Lead Associate, Information Security

Betanxt
Betanxt

IT

Bengaluru, Karnataka, India

Posted on Sep 24, 2026

This role is being created to backfill a resigning Senior Associate, Information Security with 3.5 yrs of experience at BetaNXT, and it is being redefined with a sharper mandate. The Lead Associate / Cybersecurity Engineer will own day-to-day execution of BetaNXT's Vulnerability & Exposure Management program — the single highest-priority function in this role — while also contributing to PKI/Certificate Lifecycle Management and Data Loss Prevention (DLP) / Data Classification initiatives. This is an execution and delivery role as much as a technical one: success depends on the ability to organize, prioritize, and personally drive remediation work across engineering teams that do not report to this person.

We are looking for someone with genuine passion, ambition — someone who treats this role as a launchpad to grow into broader security engineering and program leadership responsibility, not a fixed job description.

Key Responsibilities

1. Vulnerability & Exposure Management — Primary Focus

  • Serve as the day-to-day counterpart to DXC's Vulnerability Management lead, running a recurring, evidence-based triage cadence across findings from Qualys VMDR/TruRisk, GitLab Ultimate (SDLC/dependency findings), and CyCognito (external attack surface).
  • Segment and prioritize triaged findings by business unit (Beta, Maxit, Mediant, Delta Data), applying asset criticality, exploitability signals (EPSS/KEV), and business context rather than raw severity counts alone.
  • Build remediation plans with each BU's technology and development engineering teams, and personally drive them to closure — this requires the judgment and persistence to negotiate realistic timelines and the persuasion skills to keep remediation moving with teams that have competing priorities and no reporting relationship to this role.
  • Apply project/delivery-management discipline to the remediation portfolio: maintain trackers and burn-down views, flag at-risk items early, and escalate clearly and factually to BU and technology leadership when a commitment is slipping.
  • Contribute to the ongoing evolution of BetaNXT's Risk-Based Vulnerability Management (RBVM) / Continuous Threat Exposure Management (CTEM) program, including per-BU scorecards and monthly VM governance reporting to CLO/GRC leadership.

2. PKI & Certificate Lifecycle Management

  • Support the operation and continuous improvement of enterprise PKI and Certificate Lifecycle Management (CLM) tooling (e.g., Venafi), including issuance, automated renewal, and revocation workflows.
  • Maintain an accurate certificate inventory across on-prem and cloud environments; proactively identify and remediate certificates that are expired, expiring, or improperly configured before they cause a production or client-facing incident.
  • Coordinate with DXC and internal infrastructure owners on certificate-related change work and the broader CLM ownership transition.

3. Data Loss Prevention & Data Classification

  • Support configuration, tuning, and expansion of DLP controls (e.g., Microsoft Purview) across email, endpoint, and cloud channels.
  • Assist with data classification efforts, partnering with BU and compliance stakeholders to identify, label, and appropriately protect sensitive client and company data.
  • Investigate DLP alerts and turn recurring patterns into concrete policy or control refinements that reduce noise without reducing coverage.

4. Knowledge Base & Documentation

  • As bandwidth allows, streamline and document InfoSec processes, runbooks, and SOPs — starting with VM, PKI/CLM, and DLP workflows — so institutional knowledge is captured and transferable rather than held by one person.

5. Program Support & Professional Growth

  • Participate in incident response, security architecture reviews, and audit/compliance evidence requests as needed.
  • Proactively pursue adjacent skills and stretch responsibilities (cloud security, IAM, security architecture, automation) as the program and this role mature — we are looking for someone who will outgrow the initial job description.

Must support US Eastern Timezone hours