Vice President - Offensive Security Lead

Sbi Cards And Payment Services Limited

Gurgaon/Gurugram

Not disclosed

Work from Office

Full Time

Min. 5 years

Job Details

Job Description

Vice President - Offensive Security Lead

About Us

SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto 'Make Life Simple' inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.

SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, colour, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.

Join us to shape the future of digital payment in India and unlock your full potential.

What’s in it for YOU

  1. SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
  2. Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
  3. Dynamic, Inclusive and Diverse team culture 
  4. Gender Neutral Policy
  5. Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
  6. Commitment to the overall development of an employee through comprehensive learning & development framework

Role Purpose 

Responsible for ensuring development, implementation, and effectiveness of vulnerability management and security testing programs, initiatives, and capabilities

Role Accountability 

  1. Assist with strategic planning, providing input on capabilities and methods used for vulnerability management and security testing, and driving improvements
  2. Develop Vulnerability management framework, support compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks
  3. Lead innovative research and stay updated on emerging threats, vulnerabilities, and exploits with the goal of developing new TTPs improving attack efficacy 
  4. Partner with Security Operations team to develop tooling and instrumentation (including automation) to improve detection and response capabilities
  5. Design scenario-based / thematic security testing to identify vulnerabilities in the product and gaps in detection and response capabilities
  6. Engage with the developers in developing workarounds / mitigation plan and ensure they are implemented per policy
  7. Manage security testing related programs such as responsible disclosure / bug bounty
  8. Conduct vulnerability assessments and penetration testing, red teaming, blue teaming (application and/or infrastructure) and articulating security issues to technical and non-technical audience
  9. Provide expertise in security tools for vulnerability assessment, penetration testing & application security
  10. Perform vulnerability risk profiling and prioritization of vulnerabilities
  11. Perform regular status reviews with IT asset owners & senior leadership to ensure compliance with InfoSec policies
  12. Provide security architecture and advice in support of application development, infrastructure, and enterprise technology projects
  13. Drive secure coding related training and awareness initiatives for software developers & architects at SBI Cards 
  14. Oversee the development, implementation and maintenance of vendor standard operating procedures/ run book in line with SBI Card policies & standards
  15. Monitor offensive security vendor SLAs, perform regular review with vendor management and report to SBI Card leadership
  16. Ensure process documentation and compliance adherence

Measures of Success 

  1. Reduction in security vulnerabilities in SBI Card IT platforms
  2. Reduction in information leakage and exploitation from vulnerabilities
  3. Compliance with regulatory guidelines
  4. Timely and accurate vulnerability testing and remediation
  5. Vendor SLA Adherence 
  6. No adverse observations in internal/external audits
  7. Process Adherence as per MOU

Technical Skills / Experience / Certifications

  1. Strong knowledge of web development and programming languages e.g. Java, .NET, Python, etc.
  2. Strong knowledge of web application technology, e.g. Application Servers, Web Servers, Databases
  3. Ability to perform security testing on an app development project either using struts, spring much like java based frameworks
  4. Experience of performing manual code review and manual dynamic testing to find application vulnerabilities
  5. GIAC/GWAPT/GPEN/GXPN/OSCP/CISSP certification, or any other equivalent industry accredited certification
  6. Exposure to methodologies, such as OWASP preferred, Penetration, Host, Applications (Ethical Hacking tools such as Nessus, Qualys, Nexpose), Vulnerability Assessments - Network, Host, Applications, Security in SDLC (Application Security), Secure code review - .NET and J2EE technologies
  7. Experience of building, deploying, and managing offensive security operational infrastructure
  8. Knowledge of open source intelligence gathering and social engineering
  9. Knowledge of Commodity and advanced threat actor Tactics, Techniques and Procedures
  10. Expert-level knowledge and experience in identifying multiple classes of vulnerabilities that includes cross-site scripting, SQL Injection, CSRF, cryptographic related weakness, and code injection

Competencies critical to the role

  1. Analytical Ability
  2. Innovation & Problem Solving
  3. High Impact Communication
  4. Market Awareness
  5. Continuous Learning

Qualification 

Bachelor of Engineering in Computer Science / Engineering/ or any other relevant discipline, Masters in Computer Science/or any other relevant discipline

Preferred Industry

BFSI, NBFC, E-Commerce, IT development and operations

Experience Level

Senior Level

Job role

Work location

Gurugram, India

Department

IT & Information Security

Role / Category

IT Security

Employment type

Full Time

Shift

Day Shift

Job requirements

Experience

Min. 5 years

About company

Name

Sbi Cards And Payment Services Limited

Job posted by Sbi Cards And Payment Services Limited

Apply on company website