Skip to main content
← Back to search
IT

Information Security Engineer

IMC Trading

Salary not disclosed

Mumbai, IndiaFull-timeOn-siteIntermediate

Applying takes a free account: you'll come right back to this job to finish with your profile.

Need a reasonable accommodation to apply or interview? Contact us.

JobMinglr uses automated technology to recommend jobs based on profile information and job preferences. Match Score does not determine eligibility for a position, prevent a user from viewing or applying to a job, or make hiring decisions on behalf of an employer.

Description

The Information Security team at IMC Trading is responsible for protecting IMC's intellectual property, IT infrastructure and business operations against external and internal threats. We work closely with technology, risk, compliance, internal audit and business leaders to reduce cyber risk to acceptable levels.

We are looking for an Information Security Engineer to help grow and mature our Security Operations Centre, which runs on EDR, SIEM, SOAR, CSPM, IAM, firewalls, NIDS/NIPS and a range of other security controls. Alongside SOC work, you will play a central role in supporting IMC's regulatory obligations in India, preparing evidence and coordinating the cyber and systems audits that come with operating in this market.

We offer an environment that lets you broaden and deepen your information security knowledge, with access to advanced security technology, frequent training and a culture of knowledge sharing. As you gain experience with our existing SOC technology and processes, you will be given considerable freedom to mature the function through your own initiatives.

 

Your Core Responsibilities: 

  • Analyse security logs, alerts and reported events, and respond to or assist with the remediation of incidents.

  • Hunt for potential compromise across the infrastructure using a range of threat intelligence sources.

  • Report discovered vulnerabilities to technology owners and recommend remediation steps.

  • Support and improve technical security controls.

  • Leverage automation and orchestration to remove repetitive manual work.

  • Apply AI-assisted tooling to alert triage, event summarisation and investigation workflows, with a pragmatic view of its limitations.

  • Develop reporting that measures the effectiveness of security controls.

  • Develop and improve incident response playbooks.

  • Support regulatory and assurance audits: prepare evidence, coordinate with auditors and track observations through to closure.

 

Your Skills and Experience: 

  • Strong analytical and problem-solving skills.

  • A self-starter with a genuine passion for cybersecurity.

  • Previous SOC experience, and/or 3+ years of hands-on experience in an enterprise IT environment managing endpoints and applications on-premises or in the cloud.

  • Exposure to security controls such as identity and access management, vulnerability management, and endpoint detection and response.

  • Working knowledge of — or a strong willingness to learn — the Indian regulatory cybersecurity landscape: SEBI CSCRF, exchange circulars (NSE/BSE/MCX) and CERT-In directions, along with familiarity with ISO 27001 and the NIST CSF on which CSCRF is modelled.

  • Experience supporting audits (cyber audit, systems audit, VAPT, ISO or SOC 2 assessments) — evidence preparation, auditor coordination and observation remediation — is a strong plus.

  • Automation using basic coding skills or low-code / no-code tools.

  • Awareness of AI and machine learning applications in security operations is a plus; hands-on experience with AI-assisted security tooling or LLM-based workflows is highly regarded.

  • Understanding of common attack techniques and frameworks such as MITRE ATT&CK.

  • Strong documentation and communication skills, with the ability to translate technical findings into audit-ready evidence and regulator-facing reports.

  • Relevant tertiary and/or security qualifications are a plus — for example a Bachelor's degree in information systems or computer science, CompTIA Security+, Certified in Cybersecurity (CC), CEH, or ISO 27001 Lead Auditor / Lead Implementer. If you don't have them yet, you will be supported to pursue certifications on the job.

About Us

IMC is a research-driven trading firm where quantitative modeling, machine learning, and engineering shape how modern markets are traded. A stabilizing force in markets since 1989, we provide liquidity across trading venues, delivering the best outcome in value and risk management to investors. Using our own technology and capital, we build proprietary systems and algorithms that operate across global markets. Our researchers, traders, and engineers work as a collective, combining rapid experimentation, advanced infrastructure, and real-time feedback to turn insight into execution and execution into advantage.

 

How this employer is doing

solid

  • Hiring Mentioned

Pay for this role

The employer didn't post a pay range for this role. That usually means pay is set in negotiation, which favors whoever arrives with numbers. Check ranges on comparable Information Security Engineer postings in Mumbai, and analyze any offer before you accept it.

How JobMinglr reads this job

Every listing here is scored against your profile before you apply: skills overlap, experience level, location and work arrangement, each weighted and explained. You see the score and the reasons, not just a list. How the matching works.