Source description
About the role
Basic Position Details Position Title: Lead Threat Exposure & Security Assurance Location: Mumbai (Cuffe Parade) Candidate Profile Requirements Mandatory Criteria Age Limit as on: 25-32 Education Qualification: BCA/B.tech/B.E Minimum % Required:60 Minimum Experience Required: 3 to 4 Years Relevant Industry/Domain Experience: BFSI experience mandatory of atleast 12 to 18 months with good understanding of regulatory requirements surrounding VAPT. Preferred Criteria (if applicable) Preferred Skills: good understanding of: Vulnerability Assessment Penetration Testing Configuration Vulnerability Assessment Red Teaming Continuous Threat Exposure Management Change Management Certifications (if any): Relevant certification like CEH or equivalent is a must. A good understanding of OSCP / OSCP certified is a must Languages Required: English Interview & Selection Process Any Skill test /Assessments Needed: Yes, as mentioned Interview (Online / In-person): First round online and second in-person Roles & Responsibilities Vulnerability Assessment & Management Ensure the performance regular network, application, and endpoint VA scans Identify, classify and prioritize vulnerabilities (CVSS as well as EPSS - based) Validate false positives Assist IT team to fix the identified vulnerabilities Track remediation lifecycle with IT teams Penetration Testing (PT) Oversee manual + automated penetration testing Coverage: Application PT Web + Mobile + Thick client APIs PT Internal network PT External attack surface risk assessment Develop proof-of-concepts (PoCs) for vulnerabilities Provide remediation guidance Perform pre and post-Change Validation Testing Ensure No new high-risk vulnerabilities are getting introduced Configuration Vulnerability Assessment (Config VA): Preparation of Secure configuration document (SCD) Work with partner(s) and prepare SCDs as per CIS Benchmarks Get them approved as per internal process Ensure that assessment is conducted against the above defined SCDs Ensure that the Config VA Review covers following: Servers (Windows/ Linux) Databases Web Servers Network devices Any other applicable device/ servers/ Systems Identify misconfigurations (e.g., open ports, weak policies) Red Teaming (Advanced Capability) Prepare Red Teaming approach note. Ensure the test cases simulate real-world attacks, including but not limited to: Privilege escalation Lateral movement Phishing campaigns Test detection capabilities (SOC effectiveness) Emulate adversary tactics (MITRE ATT&CK framework) Continuous Threat Exposure Management (f CTEM) Continuously identify attack surface exposure The process should ensure the coverage Integration: Vulnerabilities Misconfigurations Identity risks Prioritize risks based on exploitability (not just CVSS) Work with following to get the identified gaps fixed: SOC Infra App teams Maintain continuous visibility not periodic testing Reporting & Governance Ensure that the team delivers Executive risk reports and detailed Technical reports Track remediation SLAs Support audits (RBI / NHB / ISO 27001 likely relevant for LICHFL) Maintain documentation and evidence Maintain risk-based vulnerability dashboards Prepare, maintain and regularly update Internal security policies and procedure documents. Ensure that these documents are aligned to regulatory requirements and internal expectations. Translate technical risks into: Business impact Financial exposure Regulatory risk Provide: Clear go / no-go recommendations Risk acceptance notes (if needed) Main the VAPT trackers and ensure that they are getting fixed within the defined time-lines Main risk registers depicting the open risk, impact, time-lines to fix the identified gap (If available) Tooling Responsibility Candidate should have experience in: VA Tools: Nessus / Qualys / Rapid7 Pentest: Burp Suite, Metasploit, Nmap Red Team: Cobalt Strike / BloodHound CTEM: Exposure management platforms (if available) Change Management Security Oversight Participate in Change Advisory Board (CAB) meetings Review all critical / high-risk changes such as: New application deployments Infrastructure changes Firewall rule changes Cloud configuration updates Perform pre-change risk assessments such as: Security Risk Evaluation (Pre-Implementation risk assessment) Secure Design Validation covering at least the following: Secure architecture principles Least privilege access Segmentation
More at LIC HOUSING FINANCE LIMITED