About the Company
iServeU is a modern banking infrastructure provider operating across the APAC region. The company empowers financial enterprises with embedded fintech solutions, enabling them to offer seamless digital banking experiences to their customers. iServeU is one of the few certified partners of the National Payment Corporation of India (NPCI) and Visa, reflecting its strong compliance and technological credibility. The platform is cloud-native, microservices-enabled, and offers over 5,000 product configurations through a low-code/no-code interface. Serving over 20 banks and 250+ enterprises across India and abroad, iServeU processes around 2,500 transactions per second using distributed and auto-scaling technologies like Kubernetes. With a team of 500+ employees (over 80% in technology roles) and offices in Bhubaneswar, Bangalore, and Delhi, the company has raised $8 million in funding to support its growth and innovation.
Role Overview
We are seeking a Senior Information Security Engineer to join our InfoSec team. In this role, you will be responsible for designing, implementing, and maintaining security controls across our infrastructure, applications, and cloud environments. You will protect company data, systems, and networks from evolving cyber threats and respond to security incidents. The ideal candidate possesses hands-on technical cybersecurity knowledge combined with governance and compliance expertise, and has experience in SOC operations, VAPT, GRC, security audits, risk assessments, and regulatory compliance.
Key Responsibilities
- Design, implement, and review secure network, infrastructure, application, and cloud security architectures, including firewalls, IDS/IPS, IAM, DLP, SOAR, EDR, NDR, and other security technologies.
- Manage SIEM and Security Operations using tools like Wazuh; monitor and investigate security events and support incident response activities.
- Conduct Vulnerability Assessments, Penetration Testing (VAPT), Red Team operations, attack simulations, and exploit validation across web, API, mobile, infrastructure, and cloud environments.
- Perform manual and automated web application and API security testing, including business logic validation, aligned with OWASP Top 10 and industry best practices.
- Conduct security assessments and code reviews for Android and iOS mobile applications, following OWASP methodologies and mobile security best practices.
- Conduct Third-Party Risk Assessments, security reviews, customer security questionnaires, and vendor assessments.
- Support GRC, internal audits, regulatory audits, and certification audits, including ISO 27001, PCI DSS, SOC, RBI, and NPCI requirements.
- Conduct periodic risk assessments, security audits, control assessments, and compliance reviews, ensuring identified risks and audit observations are tracked through closure.
- Coordinate with Development, Infrastructure, DevOps, Cloud, Networking, and Business teams to identify security gaps, prioritize risks, and drive remediation activities.
- Develop and maintain security policies, standards, procedures, hardening guidelines, risk registers, audit documentation, and technical security documentation.
- Implement and maintain security monitoring, detection, alerting, vulnerability management, and security controls to strengthen the organization's overall security posture.
- Participate in incident response, root-cause analysis, containment, eradication, and recovery, and recommend preventive measures to avoid recurrence.
- Identify and eliminate public exposure and security vulnerabilities while ensuring remediation is completed with minimal or zero impact to production environments.
- Handle and coordinate banking and regulatory security audits, ensuring timely submission of evidence, responses, and corrective actions.
- Stay updated on emerging threats, vulnerabilities, attack techniques, regulatory requirements, and cybersecurity technologies, and recommend appropriate security improvements.
- Provide technical guidance and mentorship to junior security engineers and support security awareness across technical and business teams.
Tech Stack
- SIEM: Wazuh
- Security Tools: IDS/IPS, IAM, DLP, SOAR, EDR, NDR, Firewalls
- Cloud: Cloud-native (AWS/GCP/Azure)
- Container Orchestration: Kubernetes (K8)
- Microservices: 1200+ microservices architecture
- Mobile Security: Android, iOS (OWASP Mobile)
- Web/API Security: OWASP Top 10, API security testing
- Compliance Frameworks: ISO 27001, PCI DSS, SOC, RBI, NPCI
- Audit & GRC: Risk assessment, vendor security assessments
- Development & DevOps: Python, Bash, CI/CD pipelines (implied)