Company Description
ByoSync OS Layer is an advanced biometric authentication platform that replaces traditional OTPs and passwords with secure real-time facial verification. Tailored for India's dynamic digital space, the platform operates seamlessly on any smartphone using encrypted tokens, ensuring no biometric data is stored. ByoSync enables secure payments, identity access, and digital services, all with a single scan. It delivers a fast, private, and hardware-free experience, ensuring cutting-edge security for users.
Role Description
This is an internship position for a Cybersecurity/AppSec Engineer, with a hybrid work arrangement at our New Delhi office, allowing for partial remote work. The responsibilities include identifying and mitigating security vulnerabilities, conducting code reviews, analyzing security threats, and implementing security measures. The engineer will collaborate with the development team to ensure application security, test various security systems, and adhere to industry best practices.
This is a 2-month probation (contract-to-hire) role for a Cybersecurity / AppSec Engineer.
Converts to full-time upon successful delivery.
You will design and enforce security controls across mobile apps, backend APIs, and ML pipelines.
What You'll Work On (RBI / NPCI / Fintech Compliant)
- Perform end-to-end threat modeling across mobile apps, backend APIs, identity flows, and device binding, aligned with RBI cyber-security guidelines
- Design and enforce secure key management (HSM / KMS where applicable), encryption at rest & in transit, and secure token lifecycle management (generation, rotation, revocation)
- Lead application security hardening for Android and backend services in line with OWASP MASVS / ASVS and fintech best practices
- Implement secure authentication and authorization controls suitable for high-risk financial transactions (step-up auth, replay protection, rate limiting)
- Integrate security checks into CI/CD (SAST, dependency scanning, secrets detection) with release gating
- Define and implement centralized logging, audit trails, and access logs required for regulatory audits (RBI / NPCI expectations)
- Prepare and manage VAPT (Vulnerability Assessment & Penetration Testing) scope, remediation tracking, and audit evidence documentation
- Create and maintain incident response, breach notification, and escalation playbooks aligned with Indian fintech compliance norms
- Support regulatory readiness for fintech partners, including security questionnaires, due-diligence reviews, and bank audits
Qualifications
- Strong understanding of application security fundamentals for mobile and backend systems
- Hands-on experience securing fintech, payments, or BFSI applications
- Solid knowledge of cryptography concepts, secure key handling, and modern authentication flows
- Working familiarity with OWASP MASVS / ASVS, mobile security testing, and API security
- Experience operating in regulated environments (RBI / NPCI / bank security reviews) is highly preferred
- Ability to produce clear security documentation (policies, controls, risk registers, audit artifacts)