Posted on: 05/08/2026
Role Summary :
You will own Mynts full security lifecycle end-to-end: harden application, data, and infrastructure security; embed SAST/DAST into every CI/CD gate; run penetration testing and vulnerability assessment; own encryption, key management, and Regulatory Compliance (e.g. DPDP Act 2023 / DPDP Rules 2025 compliance); and secure the environments across Dev, QA, Staging, and Production. Youll bring DevOps, AWS, & SRE (Site Reliability Engineering) skills to keep the platform secure and available, act as first responder for security incidents, and guide the team on secure coding and threat modeling.
The AI-Augmented Edge :
At Pyvot, AI is your primary workforce. Use Claude Code, Cursor, Gemini, for threat-model drafting, SAST/DAST triage, security config review, and IaC policy generation targeting a 3x- 5x efficiency gain. Practise Cross-LLM Validation: one LLM audits findings generated by another. Your value is measured by security posture and resilience, not tickets closed.
Core Responsibilities :
Application, Data & Infrastructure Security : Be the Guardian
- Secure-by-Design & Threat Modeling : Own secure coding standards and STRIDE threat modeling for every new service and major change.
- Application & API Security : Enforce OWASP Top 10 mitigations, secure API design, safe error handling across the Mynt stack. Prevention of SQL injection, etc.
- Data Security & Encryption : Own TLS 1.3 in transit, field-level encryption at rest, and KMS/HSM key management and rotation. Prevent data security attacks.
- Cloud, Network & Tenant Isolation : Harden the applications and systems deployed in AWS via segmented VPCs/DMZs, Firewall (WAF / GuardDuty / Shield / Security Hub / Inspector, least-privilege IAM, and IDOR-safe tenant isolation.
Penetration Testing, Vulnerability Management & Security Testing :
- SAST & DAST : Run SAST (Semgrep, SonarQube, CodeQL, Snyk Code) on every PR and DAST (OWASP ZAP, Burp Suite) on every release candidate, including authenticated multi-tenant runs for IDOR.
- Penetration Testing Ownership : Plan and coordinate independent penetration tests before major launches, including annual CERT-In empanelled VAPT, and drive every finding to closure. Also, Implement the systems to prevent DDOS attacks, etc.
- Vulnerability & Risk Management : Run continuous SCA, container, and cloud configuration vulnerability scans; maintain risk register scored by likelihood impact.
- CI/CD Security Gating : Make SAST, secrets scanning, SCA, IaC, and container scanning blocking gates on critical findings before promotion to production.
Data Protection, Encryption & Regulatory Compliance : Build the Trust Layer :
- Data Classification & Governance : Classify data by sensitivity, document data flows, and enforce minimization, retention, and deletion schedules. Implement industry standards & best-practices related to data privacy, data protection, data auditing, tenant data isolation, principle of least privilege (PoLP), etc.
- Data Privacy and Regulatory Compliance : DPDP Act 2023 / DPDP Rules 2025 Compliance: Own data residency in AWS ap-south-(1or2), encryption / masking / tokenization safeguards, and breach-notification readiness. Ensure compliance with all other regulatory requirements related to managing financial data of customers.
- OAuth & Third-Party Integration Security : Secure Gmail/Outlook OAuth with minimum-viable scopes, encrypted token vaulting, and Google CASA compliance.
- Payment Security & Vendor Risk : Keep payment processing at PCI-DSS SAQ-A scope with HMAC webhook verification, and run DPDP-aligned vendor risk assessments for every data processor.
DevOps, Cloud Infrastructure & Site Reliability Engineering :
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1660750