Posted By

user_img

Paramjeet Singh

Lead TA Partner at PhonePe

Last Login: 01 February 2022

Job Views:  
144
Applications:  27
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

1337866

PhonePe - Risk Analyst - Security Engineering

6 - 10 Years.Bangalore
Posted 10 months ago
Posted 10 months ago

About PhonePe :


- PhonePe is Indias leading digital payments platform with over 400 million+ registered users. Using PhonePe, users can send and receive money, recharge mobile, DTH, data cards, pay at stores, make utility payments, buy gold, and make investments. PhonePe went live for customers in August 2016 and was the first non-banking UPI app and offered money transfer to individuals and merchants, recharges and bill payments to begin with. In 2017, PhonePe forayed into financial services with the launch of digital gold, providing users with a safe and convenient option to buy 24-karat gold securely on its platform. PhonePe has since launched Mutual Funds and Insurance products like tax-saving funds, liquid funds, international travel insurance, Corona Care, a dedicated insurance product for the COVID-19 pandemic among others.


- PhonePe launched its Switch platform in 2018, and today its customers can place orders on over 300 apps including Ola, Myntra, IRCTC, Goibibo, RedBus, Oyo etc. directly from within the PhonePe mobile app. PhonePe is accepted at over 18 million merchant outlets across 500 cities nationally. Culture At PhonePe, we take extra care to make sure you give your best at work, Everyday! And creating the right environment for you is just one of the things we do. We empower people and trust them to do the right thing. Here, you own your work from start to finish, right from day one. Being enthusiastic about tech is a big part of being at PhonePe.


- If you like building technology that impacts millions, ideating with some of the best minds in the country and executing on your dreams with purpose and speed, join us! PhonePe is the leading payments app in India and we are looking for people who are experts in Application Security. You will be responsible for security assessments and penetration testing of application and merchant integrations as well as security research and development of security tools, processes and testing methodologies.


Desired Qualifications And Skills Set - We are seeking a skilled and motivated Risk Analyst & Vulnerability Management professional to join our Product Security team. The ideal candidate will be critical in assessing and mitigating security risks associated with our mobile and web applications. You will be responsible for managing Vulnerability Management Lifecycle through risk analysis, vulnerability prioritisation, and working collaboratively with development teams to implement effective mitigation strategies and maintain the overall SLA.


Key Responsibilities: Risk Assessment: Perform comprehensive risk assessments for our mobile & web applications, prioritising vulnerabilities and security risks and driving effective mitigation/remediation strategies. Evaluate risks based on their potential impact, likelihood, and business context, and provide actionable and time-bound recommendations for mitigation.


- Vulnerability Management: Maintain Vulnerability Management Lifecycle as per organisation standards with reference to industry standards and practices. Analyse scan results, prioritise vulnerabilities based on risk and collaborate with development teams to coordinate timely remediation efforts. Mitigation Strategies: Collaborate closely with development teams to define and implement effective mitigation strategies for identified vulnerabilities.


- Assist in the design and implementation of secure coding practices and application security controls. Security Awareness: Provide guidance and training to development teams on risk assessment methodologies, vulnerability management best practices, and secure coding principles. Promote a culture of security awareness and proactive risk management. Reporting and Documentation: Maintain detailed records of risk assessments, vulnerability assessments, and mitigation efforts. Generate clear and concise reports and documentation for stakeholders, including management, development teams, and auditors.


Collaboration: Work collaboratively with cross-functional teams, including developers, quality assurance engineers, and IT personnel, to ensure that security considerations are integrated throughout the software development lifecycle. Continuous Improvement: Stay informed about emerging security threats, vulnerabilities, and industry trends. Identify opportunities to enhance vulnerability management processes and risk assessment methodologies.


Qualifications: Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience). Proven experience in risk analysis, vulnerability management, and application security, with a focus on identifying and mitigating vulnerabilities in mobile & web applications. Familiarity with vulnerability scanning tools, penetration testing methodologies, and risk assessment frameworks.


- Strong understanding of application security principles, secure coding practices, and common software vulnerabilities (e.g., OWASP Top Ten). Excellent analytical skills, with the ability to assess risks and prioritise based on potential impact and likelihood. Effective communication skills, including the ability to convey technical concepts to technical and non-technical stakeholders.


- Familiarity with regulatory compliance standards (e.g., GDPR, HIPAA) and industry security frameworks (e.g., NIST, ISO 27001) is a plus. Relevant certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA) are advantageous. Self-motivated and capable of working independently, as well as collaboratively within a team environment. Why Join Us: Contribute to the enhancement of our application security posture and play a key role in identifying and mitigating security risks.


- Work in a dynamic and collaborative environment alongside skilled professionals dedicated to improving security practices. Opportunities for professional growth and skill development through training and hands-on experience. Competitive compensation package, comprehensive benefits, and potential for career advancement.

Didn’t find the job appropriate? Report this Job

Posted By

user_img

Paramjeet Singh

Lead TA Partner at PhonePe

Last Login: 01 February 2022

Job Views:  
144
Applications:  27
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

1337866

UPSKILL YOURSELF

My Learning Centre

Explore CoursesArrow