Jobs
Interviews

Sisa Information Security

SISA is a global leader in information security consulting, specializing in cyber security and compliance solutions tailored to businesses worldwide.

20 Job openings at Sisa Information Security
Hitrust Auditor Gurugram,Bengaluru,Mumbai (All Areas) 1 - 3 years INR 12.0 - 14.0 Lacs P.A. Hybrid Full Time

Associate Consultant Roles and Responsibilities: Assist the project management team in analysing project data and generating reports to track progress and identify areas for improvement. Assist the Business Operations head with financial budgeting, forecasting and revenue tracking Obtain quarterly client feedback and customer testimonials. Collaborate with cross-functional teams to gather and analyse data, ensuring accuracy and completeness. Participate in governance meetings and track client issues to avoid escalations. Identify and escalate project risks and issues to the project management team. Collaborate with team members to identify opportunities for process improvement and implement solutions. Help track contract timelines, renewals and upsell opportunities. Qualifications: Bachelor's degree and an MBA in Operations/Finance or a related field. 1-3 years of experience in a Business Operations/PMO department or similar role. Strong analytical and problem-solving skills. Proficient in Microsoft Office Suite, particularly Excel and PowerPoint. Excellent communication and interpersonal skills. Ability to work independently and collaboratively in a team environment. Detail-oriented with strong organizational skills. CAPM, PMP certification is a plus.

Network Security Consultant Kochi 2 - 5 years INR 7.0 - 12.0 Lacs P.A. Work from Office Full Time

Job Description in brief including Roles & Responsibilities : Perform periodically system and application VAPT (Vulnerability Assessment and l Penetration Testing) using automated and manual approach. Perform asset and network discovery activities, helping ensure full coverage of the vulnerability discovery. Prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and asset. Identify and test vulnerabilities in the areas of the information system and networks security. Conduct and compile findings on new vulnerabilities, new tools for departmental use. Create project deliverables /reports and assist the immediate supervisor during submissions and client discussions. Performing assessment related to Red Teaming, Network Penetration Testing, Web Application Penetration Testing, Mobile Application Penetration Testing, Secure Code review, AD Security Assessments, Vulnerability Management, Social Engineering Assessments,Wireless Penetration Testing. Mandatory Skills required for the role: Hands on experience with Vulnerability Assessment and Penetration testing of thick & thin client-based applications, Operating systems, edge devices and firewalls. Research, recommend, evaluate and implement information security solutions that identify and and/ or protect against potential threats, and respond to security violations, misuse of resources or noncompliance situations using defined escalation processes. Strong Experience of using open-source tools and commercials tools such as but not limited to Burp Suite, Metasploit, Nessus, Acunetix, Checkmarx, and Nexpose with operating systems Windows and Linux. Expertise and experience of conducting VAPT (Vulnerability Assessment and Penetration Testing) as per standards such as OWASP Top 10, SANS Top 25 and WASC, NIST. Perform research on new vulnerabilities, attack vectors, exploits, tools and industry trends services. Provide offsite and on-site consulting services to our customers. Collaborating with other members of the engagement team to plan the engagement and develop work program timelines, risk assessments and other douments/templates. Well familiar with basics of TCP/IP and Networking principles. Extensive Working knowledge of Operating systems: Windows NT/2K3/XP and Linux or any Unix OS Knowledge about Computer Networks, System Security, Firewalls and l Vulnerabilities. Optional Skills for the role: Firewall rule review Segmentation Testing

SOC L2 Bengaluru 2 - 6 years INR 13.0 - 15.0 Lacs P.A. Work from Office Full Time

Role & responsibilities Daily review of security alerts/logs with follow-up on any suspicious activity Perform investigation of network and hosts/endpoints for malicious activity, to include analysis of packet captures, and assist in efforts to detect, confirm, contain, remediate, and recover from attacks. Proactively monitor, identify and analyze complex internal and external threats, including viruses, targeted attacks and unauthorized access, and mitigate risk to IT systems Work in concert with team members, Information Security engineering, and relevant Subject Matter Experts to process, analyze and drive the remediation of identified IT related vulnerabilities Responsible to follow the IT Security Incident Response policies and tools Contribute to Information Security policies, standards, and supporting documentation Root cause analysis, troubleshoot complex issues with existing security and privacy protection protocols Responding to inbound security monitoring alerts, emails, and inquiries from the organization. Providing support for Incident Response, including evidence collection, documentation, communications, and reporting Maintaining and improving standard operating procedures and processes

Fresher (Strategic Risk Planning) Bengaluru,Mumbai (All Areas) 0 - 1 years INR 1.0 - 4.5 Lacs P.A. Work from Office Full Time

Trainee Roles and Responsibilities : Introduction to Information Security, Overview of Information Security Standards and Frameworks, ISO 27001: Information Security. Management System (ISMS), Business Continuity Management System (BCMS) - ISO 22301, Privacy Information Management System (PIMS) - ISO 27701, Risk Assessment and Management, Practical Implementation and Case Studies, NIST Cybersecurity Framework (CSF). GDPR (General Data Protection Regulation), HIPAA (Health Insurance Portability and Accountability Act), Introduction to Auditing Qualifications: B.E. / B.Tech in Computer engineering, ETC, masters in information security, Cyber Law

Digital Forensic Gurugram,Bengaluru,Mumbai (All Areas) 9 - 14 years INR 35.0 - 50.0 Lacs P.A. Hybrid Full Time

We are seeking a Senior DFIR Analyst with experience in forensic investigation and incident response. The candidate should be able to handle cases end-to-end, including client communication, reporting, and leading the team of forensic analysts. The ideal candidate should have experience in forensic investigation of all major operating systems such as Windows Server, Linux, and Mac OS. The candidate would also be responsible to R&D activities to identify new tools and techniques for forensic analysis and incident response. Key Responsibilities: Handle digital forensic cases end to end, including acquisition of data, analysis of complex digital evidence, client communication, presentations and reporting. Conduct forensic investigations of all major operating systems such as Windows, Linux, Mac OS, etc. Conduct forensic analysis of system and application logs, web applications logs, network traffic, and other digital artifacts. Provide expert technical assistance to clients during investigations and incident response activities. Lead the team of forensic analysts in conducting investigations and incident response activities. Mentor and train junior analysts on DFIR techniques, tools, and best practices. Conduct R&D activities to identify new tools and techniques for forensic analysis and incident response. This includes staying up-to-date with industry trends and emerging technologies to continually enhance our forensic capabilities Document and present findings, including preparing detailed forensic analysis reports. Requirements: Bachelor/master's degree in digital Forensics, Computer Science, or a related field. 5-8 years of experience in digital forensics and incident response. Experience in leading a team of forensic analysts. In-depth knowledge of digital forensic tools and techniques. Excellent written and verbal communication skills. Ability to effectively communicate technical concepts to non-technical stakeholders. Ability to manage multiple cases simultaneously and provide timely updates and status reports. Ability to work independently and as part of a team. Experience with forensic analysis of system and application logs, web applications logs, network traffic, and other digital artifacts. Strong analytical and problem-solving skills. Excellent searching skills and self-learning. Preferred Qualifications: Relevant industry certifications such as AccessData Certified Examiner (ACE), EC-Council Certified Hacking Forensic Investigator (EC-CHFI), GCFA, GCFE, EnCE or other relevant certifications. Experience with programming languages for scripting/automation of tasks. Experience with reverse engineering and malware analysis. Strong analytical and problem-solving skills. Experience in R&D activities. Familiarity with legal and regulatory requirements related to digital forensics and incident response.

Specialist Bengaluru 5 - 8 years INR 10.0 - 11.0 Lacs P.A. Work from Office Full Time

Job Description: We are seeking a Senior DFIR Analyst with experience in forensic investigation and incident response. The candidate should be able to handle cases end-to-end, including client communication, reporting, and leading the team of forensic analysts. The ideal candidate should have experience in forensic investigation of all major operating systems such as Windows Server, Linux, and Mac OS. The candidate would also be responsible to R&D activities to identify new tools and techniques for forensic analysis and incident response. Key Responsibilities: Handle digital forensic cases end to end, including acquisition of data, analysis of complex digital evidence, client communication, presentations and reporting. Conduct forensic investigations of all major operating systems such as Windows, Linux, Mac OS, etc. Conduct forensic analysis of system and application logs, web applications logs, network traffic, and other digital artifacts. Provide expert technical assistance to clients during investigations and incident response activities. Lead the team of forensic analysts in conducting investigations and incident response activities. Mentor and train junior analysts on DFIR techniques, tools, and best practices. Conduct R&D activities to identify new tools and techniques for forensic analysis and incident response. This includes staying up-to-date with industry trends and emerging technologies to continually enhance our forensic capabilities Document and present findings, including preparing detailed forensic analysis reports. Requirements: Bachelor/masters degree in digital Forensics, Computer Science, or a related field. 5-8 years of experience in digital forensics and incident response. Experience in leading a team of forensic analysts. In-depth knowledge of digital forensic tools and techniques. Excellent written and verbal communication skills. Ability to effectively communicate technical concepts to non-technical stakeholders. Ability to manage multiple cases simultaneously and provide timely updates and status reports. Ability to work independently and as part of a team. Experience with forensic analysis of system and application logs, web applications logs, network traffic, and other digital artifacts. Strong analytical and problem-solving skills. Excellent searching skills and self-learning. Preferred Qualifications: Relevant industry certifications such as AccessData Certified Examiner (ACE), EC-Council Certified Hacking Forensic Investigator (EC-CHFI), GCFA, GCFE, EnCE or other relevant certifications. Experience with programming languages for scripting/automation of tasks. Experience with reverse engineering and malware analysis. Strong analytical and problem-solving skills. Experience in R&D activities. Familiarity with legal and regulatory requirements related to digital forensics and incident response.

Analyst Mumbai 1 - 3 years INR 3.0 - 5.0 Lacs P.A. Work from Office Full Time

Key Responsibilities: Plan, coordinate, and perform PCI DSS assessments. Work with stakeholders across departments to gather evidence and validate compliance. Identify areas of non-compliance and develop recommendations for remediation. Prepare formal audit reports Liaise with Qualified Security Assessors (QSAs) and support formal PCI DSS validation efforts. Maintain documentation of security policies, procedures, and controls as they relate to PCI DSS. Required Qualifications: Bachelor s degree in Information Security, Computer Science, Information Systems, or related field. Minimum of 1-3 years of experience in IT auditing, security assessment. Basic knowledge of PCI DSS v4.0 Familiarity with information security frameworks (e.g., NIST, ISO 27001). Basic Understanding of network security, encryption, access control, and vulnerability management. Excellent verbal and written communication skills.

Senior Specialist Bengaluru 3 - 5 years INR 5.0 - 7.0 Lacs P.A. Work from Office Full Time

Job Summary: We are seeking a knowledgeable and detail-oriented PCI DSS Auditor to join our compliance and information security team. The auditor will be responsible for planning, executing, and managing audits to ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS) . The ideal candidate will have deep knowledge of PCI DSS requirements and a strong background in IT security, risk management, and regulatory compliance. Key Responsibilities: Plan, coordinate, and perform internal and external PCI DSS assessments. Conduct risk assessments and gap analyses against PCI DSS requirements. Work with stakeholders across departments to gather evidence and validate compliance. Identify areas of non-compliance and develop recommendations for remediation. Prepare formal audit reports and present findings to management. Liaise with Qualified Security Assessors (QSAs) and support formal PCI DSS validation efforts. Maintain documentation of security policies, procedures, and controls as they relate to PCI DSS. Monitor changes to PCI DSS and related regulations to ensure ongoing compliance. Provide training and guidance to internal teams on PCI DSS requirements and best practices. Assist in the remediation of audit findings and track progress until closure. Required Qualifications: Bachelor s degree in Information Security, Computer Science, Information Systems, or related field. Minimum of 3-5 years of experience in IT auditing, security assessment, or compliance. In-depth knowledge of PCI DSS v4.0 and prior experience conducting PCI audits. Familiarity with information security frameworks (e.g., NIST, ISO 27001). Strong understanding of network security, encryption, access control, and vulnerability management. Preferred Qualifications: Certification such as PCI ISA , PCI QSA , CISA , CISSP , or CISM . Experience working in regulated industries (e.g., finance, healthcare, e-commerce). Experience with audit tools, GRC platforms, or compliance tracking systems. Excellent verbal and written communication skills.

Senior Specialist Chennai 3 - 5 years INR 20.0 - 25.0 Lacs P.A. Work from Office Full Time

Job Description : Customer Success Team Experience : 3 to 5 Years Business Requirements Good Communication Skills which include verbal and non-verbal communication skills. Previous Experience in handling multi-geographical clients. Good to have experience in the Cyber Security Domain. Willing to travel to customer location - Chennai and to SISA premises (includes SDC) on-need basis. Good interpersonal skills and to be a team player. Strong Learning Curve, ability to understand the requirements and support the customers. Technical Requirements Hands-on experience in handling the Windows and Linux Servers. Must have experience in the L1/L2 Support/Operations Background. Prior knowledge in handling the IIS configurations and supporting the same. Good to have prior product installations and configurations experience. Ability to understand the customer requirements and support them. Ability to provide walk-through about the product to the customers/end-users. Basic understanding of the Networking concepts. Good to have Cloud Support Experience (Azure, AWS and GCP etc.). Strong Troubleshooting and problem-solving experience. Good understanding of database concepts and hands-on experience in any of the RDBMS databases (Oracle, SQL Server, MySQL, PostgreSQL etc.). Basic understanding about the Load balancers, SSL certificates etc. Strong understanding of data classification, discovery tools, and regulatory compliance (PCI DSS, DPDP, HIPAA, etc.). Basic scripting or SQL knowledge is a plus Create and maintain SOPs, deployment runbooks, and customer-specific implementation documentation. Collaborate with customers to define scanning scopes, schedules, and classification rules.

Associate Consultant Bengaluru 1 - 5 years INR 9.0 - 10.0 Lacs P.A. Work from Office Full Time

Roles and Responsibilities: 1. To perform Web and Mobile Application and API Penetration testing 2. Client interaction 3. Perform retest post confirmation on the fixes 4. Follow up with the relevant stakeholders on the remediation of open vulnerabilities Mandatory skills required for the role: Web, API, and Mobile Penetration Testing Good understanding of OWASP methodology, ASVS, and other checklists Good written and spoken communication skills Ability to do report walkthrough with relevant stakeholders Hands-on experience with Burp suite pro, SQLmap, Kali Linux tools Optional skills for the role: Thick client App PT Secure code review

Associate Consultant Bengaluru 2 - 4 years INR 8.0 - 9.0 Lacs P.A. Work from Office Full Time

Associate Consultant 2-4 Years Roles and Responsibilities: 1. To perform Web and API Penetration testing 2. Perform Cloud security assessment (AWS and Azure must) based on CIS benchmark 3. Client interaction 4. Perform retest post confirmation on the fixes 5 Follow-up with the relevant stakeholders on the remediation of open vulnerabilities Mandatory Skills required for the role: Web, API Penetration Testing Good understanding of OWASP methodology, ASVS and other checklists Knowledge on cloud security and CIS benchmark Good written and spoken communication skills Ability to do report walkthrough with relevant stakeholders Hands-on experience with Burp suite pro, SQLmap, Kali Linux tools Hands on experience with Prowler, Pmapper, Scoutsuite, Cloudsploit Optional Skills for the role: Thick client/ Mobile App PT Secure code review

Data Privacy Lead Bengaluru 10 - 15 years INR 35.0 - 50.0 Lacs P.A. Hybrid Full Time

Key Responsibilities: Expansion of Data Privacy Professional Services: Engage with Decision-makers like Chief Information Security Officers (CISO) and Chief Information Officers (CIO), DPO (Data Protection Officer), CRO (Chief Risk Officer), to present and promote Data Protection and Governance Offerings and solutions. Increase SISAs wallet-share of business by showcasing the superiority of Companys Data Privacy service offerings and solution to existing and new clients. Strategy and Recasting of Service Offerings, solutions: Understand and develop competitive Data Privacy Service Offering Roadmap, artefacts, frameworks with respect to the service offering keeping in mind on competitive products and analyst reports. Craft implementable strategies to increase SISA’s footprint in the Data Protection and Governance space. Privacy requirements for products and solutions: Work with Product Development Teams to align products and service offerings in line with Contemporary Data Protection Laws and Industry-specific requirements in line with Laws prevailing in different geographies. Translating law requirements into workable and implementable work packets. Keep up to date with Market and Industry in Data Privacy domain: Ensure to keep self, team and management updated about latest happenings in Data Privacy and its applicability to transform offerings and product features in agile methodology to be current among others. Thought Leadership and Industry Connect: To stay connected with industry bodies, updates, guidance and contribute effectively through required means with focus of promoting service offerings, product solutions. Mentoring team members to contribute to blogs, white papers, patents and to enhance the proficient in privacy knowledge. Privacy Engineering and Technology Tools: To contribute and recommend the suitable privacy enhancing tools and technologies to clients and also to be integrated with existing Service offerings and enhance features in current platform and tools. Qualifications and Desired Skill: Technical Graduate preferably with an MBA and a Law Degree or Certification in Data Protection and Governance Proficient and hands-on experience in Data Privacy Enhancing Technology, Privacy Engineering and Industry Products Strong communication, collaboration, team management and interpersonal skills with key attention to details. Publishing of white papers, patents and other recognitions

Specialist Mumbai 6 - 8 years INR 8.0 - 10.0 Lacs P.A. Work from Office Full Time

Key Responsibilities: Certificates of Compliance: Prepare and maintain compliance certificates, ensuring timely completion and accuracy. PMO Repository Management: Organize and update project documentation within PMO repositories, ensuring proper version control and accessibility. Code Book Updates: Perform regular updates to project code books, maintaining alignment with project standards. Zoho Creator Updates: Follow up with stakeholders on Zoho Creator updates, ensuring project data is current and accurate. NPS Coverage Checks: Conduct Net Promoter Score (NPS) coverage checks and report findings to relevant teams. Timesheet Entry Checks: Monitor and verify timesheet submissions for completeness and accuracy, following up with team members on discrepancies. Operational Support: Assist with scheduling meetings, preparing reports, and other administrative tasks as required by the PMO team. Qualifications and Skills: Educational Background: Bachelor s degree in business administration, Project Management, or a related field. Experience: 6-71 years of experience in project management support, operations, or administrative roles. Fresh graduates with relevant internship experience are welcome to apply. Technical Skills: Proficiency in project management tools (e.g., Zoho Creator, Jira, MS Project) and MS Office Suite (Excel, Word, PowerPoint). Adobe Photoshop, WordPress. Communication: Strong verbal and written communication skills. Organizational Skills: Excellent attention to detail and ability to manage multiple tasks simultaneously. Analytical Skills: Basic understanding of project management concepts and ability to interpret data for reporting.

Standard Audit Bengaluru,Mumbai (All Areas) 4 - 7 years INR 8.0 - 15.0 Lacs P.A. Hybrid Full Time

Role & responsibilities Project delivery for skills ISO 27001, SOC 1&2, GDPR, Risk Assessment, SOX, HIPPA, HITRUST, etc. Hands on experience and/or working knowledge. Knowledge on laws, framework, and regulations pertaining to information security standards - ISO27001, NIST CSF, SOC, Privacy. Conduct third party risk assessments & vendor risk assessments in alignment with company security policies and industry standards. As part of the SRC team deliver on engagements related to information security, cyber security, risk management and privacy for our customers across the globe. Responsible for managing and delivering on accounts in accordance with SISA quality guidelines & methodologies. Execute the engagement requirements, prepare and validate reports and schedules that will be delivered to clients and other parties. Work effectively as team lead and managing the team members, sharing responsibility, providing support, maintaining communication and updating management on progress. Develop and maintain productive working relationships with client personnel. Prepare status updates and prepare management presentations etc. Actively contribute to improving operational efficiency on projects & internal initiatives. Assist in creating innovative insights for clients, adapt methods & practices to fit operational team needs, contribute to thought leadership documents and develop new methodologies. Understand and follow workplace policies and procedures. Flexible to travel to client location for the project delivery. Conducting research, surveys and interviews to gain understanding of the business. Assessing the pros and cons of possible strategies. Compiling and presenting information orally, visually and in writing.

SOC Manager bengaluru 7 - 12 years INR 30.0 - 35.0 Lacs P.A. Hybrid Full Time

Roles and Responsibilities: Serve as an escalation point for all Threat Analysts on shift for complex/unusual alerts/cases/requests/incidents. Daily review of security alerts/logs with follow-up on any suspicious activity. Basic understanding of Forensics / hands on experience of sandboxing Hands on experience and rule revisions of security solutions on phishing emails Review cases escalated by Threat Analysts to investigate, respond and remediate; Ensure an effective flow of escalated cases; and Conduct quality assurance of cases. Mentoring associate team members and contribute to streamlining SOC operations for continuous improvement. To ensure an escalate flow of Incident Management System; Assist the team in developing the incident response strategy and then creating and assigning response actions to Threat Analysts as needed. Perform investigation of network and hosts/endpoints for malicious activity, to include analysis of packet captures, and assist in efforts to detect, confirm, contain, remediate, and recover from attacks. Proactively monitor, identify, and analyze complex internal and external threats, including viruses, targeted attacks and unauthorized access, and mitigate risk to IT systems. Work in concert with team members, Information Security engineering, and relevant Subject Matter Experts to process, analyze and drive the remediation of identified IT related vulnerabilities Responsible to follow the IT Security Incident Response policies and tools. Contribute to Information Security policies, standards, and supporting documentation. Root cause analysis, troubleshoot complex issues with existing security and privacy protection protocols. Responding to inbound security monitoring alerts, emails, and inquiries from the organization. Providing support for Incident Response, including evidence collection, documentation, communications, and reporting. Maintaining and improving standard operating procedures and processes Responsible for onboarding the clients; both in cloud and on-prem. Mandatory Skills required for the role: Proven work experience as a Technical Support Engineer, Operation, System Admin or similar role. Hands on working Experience on any SIEM tool (Qradar /Alien Vault/ McAfee ESM/DNIF). 6 months to 1 year of L3 experience and team management is required. Team Management and Network Management / Operations Management. Good understanding of database, security products (Firewall, IDS/IPS, AV, WAF) and other security products. Desired Skills: Networking concepts Information security concepts Windows and troubleshooting and domain knowledge Linux and troubleshooting and domain knowledge Data Analysis Data Analytics for Security

Specialist bengaluru 3 - 5 years INR 5.0 - 7.0 Lacs P.A. Work from Office Full Time

Key Responsibilities: Plan, coordinate, and perform internal and external PCI DSS assessments. Conduct risk assessments and gap analyses against PCI DSS requirements. Work with stakeholders across departments to gather evidence and validate compliance. Identify areas of non-compliance and develop recommendations for remediation. Prepare formal audit reports and present findings to management. Liaise with Qualified Security Assessors (QSAs) and support formal PCI DSS validation efforts. Maintain documentation of security policies, procedures, and controls as they relate to PCI DSS. Monitor changes to PCI DSS and related regulations to ensure ongoing compliance. Provide training and guidance to internal teams on PCI DSS requirements and best practices. Assist in the remediation of audit findings and track progress until closure. Required Qualifications: Bachelor s degree in Information Security, Computer Science, Information Systems, or related field. Minimum of 3 5 years of experience in IT auditing, security assessment, or compliance. In-depth knowledge of PCI DSS v4.0 and prior experience conducting PCI audits. Familiarity with information security frameworks (e.g., NIST, ISO 27001). Strong understanding of network security, encryption, access control, and vulnerability management.

Senior Specialist bengaluru 3 - 5 years INR 5.0 - 7.0 Lacs P.A. Work from Office Full Time

Job Summary: We are seeking a knowledgeable and detail-oriented PCI DSS Auditor to join our compliance and information security team. The auditor will be responsible for planning, executing, and managing audits to ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS). The ideal candidate will have deep knowledge of PCI DSS requirements and a strong background in IT security, risk management, and regulatory compliance. --- Key Responsibilities: Plan, coordinate, and perform internal and external PCI DSS assessments. Conduct risk assessments and gap analyses against PCI DSS requirements. Work with stakeholders across departments to gather evidence and validate compliance. Identify areas of non-compliance and develop recommendations for remediation. Prepare formal audit reports and present findings to management. Liaise with Qualified Security Assessors (QSAs) and support formal PCI DSS validation efforts. Maintain documentation of security policies, procedures, and controls as they relate to PCI DSS. Monitor changes to PCI DSS and related regulations to ensure ongoing compliance. Provide training and guidance to internal teams on PCI DSS requirements and best practices. Assist in the remediation of audit findings and track progress until closure. --- Required Qualifications: Bachelor s degree in Information Security, Computer Science, Information Systems, or related field. Minimum of 3 5 years of experience in IT auditing, security assessment, or compliance. In-depth knowledge of PCI DSS v4.0 and prior experience conducting PCI audits. Familiarity with information security frameworks (e.g., NIST, ISO 27001). Strong understanding of network security, encryption, access control, and vulnerability management. --- Preferred Qualifications: Certification such as PCI ISA, PCI QSA, CISA, CISSP, or CISM. Experience working in regulated industries (e.g., finance, healthcare, e-commerce). Experience with audit tools, GRC platforms, or compliance tracking systems. Excellent verbal and written communication skills.

Analyst bengaluru 1 - 3 years INR 6.0 - 6.0 Lacs P.A. Work from Office Full Time

Key Responsibilities: Plan, coordinate, and perform PCI DSS assessments. Work with stakeholders across departments to gather evidence and validate compliance. Identify areas of non-compliance and develop recommendations for remediation. Prepare formal audit reports Liaise with Qualified Security Assessors (QSAs) and support formal PCI DSS validation efforts. Maintain documentation of security policies, procedures, and controls as they relate to PCI DSS. Required Qualifications: Bachelor s degree in Information Security, Computer Science, Information Systems, or related field. Minimum of 1 3 years of experience in IT auditing, security assessment. Basic knowledge of PCI DSS v4.0 Familiarity with information security frameworks (e.g., NIST, ISO 27001). Basic Understanding of network security, encryption, access control, and vulnerability management. Excellent verbal and written communication skills.

Analyst mumbai 1 - 3 years INR 6.0 - 6.0 Lacs P.A. Work from Office Full Time

Key Responsibilities: Plan, coordinate, and perform PCI DSS assessments. Work with stakeholders across departments to gather evidence and validate compliance. Identify areas of non-compliance and develop recommendations for remediation. Prepare formal audit reports Liaise with Qualified Security Assessors (QSAs) and support formal PCI DSS validation efforts. Maintain documentation of security policies, procedures, and controls as they relate to PCI DSS. Required Qualifications: Bachelor s degree in Information Security, Computer Science, Information Systems, or related field. Minimum of 1 3 years of experience in IT auditing, security assessment. Basic knowledge of PCI DSS v4.0 Familiarity with information security frameworks (e.g., NIST, ISO 27001). Basic Understanding of network security, encryption, access control, and vulnerability management. Excellent verbal and written communication skills.

Analyst bengaluru 2 - 4 years INR 6.0 - 7.0 Lacs P.A. Work from Office Full Time

Associate Consultant 2 4 Years Roles and Responsibilities: 1. Conduct penetration testing on web, mobile(android +ios), API, and thick-client applications to identify security weaknesses 2. Conduct automated and manual Secure code review 3. Identify and exploit vulnerabilities such as OWASP Top 10, SANS Top 25, and business logic flaws . 3. Client interaction on project updation/status 5. Collaborate with developers, product teams for Remediation support 6. Perform retest post confirmation on the fixes 6. Follow-up with the relevant stakeholders on the remediation of open vulnerabilities Mandatory Skills required for the role: Web, API and Mobile Penetration Testing Proficiency with penetration testing tools such as: Burp Suite, OWASP ZAP, Postman, Nmap, SQLMap, Metasploit, Echo mirage Mobile testing tools (e.g., MobSF, Frida ) is a plus. Good understanding on OWASP Top 10, SANS CWE Top 25, NIST standards . Good written and spoken communication skills Ability to do report walkthrough with relevant stakeholder Understanding of programming languages such as PHP, HTML, javascript, etc Education Requirements: BE/B.Tech in Computer Science or Information Science Or M.Tech in Computer Science or Information Science Certifications: CEH, CompTIA, PenTest+, GPEN, OSCP, CREST CRT preferable

FIND ON MAP

Sisa Information Security