mechanisms, techniques and nuances which can assist our organisation in quick decision-making, cross-disciplinary communication, solving problems, troubleshooting errors, and creating innovations.
• Design, implement, and review secure network, infrastructure, application, and cloud security architectures, including firewalls, IDS/IPS, IAM, DLP, SOAR, EDR, NDR and other security technologies.
• Manage SIEM and Security Operations using tools like Wazuh, monitor and investigate security events and support incident response activities.
• Conduct Vulnerability Assessments, Penetration Testing (VAPT), Red Team operations, attack simulations, and exploit validation across web, API, mobile, infrastructure, and cloud environments.
• Perform manual and automated web application and API security testing, including business logic validation, aligned with OWASP Top 10 and industry best practices.
• Conduct security assessments and code reviews for Android and iOS mobile applications, following OWASP methodologies and mobile security best practices.
• Conduct Third-Party Risk Assessments, security reviews, customer security questionnaires, and vendor assessments.
• Support GRC, internal audits, regulatory audits, and certification audits, including ISO 27001, PCI DSS, SOC, RBI, and NPCI requirements.
• Conduct periodic risk assessments, security audits, control assessments, and compliance reviews, ensuring identified risks and audit observations are tracked through closure.
• Coordinate with Development, Infrastructure, DevOps, Cloud, Networking, and Business teams to identify security gaps, prioritize risks, and drive remediation activities.
• Develop and maintain security policies, standards, procedures, hardening guidelines, risk registers, audit documentation, and technical security documentation.
• Implement and maintain security monitoring, detection, alerting, vulnerability management, and security controls to strengthen the organization's overall security posture.
• Participate in incident response, root-cause analysis, containment, eradication, and recovery, and recommend preventive measures to avoid recurrence.
• Identify and eliminate public exposure and security vulnerabilities while ensuring remediation is completed with minimal or zero impact to production environments.
• Handle and coordinate banking and regulatory security audits, ensuring timely submission of evidence, responses, and corrective actions.
• Stay updated on emerging threats, vulnerabilities, attack techniques, regulatory requirements, and cybersecurity technologies, and recommend appropriate security improvements.
• Provide technical guidance and mentorship to junior security engineers and support security awareness across technical and business teams.


Requirements

Educational Qualification
BE / B.Tech
Candidates with security or compliance related certifications will be given due preference
Experience: 3-5 years in Information Security / Cybersecurity

Key Skills
• Audit Planning & Execution
• Security Monitoring, Incident Detection and Response
• Regulatory Compliance and Certification Support
• NPCI Ecosystem Compliance.
• Vulnerability Assessment, Risk Identification and Remediation Management
• Compliance Support, Audit Readiness and Governance Framework
• Security Policy, SOP Development as per Regulatory Alignment
• Third-Party and Vendor Security Risk Assessments
• Technical Security Evaluations as per PCI DSS Compliance


See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available