HamburgerMenu
hirist

Job Description

Role Summary :

You will own Mynts full security lifecycle end-to-end: harden application, data, and infrastructure security; embed SAST/DAST into every CI/CD gate; run penetration testing and vulnerability assessment; own encryption, key management, and Regulatory Compliance (e.g. DPDP Act 2023 / DPDP Rules 2025 compliance); and secure the environments across Dev, QA, Staging, and Production. Youll bring DevOps, AWS, & SRE (Site Reliability Engineering) skills to keep the platform secure and available, act as first responder for security incidents, and guide the team on secure coding and threat modeling.

The AI-Augmented Edge :

At Pyvot, AI is your primary workforce. Use Claude Code, Cursor, Gemini, for threat-model drafting, SAST/DAST triage, security config review, and IaC policy generation targeting a 3x- 5x efficiency gain. Practise Cross-LLM Validation: one LLM audits findings generated by another. Your value is measured by security posture and resilience, not tickets closed.

Core Responsibilities :

Application, Data & Infrastructure Security : Be the Guardian

- Secure-by-Design & Threat Modeling : Own secure coding standards and STRIDE threat modeling for every new service and major change.

- Application & API Security : Enforce OWASP Top 10 mitigations, secure API design, safe error handling across the Mynt stack. Prevention of SQL injection, etc.

- Data Security & Encryption : Own TLS 1.3 in transit, field-level encryption at rest, and KMS/HSM key management and rotation. Prevent data security attacks.

- Cloud, Network & Tenant Isolation : Harden the applications and systems deployed in AWS via segmented VPCs/DMZs, Firewall (WAF / GuardDuty / Shield / Security Hub / Inspector, least-privilege IAM, and IDOR-safe tenant isolation.

Penetration Testing, Vulnerability Management & Security Testing :

- SAST & DAST : Run SAST (Semgrep, SonarQube, CodeQL, Snyk Code) on every PR and DAST (OWASP ZAP, Burp Suite) on every release candidate, including authenticated multi-tenant runs for IDOR.

- Penetration Testing Ownership : Plan and coordinate independent penetration tests before major launches, including annual CERT-In empanelled VAPT, and drive every finding to closure. Also, Implement the systems to prevent DDOS attacks, etc.

- Vulnerability & Risk Management : Run continuous SCA, container, and cloud configuration vulnerability scans; maintain risk register scored by likelihood impact.

- CI/CD Security Gating : Make SAST, secrets scanning, SCA, IaC, and container scanning blocking gates on critical findings before promotion to production.

Data Protection, Encryption & Regulatory Compliance : Build the Trust Layer :

- Data Classification & Governance : Classify data by sensitivity, document data flows, and enforce minimization, retention, and deletion schedules. Implement industry standards & best-practices related to data privacy, data protection, data auditing, tenant data isolation, principle of least privilege (PoLP), etc.

- Data Privacy and Regulatory Compliance : DPDP Act 2023 / DPDP Rules 2025 Compliance: Own data residency in AWS ap-south-(1or2), encryption / masking / tokenization safeguards, and breach-notification readiness. Ensure compliance with all other regulatory requirements related to managing financial data of customers.

- OAuth & Third-Party Integration Security : Secure Gmail/Outlook OAuth with minimum-viable scopes, encrypted token vaulting, and Google CASA compliance.

- Payment Security & Vendor Risk : Keep payment processing at PCI-DSS SAQ-A scope with HMAC webhook verification, and run DPDP-aligned vendor risk assessments for every data processor.

DevOps, Cloud Infrastructure & Site Reliability Engineering :


- CI/CD & Infrastructure-as-Code : Co-own GitHub Actions pipelines and provision/harden AWS (EC2, ECS/EKS, Lambda, RDS, S3) via Terraform / CloudFormation with security checks baked in.

- Monitoring & Observability : Design monitoring and alerting via CloudWatch, ELK, Grafana, or PagerDuty, with dedicated alarms for security events and anomalies.

- Site Reliability Engineering : Own on-call, incident response, RTO/RPO targets, and regular disaster-recovery/failover testing.

- Audit Logging & Cost-Aware Security : Maintain tamper-evident, deny-delete audit logging, balanced against a lean, startup-scale cloud footprint.

Incident Response & Team Leadership : Be the Last Line of Defence

- Security Incident First Response : Triage, contain, eradicate, and recover from security incidents, with credential revocation and rollback ready to go.

- Incident Response Planning : Maintain and test a formal incident-response plan with DPDP-aligned breach-notification timelines and blameless post-incident reviews.

- Mentoring, Standards & Reporting : Mentor engineers on secure coding and threat modeling, maintain runbooks/standards, and report security posture to the CTO.

Roles Requirements : Intersection of Cybersecurity, Data Protection & Cloud

Were looking for a full-spectrum security specialist equal parts application security engineer, cloud/infrastructure/AWS architect, data protection owner, and DevOps/SRE practitioner: a Guardian of Mynts security posture, at ease with a threat model, a WAF rule, a Terraform diff, and a 2 AM security alert.

Must-Have Skills & Experience :

- Cybersecurity Engineering Experience : 7 - 10 years owning application, data, and infrastructure security for a production SaaS/cloud-native product end-to-end.

- Application & Data Security : Deep expertise in OWASP Top 10, secure API design, encryption at rest/in transit, secrets management, and multi-tenant/IDOR-safe authorization.

- SAST/DAST & Penetration Testing : Hands-on with SAST (Semgrep, SonarQube, CodeQL, Snyk) and DAST (OWASP ZAP, Burp Suite) in CI/CD, plus direct penetration-testing/VA experience.

- DevOps, AWS & SRE : 5+ years with AWS (EC2, ECS/EKS, Lambda, RDS, S3, IAM, KMS, VPC), Terraform/CloudFormation, CI/CD, and SRE practices (on-call, RTO/RPO).

- Data Protection & Regulatory Compliance : Working knowledge of DPDP Act 2023 / DPDP Rules 2025 or equivalent (GDPR) classification, encryption governance, breach notification.

Should-Have Skills & Experience :

- Security Frameworks & AWS Services : Familiarity with ISO 27001/SOC 2/CERT-In audit processes, plus hands-on with WAF, GuardDuty, Shield, Security Hub, Inspector, and Trivy.

- Third-Party, Vendor & Monitoring : Experience securing OAuth integrations, PCI-DSS SAQ-A payment flows, vendor risk reviews, and monitoring via CloudWatch/ELK/Grafana/PagerDuty.

- Incident Response Leadership : Experience leading security incident response, breach investigations, and post-incident reviews in production.

- Agile & Cross-Functional Collaboration : Comfortable in Agile/Scrum delivery, sprint planning, and close collaboration with engineering, product, and leadership.

Good-To-Have Skills & Experience :

- Education & Certifications : Degree from a premier institute (IITs/NITs/BITS/IIITs) plus CISSP/CEH/OSCP/AWS Security Specialty/CompTIA Security+ a strong plus.

- QA Automation Exposure : A bonus, not a requirement this roles mandate is security, not QA automation.

- AI-Augmented Security Tooling : Experience using AI/LLM tools (Claude Code, Cursor, Gemini) for threat-model drafting and vulnerability triage.

- Regulated-Industry Experience : Prior security ownership in a fintech, healthtech, or other DPDP/GDPR-regulated product.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...