
About the Role
We are seeking an experienced Cyber Security Specialist who can operate across both offensive and defensive security disciplines. This dual-role professional will lead Vulnerability Assessment and Penetration Testing (VAPT) engagements, act as the in-house Red Team to simulate real-world adversaries, and own the implementation and continuous improvement of the Information Security Management System (ISMS) aligned with ISO/IEC 27001 and related standards. You will combine hands-on offensive security work with governance, audit readiness, and stakeholder engagement across engineering, IT, legal, and executive leadership.
Key Responsibilities
VAPT & Red Team Operations
- Plan, scope, and execute end-to-end Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, mobile apps, APIs, networks, cloud environments, wireless, and physical infrastructure.
- Act as the organization's in-house Red Team, simulating advanced persistent threat (APT) actors through adversary emulation, social engineering, phishing campaigns, and physical intrusion testing where authorized.
- Design and execute Red Team operations aligned with MITRE ATT&CK, TIBER-EU, and similar frameworks; develop custom Tactics, Techniques, and Procedures (TTPs).
- Conduct manual and automated exploitation, post-exploitation, lateral movement, privilege escalation, and persistence testing in production-like environments.
- Develop custom exploits, payloads, scripts, and tooling (Python, PowerShell, Bash, C/C++, Go) to bypass security controls during sanctioned engagements.
- Perform source code reviews, threat modeling, and secure architecture reviews of new and existing systems.
- Coordinate Purple Team exercises with the Blue Team / SOC to validate detection coverage and improve defensive playbooks.
- Produce high-quality VAPT and Red Team reports with executive summaries, technical findings, proof-of-concept exploits, risk ratings (CVSS), and prioritized remediation guidance.
- Re-test remediated findings and track closure with engineering and IT teams through to verification.
ISO Compliance & Governance
- Lead the implementation, maintenance, and continual improvement of the ISMS in line with ISO/IEC 27001:2022, including scope definition, Statement of Applicability (SoA), and risk treatment plans.
- Own and maintain ISO policies, procedures, controls, and documentation across the organization, ensuring alignment with ISO 27001, ISO 27017, ISO 27018, and ISO 22301.
- Plan and coordinate internal and external audits; serve as the primary liaison with certification bodies, auditors, and regulators.
- Conduct risk assessments, business impact analyses (BIA), and threat modeling; maintain a central risk register and drive remediation.
- Map VAPT and Red Team findings to ISO 27001 Annex A controls and feed results into the risk management lifecycle.
- Support compliance with adjacent frameworks: SOC 2, NIST CSF, GDPR, HIPAA, PCI-DSS, and DPDP Act (India), as applicable.
- Define and report security and compliance KPIs/KRIs to senior leadership; prepare materials for management reviews and board updates.
- Develop and deliver security awareness training, phishing simulations, and role-based secure-coding training.
- Drive third-party / vendor risk management, including security questionnaires, contractual clauses, and ongoing monitoring.
- Partner with engineering and DevOps to embed security into the SDLC, CI/CD pipelines, and cloud architectures (DevSecOps).
Incident Response & Continuous Improvement
- Support incident response activities: detection, triage, containment, eradication, recovery, and post-incident reviews.
- Maintain business continuity and disaster recovery plans; coordinate BCP/DR testing and tabletop exercises.
- Stay current on emerging threats, CVEs, attacker techniques, regulatory changes, and ISO standard updates; recommend and drive improvements.
Required Qualifications
- 8+ years of progressive experience in cyber security, with at least 4 years in hands-on offensive security (VAPT, penetration testing, or Red Team) and 3+ years in ISO 27001 implementation and audits.
- Proven track record of leading VAPT engagements across web, mobile, API, network, cloud (AWS / Azure / GCP), and wireless environments.
- Hands-on experience executing Red Team operations and adversary emulation aligned with MITRE ATT&CK.
- Deep proficiency with offensive security tooling: Burp Suite Pro, Metasploit, Cobalt Strike (or open-source equivalents like Sliver, Mythic, Havoc), Nmap, Nessus, Nuclei, BloodHound, Impacket, Responder, and OWASP ZAP.
- Strong scripting and exploit development skills in Python, PowerShell, Bash, and at least one compiled language (C/C++, Go, or Rust).
- Proven hands-on experience leading an organization through ISO 27001 certification and surveillance audits end-to-end.
- Strong working knowledge of ISO/IEC 27001:2022 (including Annex A controls), ISO 27002, ISO 27017, ISO 27018, and ISO 22301.
- Solid understanding of security domains: IAM, network security, endpoint security, cloud security, application security (OWASP Top 10, API Security Top 10), and Active Directory attack paths.
- Experience with risk assessment methodologies (ISO 27005, NIST 800-30) and the ability to translate offensive findings into business risk.
- Strong report-writing, policy-drafting, and executive communication skills.
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field (or equivalent experience).
Preferred Qualifications
- Offensive security certifications: OSCP, OSEP, OSWE, OSED, CRTO, CRTP, CRTE, CRTL, GPEN, GXPN, GWAPT, or CEH Practical.
- Governance certifications: ISO 27001 Lead Implementer and/or Lead Auditor, CISSP, CISM, CISA, or CRISC.
- Cloud security certifications (CCSP, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer).
- Published CVEs, security research, bug bounty achievements, or contributions to open-source security tools.
- Experience with Active Directory / Entra ID red teaming, Kerberos attacks, and modern EDR/XDR evasion techniques.
- Experience with container, Kubernetes, and serverless security testing.
- Experience implementing or auditing additional frameworks: SOC 2 Type II, NIST CSF, NIST 800-53, HITRUST, or PCI-DSS.
- Experience with GRC platforms (Vanta, Drata, Sprinto, ServiceNow GRC, Archer, OneTrust).
- Experience in regulated industries: financial services, healthcare, SaaS, or critical infrastructure.
- Experience briefing executive leadership, customers, and external auditors on offensive findings and remediation strategy.

Similar jobs
Job Description : Quantitative R&D Engineer
As a Quantitative R&D Engineer, you’ll explore data and design logic that becomes live trading strategies. You’ll bridge the gap between raw research and deployed, autonomous capital systems.
What You’ll Work On
- Analyze on-chain and market data to identify inefficiencies and behavioral patterns.
- Develop and prototype systematic trading strategies using statistical and ML-based techniques.
- Contribute to signal research, backtesting infrastructure, and strategy evaluation frameworks.
- Monitor and interpret DeFi protocol mechanics (AMMs, perps, lending markets) for alpha generation.
- Collaborate with engineers to turn research into production-grade, automated trading systems.
Ideal Traits
- Strong in data structures, algorithms, and core CS fundamentals.
- Proficiency in any programming language
- Understanding of probability, statistics, or ML concepts.
- Self-driven and comfortable with ambiguity, iteration, and fast learning cycles.
- Strong interest in markets, trading, or algorithmic systems.
Bonus Points For
- Experience with backtesting or feature engineering.
- Exposure to crypto primitives (AMMs, perps, mempools, etc.)
- Projects involving alpha signals, strategy testing, or DeFi bots.
- Participation in quant contests, hackathons, or open-source work.
What You’ll Gain:
- Cutting-Edge Tech Stack: You'll work on modern infrastructure and stay up to date with the latest trends in technology.
- Idea-Driven Culture: We welcome and encourage fresh ideas. Your input is valued, and you're empowered to make an impact from day one.
- Ownership & Autonomy: You’ll have end-to-end ownership of projects. We trust our team and give them the freedom to make meaningful decisions.
- Impact-Focused: Your work won’t be buried under bureaucracy. You’ll see it go live and make a difference in days, not quarters
What We Value:
- Craftsmanship over shortcuts: We appreciate engineers who take the time to understand the problem deeply and build durable solutions—not just quick fixes.
- Depth over haste: If you're the kind of person who enjoys going one level deeper to really "get" how something works, you'll thrive here.
- Invested mindset: We're looking for people who don't just punch tickets, but care about the long-term success of the systems they build.
- Curiosity with follow-through: We admire those who take the time to explore and validate new ideas, not just skim the surface.
Compensation:
- INR 6 - 12 LPA
- Performance Bonuses: Linked to contribution, delivery, and impact.
A Day in the Life:
- Collaborate with developers and product managers to understand feature requirements.
- Review feature specifications and design detailed test cases.
- Perform manual tests on payment gateway systems, including transaction flows and API validations.
- Identify, log, and track defects using tools like JIRA and prioritize them for resolution.
- Conduct regression testing to ensure system stability after updates.
- Participate in team discussions to troubleshoot and resolve issues.
- Document test results and prepare for upcoming sprint activities.
Key Qualifications and Skills:
- 5 - 7 years of QA experience, with at least 3 years in payment gateways, fintech, or banking systems.
- Strong knowledge of payment processing.
- Experience with REST/SOAP APIs, webhooks, and encryption (TLS, AES, RSA). Familiarity with PCI-DSS, PSD2, GDPR, and AML/KYC processes.
- Proficiency in SQL for database validation (transaction logs, ledger entries).
- Hands-on experience with JMeter, Postman, Selenium, or similar tools.
- Knowledge of blockchain-based payouts (optional but a plus).
Key Responsibilities:
- Test Planning & Strategy: Develop and execute test plans, test cases, and test scripts for payment processing, refunds, chargebacks, settlements, and fraud detection. Ensure compliance with PCI-DSS, PSD2, and other financial regulations.
- Functional & Integration Testing: Validate API integrations with banks, PSPs (Payment Service Providers) and third-party vendors. Test transaction flows (success, failure, retries, timeouts) and edge cases.
- Security & Compliance Testing: Perform penetration testing, vulnerability scanning, and data encryption checks. Ensure PCI compliance and adherence to EMV, 3D Secure (3DS2), and SCA (Strong Customer Authentication).
- Performance & Load Testing: Conduct stress testing to evaluate system behaviour under high transaction volumes (TPS - Transactions Per Second). Identify bottlenecks in authorization, settlement, and reconciliation processes.
- Automation & Tools: Develop and maintain automated test scripts (using tools like Postman, Selenium, JMeter, or Karate). Work with CI/CD pipelines for regression testing.
- Defect Management: Log, track, and prioritize bugs using JIRA, Bugzilla, or similar tools. Collaborate with developers, product managers, and compliance teams for issue resolution.
- Documentation & Reporting: Maintain test documentation, including test cases, test data, and audit logs. Provide QA metrics and test summary reports to stakeholders.
Job Title: HR Executive (Fresher)
Location: Noida, Sec 63
Experience: 3-5 Years
Employment Type: Full-time
Job Summary
We are looking for an enthusiastic and motivated HR Executive (Fresher) to support day-to-day HR operations. The ideal candidate should have a basic understanding of HR functions and a strong willingness to learn and grow in the Human Resources domain.
Key Responsibilities
Recruitment & Onboarding
- Assist in sourcing candidates through job portals, referrals, and campus hiring.
- Schedule interviews and coordinate with hiring managers.
- Support joining formalities and employee onboarding.
HR Operations
- Maintain employee records and HR databases.
- Assist in attendance, leave, and basic payroll coordination.
- Ensure proper documentation of employee files.
Employee Engagement
- Support employee engagement activities and HR initiatives.
- Assist in handling employee queries and basic HR communication.
Compliance & Administration
- Support HR compliance documentation as per company policies.
- Assist in drafting HR letters (offer letters, appointment letters, etc.).
Required Skills & Competencies
- Good communication skills (verbal & written)
- Basic knowledge of HR concepts and labor laws
- Proficiency in MS Excel, MS Word, and email communication
- Strong organizational and time management skills
- Willingness to learn and adapt
Educational Qualification
- Graduate/Postgraduate in HR, MBA (HR), BBA, or related field
Who Can Apply
- Candidates with the experience 3 years-5 years of experience
- Candidates looking to build a long-term career in HR
What We Offer
- Career growth opportunities
- Friendly and professional work environment
We are looking out for a technically driven "Full-Stack Engineer" for one of our premium client
COMPANY DESCRIPTION:
Qualifications
• Bachelor's degree in computer science or related field; Master's degree is a plus
• 3+ years of relevant work experience
• Meaningful experience with at least two of the following technologies: Python, Scala, Java
• Strong proven experience on distributed processing frameworks (Spark, Hadoop, EMR) and SQL is very
much expected
• Commercial client-facing project experience is helpful, including working in close-knit teams
• Ability to work across structured, semi-structured, and unstructured data, extracting information and
identifying linkages across disparate data sets
• Confirmed ability in clearly communicating complex solutions
• Understandings on Information Security principles to ensure compliant handling and management of
client data
• Experience and interest in Cloud platforms such as: AWS, Azure, Google Platform or Databricks
• Extraordinary attention to detail
Profile: Project Manager
Experience: 6+ years
Education Qualification: Graduate/Postgraduate
Neewee is an Industrial Analytics start-up, focused in making manufacturing visible, transparent, efficient, and autonomous to its clients.
Started in 2014 our journey has evolved from making manufacturing complexity and risk a thing of the past.
Bodhee is our in-house product. We are looking for Project Managers to work with our Product team .
Responsibilities:
· Manage technical aspects of projects, including planning, execution, and delivery
· Translate product strategy into detailed requirements for prototype construction and final product development
· Create Functional and Technical specification documents, translate application storyboards and use cases into functional applications
· Track project progress, identify and mitigate risks, and ensure project deliverables are completed on time and within budget
· Delivering new Bodhee features using AGILE delivery programs
· Ensure project quality and adherence to industry standards and best practices
· To act as a single point of contact from the team to Bodhee Stakeholders
· Identify and implement process improvements to increase efficiency and reduce costs
· Promote teamwork, motivate, mentor and develop subordinates
· Manage and take ownership of product including defining scope and developing requirements for product launch
Requirements
· Overall 6+ years’ experience with 3+ years of experience as Project Manager for any development projects and hands-on technical experience
· Proven experience as a technical project manager, with a track record of delivering projects on time and within budget
· Experience with agile software development methodologies.
· Strong experience with Java and UI design and development
· Strong experience leading development teams utilizing Java and UI technologies.
· Working experience with Data Analytics products is a plus
· Strong understanding of RDBMS and working experience with SQL
· Experience with developing Micro-services Based applications
· Excellent problem-solving and analytical skills
· Excellent communication skills
• Has a thorough understanding of relational databases and security relating to PHP/MySQL
• Has expertise in HTML/CSS/JavaScript/jQuery
• Skilled in managing backend services and ensuring seamless data interchange between server and end-users. No traditional HR Processes
• Knowledgeable with writing web services and REST APIs for web and mobile application integration.
• Has designed and maintained database experience.
• AWS can be a plus point
Job Title: Oracle PL/SQL Developer
Qualification: (B.E./B.Tech/ Masters in Computer or IT)
Years of Experience: 3 – 7 Years
No. of Open Positions – 3
Job Location: Jaipur
- Proven hands-on Database Development experience
- Develop, design, test and implement complex database programs
- Strong experience with oracle functions, procedures, triggers, packages & performance tuning,
- Ensure that database programs are in compliance with V3 standards.
- Hands-on development using Oracle PL/SQL.
- Performance tune SQL's, application programs and instances.
- Evaluation of new and upcoming technologies.
- Providing technical assistance, problem resolution and troubleshooting support.
- Essentail Skills:
- Docker
- Jenkins
- Python dependency management using conda and pip
- Base Linux System Commands, Scripting
- Docker Container Build & Testing
- Common knowledge of minimizing container size and layers
- Inspecting containers for un-used / underutilized systems
- Multiple Linux OS support for virtual system
- Has experience as a user of jupyter / jupyter lab to test and fix usability issues in workbenches
- Templating out various configurations for different use cases (we use Python Jinja2 but are open to other languages / libraries)
- Jenkins PIpeline
- Github API Understanding to trigger builds, tags, releases
- Artifactory Experience
- Nice to have: Kubernetes, ArgoCD, other deployment automation tool sets (DevOps)
Responsibilities
Perform a mix of maintenance, enhancements, and new development as required
Work in a data analyst role and with business intelligence applications
Document features, technical specifications & infrastructure Responsibilities
Work cross-functionally to convert business needs into technical specifications
Qualifications
0-1 years of experience in web development and software design
Expertise in front-end technologies (HTML, JavaScript, CSS), PHP frameworks (Laravel), and MySQL databases
Job Description
We are looking for a Full Stack Developer to produce scalable software. You’ll be part of a cross-functional team that’s responsible for the full software development life cycle, from conception to deployment.
As a Full Stack Developer, you should be comfortable around both front-end and back-end coding languages, development frameworks and third-party libraries. With problem-solving approaches and rigorous thinking abilities, we are looking for learners who may not know all the answers but are obsessive about finding them and know exactly where to look for them.
“If you’re also familiar with Agile methodologies, we’d like to meet you.”
Responsibilities
- Writing code for both the front end and the back end using MERN stack [MongoDB, Express.js, React.js and Node. js]
- Creating RESTful API with Node.js
- Maintaining all the required documents for your project.
- Constantly coming up with new ideas and also implementing them to improve the app’s performance.
- Writing code for the app logic as well as the business logic using Reducers, Actions and Redux framework.
- Create Unit and Integration tests to ensure the quality of code
Requirements
- At iDC, we value your skills more than your background and some certificates. Attempting the assignment will be your door to the opportunity.
- Knowledge of the database and familiarity with the schema design in NoSQL (i.e MongoDB)
- A good understanding of the Software Development Lifecycle
- Knowledge of API design and development using REST
- Good understanding of object-oriented programming(OOP) and OOP patterns.
- Again, You don’t have to know it all in-depth but you should know how to dig the internet for finding the solutions.











