01Overview
Cybersecurity Analyst
Location
BKC - primary, with coverage at Vashi as required
Function
Information Security / Cybersecurity Operations
Experience
25 years
About the Role
Beacon Trusteeship Limited is looking for a Cybersecurity Analyst to own hands-on security operations for the Trusteeship, RTA and Depository Participant business. This role sits below the Group CTO and is responsible for day-to-day monitoring, coordinating VAPT cycles with empanelled vendors, and critically owning remediation: not just logging findings, but directing what gets fixed, in what order, and confirming closure.
This is an individual-contributor-plus role suited to someone early in their security career who wants real ownership of an SEBI-regulated environment, running audits, firewall reviews, and compliance documentation independently, with CTO oversight rather than day-to-day supervision.
Key Responsibilities
Own VAPT lifecycle end-to-end with empanelled vendors (e.g. CERT-In empanelled firms) scoping, coordinating execution, reviewing draft findings for accuracy, and instructing IT/infra teams on remediation priority and approach
Track every VAPT and audit finding to closure using a structured remediation tracker; escalate blocked items to the CTO
Run day-to-day monitoring of perimeter firewalls, endpoint security (EDR), and SOC alerts; triage and respond to security events
Perform periodic firewall rule reviews, identify unused, overly permissive, or risky rules and drive cleanup
Support SEBI CSCRF compliance activities as a Qualified RE: audit evidence collection, documentation, and timeline tracking
Maintain and update the IT asset inventory (hardware, software) relevant to the Vashi site
Conduct basic security reviews of new and existing third-party vendors before onboarding
Lead first-response for security incidents at BIHPL; escalate high/critical incidents to the CTO immediately
Maintain the risk register for BIHPL and support periodic risk assessments
Deliver security awareness training to BIHPL staff
Liaise directly with auditors during SEBI RTA system audits and cyber audits, and with VAPT vendors during test cycles
Assist in drafting and updating security policy documentation (IS Policy, IT Policy, Incident Response Plan) in line with Group templates
Requirements
25 years in information security / IT security operations
Working knowledge of firewalls (rule review and hardening), EDR/endpoint security tools, and vulnerability management
Understanding of the VAPT process, able to read a vendor report critically and translate findings into a remediation plan, not just pass findings along
Exposure to SEBI CSCRF, ISO 27001, or similar regulatory/compliance frameworks (financial services background preferred but not mandatory)
Comfortable coordinating directly with external security vendors and auditors
Bachelor's degree in Computer Science, IT, or related field
Good to Have
Certifications: CEH, Security+, ISO 27001 Foundation, or working toward CISSP
Prior exposure to an RTA, depository participant, or other SEBI-regulated entity
Familiarity with basic cloud security concepts (Azure) and network segmentation across multi-site setups
Compensation: 500,000.00 - 700,000.00 per year
Work Location: In person .