Všeobecné informácie
Description
Job Title: Assistant Manager
Department: Information Security
About Business line/Function: Information security and BCM team are responsible for performing the security assessment of all new/existing infrastructure and application projects. Also, responsible for assessing the business continuity requirement of each team and project based on the criticality and streamline the process to achieve the requirement.
Position Purpose: The purpose of this position is to lead a high‑performing, multidisciplinary security team and shape the future of secure software delivery across the organization. Drive tangible impact through measurable security outcomes, automation, and innovation.
Responsibilities
Direct Responsibilities
- Review and interpret various application classifications and their architectures (e.g., web apps, APIs, infrastructure, server side, mainframe, WebSphere).
- Demonstrate solid knowledge of data in transit and data at rest encryption, TLS (certificates, cipher suites such as RSA and Diffie Hellman), middleware message queues, secure file transfers, and database encryption.
- Good Understanding of access control concepts, including onboarding, automated provisioning/reconciliation, and privileged access management tools (e.g., SailPoint, CyberArk).
- Good Understanding of authentication best practices and familiarity with strong authentication mechanisms such as SSO, SAML, 2FA/MFA, Arcot, RSA, etc.
- Possess a clear grasp of application security testing processes (DAST, SAST, SCA, penetration testing, VAPT) and the end-to-end workflow, even if hands on scanning experience is not required.
- Good Understanding of payment specific applications (e.g., SWIFT messages), associated encryption of payment flows, mutual authentication, and end to end encryption.
- Work closely with application/asset owners and technical teams to conduct security compliance reviews, gather functional information, and implement appropriate security controls with documented evidence.
- Produce concise findings reports and discuss results with relevant Application owners & Stakeholders.
- Demonstrated team‑management ability, preparation of management‑level reports, capability to interact with higher ups in management steering committee meetings and skilled in handling cross‑functional meetings to drive decisions and actions.
- Mentor and onboard new team members through knowledge transfer sessions and hands on shadowing during their initial period.
Contributing Responsibilities
- Extended knowledge of IT infrastructure & Network and Application (Web, Client-Server, Payment Systems) security reviews
- Provide consultation and recommendations on application security controls for the central region.
Technical & Behavioral Competencies
- Strong knowledge of application security framework and standards (OWASP TOP 10, NIST, SANS, ISO and relevant regulatory requirements)
- Strong understanding of OWASP top 10, SAST/DAST/SCA, API security, secure coding practices, threat modeling, vulnerability management, cryptography techniques, authentication techniques (SSO, SAML, MFA/2FA, etc.), secure SDLC
- Good communication skills
- Knowledge of application security controls (Access control mechanisms and Data Security)
- Should have IT audit background
- Good knowledge of IT security (defense in depth)
Specific Qualifications:
Any technical certification (CEH/ISO27001/CISM/CISA/CISSP) will be a value addition
Skills Referential (Required knowledge, skills and abilities)
Technical Skills:
- AppSec assessments (Aplication security compliance review / API Security)
- Vulnerability management and Remediation techniques
- Governance framework and Reporting
Behavioral Skills:
- Ability to collaborate / Teamwork
- Ability to deliver / Results driven
- Communication skills Oral & Written
Education Level: Bachelor degree or equivalent
Location: Bengaluru
About BNP Paribas Group:
BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.
About BNP Paribas India Solutions:
Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.
Commitment to Diversity and Inclusion
At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.