Cybersecurity Analyst
Location
BKC - primary, with coverage at Vashi as required
Function
Information Security / Cybersecurity Operations
Experience
2–5 years
About the Role
Beacon Trusteeship Limited is looking for a Cybersecurity Analyst to own hands-on security operations for the Trusteeship, RTA and Depository Participant business. This role sits below the Group CTO and is responsible for day-to-day monitoring, coordinating VAPT cycles with empanelled vendors, and critically owning remediation: not just logging findings, but directing what gets fixed, in what order, and confirming closure.
This is an individual-contributor-plus role suited to someone early in their security career who wants real ownership of an SEBI-regulated environment, running audits, firewall reviews, and compliance documentation independently, with CTO oversight rather than day-to-day supervision.
Key Responsibilities
- Own VAPT lifecycle end-to-end with empanelled vendors (e.g. CERT-In empanelled firms) — scoping, coordinating execution, reviewing draft findings for accuracy, and instructing IT/infra teams on remediation priority and approach
- Track every VAPT and audit finding to closure using a structured remediation tracker; escalate blocked items to the CTO
- Run day-to-day monitoring of perimeter firewalls, endpoint security (EDR), and SOC alerts; triage and respond to security events
- Perform periodic firewall rule reviews, identify unused, overly permissive, or risky rules and drive cleanup
- Support SEBI CSCRF compliance activities as a Qualified RE: audit evidence collection, documentation, and timeline tracking
- Maintain and update the IT asset inventory (hardware, software) relevant to the Vashi site
- Conduct basic security reviews of new and existing third-party vendors before onboarding
- Lead first-response for security incidents at BIHPL; escalate high/critical incidents to the CTO immediately
- Maintain the risk register for BIHPL and support periodic risk assessments
- Deliver security awareness training to BIHPL staff
- Liaise directly with auditors during SEBI RTA system audits and cyber audits, and with VAPT vendors during test cycles
- Assist in drafting and updating security policy documentation (IS Policy, IT Policy, Incident Response Plan) in line with Group templates
Requirements
- 2–5 years in information security / IT security operations
- Working knowledge of firewalls (rule review and hardening), EDR/endpoint security tools, and vulnerability management
- Understanding of the VAPT process, able to read a vendor report critically and translate findings into a remediation plan, not just pass findings along
- Exposure to SEBI CSCRF, ISO 27001, or similar regulatory/compliance frameworks (financial services background preferred but not mandatory)
- Comfortable coordinating directly with external security vendors and auditors
- Bachelor's degree in Computer Science, IT, or related field
Good to Have
- Certifications: CEH, Security+, ISO 27001 Foundation, or working toward CISSP
- Prior exposure to an RTA, depository participant, or other SEBI-regulated entity
- Familiarity with basic cloud security concepts (Azure) and network segmentation across multi-site setups
Pay: ₹500,000.00 - ₹700,000.00 per year
Work Location: In person