DBS Bank

Senior Associate, Cyber/IT Security, Technology and Operations

DBS Bank  •  Republic of India (Onsite)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Business Function

Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.

Job Purpose

The purpose of this job role is to manage IT Security with strong hands-on capabilities across Application Security, Vulnerability Management, DevSecOps, and Red Teaming. The role requires end-to-end ownership from security design and troubleshooting to project execution, compliance monitoring, and continuous improvement of the security posture.

Key Accountabilities

  1. Vulnerability management and Penetration Testing
  2. Application security
  3. Virtualization and container technologies (Docker, Kubernetes, OpenShift).
  4. API Security, Red Teaming & Security Testing
  5. CI/CD assessment
  6. IS Related compliance and regulatory reporting

Job Duties & Responsibilities

Application Security

  1. Lead application security assessments including SAST, DAST, IAST, SCA, and manual code reviews.
  2. Identify, validate, and prioritize application security vulnerabilities and guide remediation with development teams.
  3. Ensure secure design and implementation aligned with OWASP Top 10, ASVS, and secure coding standards.
  4. Review application architecture and data flows from a security perspective.

Vulnerability Management

  1. Own the end-to-end vulnerability management lifecycle across applications, infrastructure, cloud, and endpoints.
  2. Perform vulnerability validation, risk-based prioritization, exception handling, and closure tracking.
  3. Coordinate with multiple stakeholders to ensure timely remediation and SLA adherence.
  4. Provide management-level reporting on vulnerability trends, risk exposure, and remediation status.

DevSecOps

  1. Integrate security controls into CI/CD pipelines (e.g., code scanning, dependency scanning, secrets management).
  2. Enable shift-left security by embedding security checkpoints in development and deployment processes.
  3. Work closely with DevOps teams to automate security testing and compliance checks.
  4. Define and enforce secure SDLC and DevSecOps governance.

Red Teaming & Security Testing

  1. Coordinate and manage red team / penetration testing exercises (internal and external).
  2. Validate findings, assess business impact, and track remediation to closure.
  3. Support purple team activities to improve detection and response capabilities.
  4. Conduct root cause analysis and provide improvement recommendations.

Compliance & Governance Monitoring

  1. Monitor and ensure compliance with internal security policies, standards, and regulatory requirements.
  2. Support audits, assessments, and regulatory reviews by providing evidence and technical clarifications.
  3. Track security issues, risk acceptances, and remediation plans across all security domains.

Troubleshooting & Project Ownership

  1. Act as a senior escalation point for complex security issues and incidents.
  2. Lead security initiatives and projects from planning and execution to closure.
  3. Coordinate with cross-functional teams to resolve security gaps without impacting business timelines.

Requirements

  1. 8–12+ years of experience in IT / Information Security, with strong hands-on exposure.
  2. Deep understanding of Application Security, Vulnerability Management, DevSecOps, and Red Teaming.
  3. Strong knowledge of web, API, cloud, and infrastructure security.
  4. Experience working with security tools (SAST/DAST/SCA, vulnerability scanners, CI/CD tools).
  5. Solid understanding of security frameworks and standards (OWASP, NIST, ISO 27001, PCI DSS – preferred).
  6. Ability to translate technical security issues into business and risk impact.
  7. Strong stakeholder management and communication skills.

Education / Preferred Qualifications

  1. Graduation: BE IT/Computers/Electronics, B.Sc - Computers, M.Sc - Computers
  2. Post-Graduation: PGDIT, MCA, MBA
  3. Certification like CISSP, CISM, SANS, OSCP/OSCE and CREST (Prefered)

Core Competencies

  1. Excellent analytical and decision-making skill sets
  2. Effective in Communication, documentation and report writing skills
  3. Ability to consult and validate solutions to mitigates risks to business and systems

Technical Competencies

  1. VAPT - Rapid7, Nessus, Metasploit, QualysGuard, Burpsuite ,CI/CD tool etc.
  2. Technical working knowledge (WAF, HIDS, IPS, Firewall, Networking
  3. SAST: Checkmarx, Fortify, Veracode, SonarQube , DAST: Burp Suite, OWASP ZAP, AppScan
  4. SCA: Black Duck, Snyk, WhiteSource (Mend)
  5. API Security: Postman, Burp, OWASP API tools.

Location:

I-Think Techno, Kanjurmarg

Job:

Technology

Schedule:

Regular

Employee Status:

Full time

DBS Bank

About DBS Bank

DBS is a leading financial services group in Asia with a presence in 19 markets. Headquartered and listed in Singapore, DBS is in the three key Asian axes of growth: Greater China, Southeast Asia and South Asia. The bank's "AA-" and "Aa1" credit ratings are among the highest in the world.

Recognised for its global leadership, DBS has been named “World’s Best Bank” by Global Finance, “World’s Best Bank” by Euromoney and “Global Bank of the Year” by The Banker. The bank is at the forefront of leveraging digital technology to shape the future of banking, having been named “World’s Best Digital Bank” by Euromoney and the world’s “Most Innovative in Digital Banking” by The Banker. In addition, DBS has been accorded the “Safest Bank in Asia“ award by Global Finance for 14 consecutive years from 2009 to 2022.

DBS provides a full range of services in consumer, SME and corporate banking. As a bank born and bred in Asia, DBS understands the intricacies of doing business in the region’s most dynamic markets. DBS is committed to building lasting relationships with customers, as it banks the Asian way. Through the DBS Foundation, the bank creates impact beyond banking by supporting social enterprises: businesses with a double bottom-line of profit and social and/or environmental impact. DBS Foundation also gives back to society in various ways, including equipping communities with future-ready skills and building food resilience.

With its extensive network of operations in Asia and emphasis on engaging and empowering its staff, DBS presents exciting career opportunities. For more information, please visit www.dbs.com

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
Singapore, SG
Year Founded
1968
Website
dbs.com
Social Media