Verified today
Associate Security Consultant
About the role
Tech Mahindra's IT security team safeguards client applications through robust GRC frameworks and secure development practices. The Associate Security Consultant leads regulatory compliance initiatives, conducts application security assessments, and integrates security controls into the SDLC. Mumbai, on-site, full-time.
What you’ll do
- Develop and manage GRC framework for regulatory compliance
- Ensure adherence to ISO 27001, PCI DSS, SOC 2, NIST standards
- Collaborate with development teams to embed security in SDLC
- Conduct application security assessments, code reviews, vulnerability scans
- Manage audits and remediation tracking for application security controls
- Deliver training on secure coding and compliance awareness
- Analyze WAF logs and risk registers
- Coordinate audit points with internal and external auditors
What you’ll bring
- 7-10 years experience
- BFSI regulatory compliance experience
- CISSP, CISA, CISM, or ISO 27001 Lead Auditor certification
- HP Fortify or Burp Suite expertise
- SAST, DAST, OSS security knowledge
Skills
Education
BE/BTech/MCA