Build and launch the GSOC from inception to full maturity
Lead 24/7 SOC operations, monitoring, threat detection & incident response
Recruit, train & manage SOC teams (Tier 1–3)
Implement & optimize SIEM, SOAR, EDR, TIP & security tool stack
Develop SOC processes, IR playbooks, SLAs, KPIs, dashboards
Conduct threat hunting, threat intelligence & major incident handling
Ensure compliance (ISO 27001, SOC 2, GDPR, DPDP, PCI, HIPAA)
Manage client communication, reporting & escalations
Drive automation, SOC maturity improvements & operational excellence
Btech, BE, Bsc CS, BCA or equivalent
8–12 years in cybersecurity with 3–5 years in SOC leadership
Hands-on SIEM experience (Splunk / QRadar / Sentinel)
Strong incident response, threat intel, threat hunting expertise
Certifications preferred: GCIH, GSOC, CISSP, CISM, CEH, Splunk Certified
Experience managing 24/7 shifts and global clients
Expert: SIEM, SOAR, EDR, IDS/IPS, Vulnerability Management
Strong: MITRE ATT&CK, NIST CSF, ISO 27001, SOC 2
Cloud security (AWS/Azure/GCP), network security, scripting (Python/PowerShell)
Leadership, communication & stakeholder management
Salary ₹15–25 LPA performance bonuses
Build a GSOC from ground up, high-impact leadership role
Advanced certification sponsorships & conference budgets
Modern GSOC facility at Lulu Twin Towers
Global exposure with multi-industry clients
Health insurance, flexible benefits & growth path toward Director/CISO roles
Manage end-to-end IT infrastructure across all locations
Administer enterprise networks: switches, routers, firewalls, VPN, ISP coordination
Maintain Windows & Linux servers, Active Directory, DNS, DHCP
Support virtualization (VMware/Hyper-V) and cloud (Microsoft 365, AWS/Azure)
Oversee endpoint management, security tools, backups & DR
Provide L1/L2 support and manage IT helpdesk
Ensure compliance with ISO 27001, SOC 2, GDPR, DPDP Act
Support GSOC infrastructure setup and security monitoring systems
Handle vendor management, licensing, documentation & IT projects
4–7 years managing IT infra for 25–50+ user organizations
Strong expertise in Windows Server, AD, enterprise networking & firewalls
Experience with Microsoft 365, VMware/Hyper-V, AWS/Azure
Linux admin, scripting (PowerShell/Bash), backup tools
Certifications (preferred): Microsoft, CCNA, CompTIA, VMware, ITIL
Salary: ₹6–12 LPA
Bonuses & certification sponsorships
Professional development budget (₹50k–75k)
Health insurance, generous leave policy
Growth path to IT Manager / Infrastructure Architect
Opportunity to build and support our state-of-the-art GSOC
Indian citizen / valid work authorization
Ready to relocate to Kochi
Available within 30–60 days
Join our IT team and gain hands-on experience building and managing enterprise infrastructure across 5 Indian locations + international operations. Be part of establishing our Global Security Operations Center (GSOC) launching April 2026!
Networks & Systems
Real-World Experience
Professional Growth
WHO WE'RE LOOKING FOR
Education: B.Tech/B.E. (CS/IT/ECE) | Diploma in Computer Engineering | MCA
Final year students or recent graduates (within 6 months)
Basic Skills:
Bonus: CompTIA A+/Network+, CCNA (or pursuing), relevant online certifications
You Should Be:
· Eager to learn and hands-on with technology
· Detail-oriented and good at problem-solving
· Team player with positive attitude
· Available for minimum 3-month commitment
· Can work from office (hands-on infrastructure work)
💎 WHY JOIN US?
Real Infrastructure, Not Simulations - Work on actual production systems
GSOC Project Exposure - Unique opportunity to build security operations center
Multi-Location Operations - Support enterprise infrastructure across India
Career Pathway - High performers receive full-time employment offers
Industry Recognition - Certificate from CERT-In empanelled organization
Mentorship - Learn from certified professionals (CISA, CISM, ISO Lead Auditor, CDPO)
Competitive Stipend - ₹8,000-12,000/month based on skills
Modern Tech Stack - Enterprise networking, cloud, virtualization, security tools
ABOUT US
John & Smith Solutions LLP operates as neXavault, providing cybersecurity consulting (VAPT, SOC Services, ISO Certifications, Compliance Advisory) and technology solutions.
Presence: Kozhikode (HQ) | Kochi (GSOC) | Trivandrum | Bangalore | Noida | UAE | UK
APPLY NOW
Email: hr@johnandsmithglobal.com
Subject: Systems & Network Engineer Intern | [Your Name]
Send:
Deadline: Rolling basis - Apply early!
QUICK SELECTION PROCESS
Application Screening → Phone Interview → Technical Test → Final Interview → Offer
Timeline: 1-2 weeks
Launch Your IT Career | Build Real Infrastructure | Join CERT-In Empanelled Firm
Equal opportunity employer - All qualified candidates welcome
#ITInternship #NetworkEngineer #SystemsAdmin #KochiJobs #TechCareers
Cybersecurity Intern – Nexavault®
Nexavault is seeking motivated and talented individuals for our cybersecurity internship program. This comprehensive, year-long internship offers hands-on experience in the field of cybersecurity.
Responsibilities:
• Assist in implementing and maintaining cybersecurity measures
• Participate in vulnerability assessments and penetration testing
• Monitor security systems and respond to potential threats
• Contribute to the development of security policies and procedures
• Support incident response and forensic analysis activities
• Assist in conducting internal audits and risk assessments
• Collaborate with team members on various cybersecurity projects
Requirements:
• Recently completed a degree in Computer Science, Information Technology, Cybersecurity, or a related field
• Candidates having certification in Cyber Security from EC-Council, CompTIA or equivalent
• Strong interest in cybersecurity and information security management
• Basic understanding of network protocols, encryption, and security concepts
• Familiarity with common cybersecurity tools and technologies
• Excellent problem-solving and analytical skills
• Strong written and verbal communication abilities
• Ability to work both independently and as part of a team
What We Offer:
• Hands-on experience in a real-world cybersecurity environment
• Mentorship from experienced cybersecurity professionals
• Competitive stipend within the range of 8000 to 10000 per month.
John and Smith is committed to fostering a diverse and inclusive workplace. We encourage applications from candidates of all backgrounds.
Responsibilities:
Perform source code reviews (manual + automated) across diverse technologies.
Utilize tools like Checkmarx, SonarQube, Fortify, or Veracode for SAST analysis.
Identify, prioritize, and report security vulnerabilities with actionable remediation guidance.
Collaborate with developers, architects, and security teams to improve secure coding practices.
Contribute to Secure SDLC and DevSecOps initiatives.
Stay updated on OWASP Top 10, SANS25, CWE, and emerging threats.
Requirements:
5-6 years of experience in application security & source code review.
Proficiency in multiple programming languages (Java, .NET, Python, JavaScript, C/C++).
Strong hands-on experience with Checkmarx, SonarQube.
Good knowledge of SAST, DAST, vulnerability assessment, penetration testing.
Relevant certifications (CEH, OSCP, SANS25, LPT, CEPT, ISTQB Foundation or Advanced) preferred.
Skills:
Source Code Review
Multiple Languages
Checkmarx
SonarQube
Certifications (CEH/OSCP/SANS25/LPT/CEPT)
Industry Type: IT / Cyber Security
Department: Engineering – Software and QA
Role Category: Quality Assurance and Testing
Education:
UG: B.Tech/B.E. in Any Specialization
PG: Any Postgraduate
Key Skills:
Code Review
Python
OSCP
CEH
Vulnerability Assessment
Programming Languages
JavaScript
DAST
Java Application Security
Penetration Testing
SAST
DevSecOps
SSDLC Programming
neXavault, the cybersecurity arm of John & Smith Solutions, is a CERT-In empanelled Information Security Auditing Organization. With our expanding presence across India and international markets, we're the trusted partner for organizations seeking robust security compliance and governance frameworks. Our 100% certification success rate speaks to our expertise in navigating complex regulatory landscapes
We're seeking a Senior Compliance & GRC Consultant to lead our rapidly growing compliance practice. You'll guide enterprise clients through their security certification journeys, from initial gap assessments to successful certification audits. With our new CERT-In empanelment opening doors across PAN-India markets, this role offers exceptional growth potential.
Key Responsibilities
Lead ISO 27001, ISO 27701, and ISO 20000-1 implementation projects from initiation to certification
Conduct comprehensive gap assessments and maturity evaluations
Design and implement Information Security Management Systems (ISMS)
Perform internal audits and prepare organizations for certification audits
Develop information security policies, procedures, and controls
Guide clients through SOC 2 Type I & II compliance journeys
Ensure compliance with Indian regulations (CERT-In directives, RBI guidelines, DPDP Act)
Conduct risk assessments using ISO 31000 and NIST frameworks
Lead business continuity and disaster recovery planning initiatives
Manage multi-framework compliance programs for enterprise clients
Train client teams on security awareness and compliance requirements
Essential Requirements
Experience: 6-10 years in information security compliance and GRC
Certifications (Mandatory):
ISO 27001 Lead Auditor (IRCA/PECB/Exemplar certified)
ISO 27001 Lead Implementer
Certifications (Preferred):
CISA, CRISC, or CGRC
ISO 22301, ISO 27701, or ISO 27017/27018 credentials
Domain Expertise:
Proven track record of successful ISO 27001 implementations (minimum 5 projects)
Deep understanding of Indian regulatory landscape
Experience with risk assessment methodologies
Knowledge of data privacy regulations (DPDP, GDPR)
Skills:
Excellent stakeholder management and communication
Strong documentation and technical writing abilities
Project management capabilities
Ability to translate technical risks into business language
Preferred Qualifications
CERT-In empanelment experience
Banking sector compliance (RBI guidelines, PCI DSS)
Healthcare compliance (HIPAA, ABDM)
Experience with GRC tools (MetricStream, ServiceNow, Archer)
Cloud compliance frameworks (CSA CCM, ISO 27017)
Certified Data Privacy Officer (CDPO) or equivalent
What We Offer
Competitive Package
High-Value Projects: Lead compliance engagements worth ₹28-50 lakhs
CERT-In Advantage: Leverage our empanelment for prestigious government projects
Professional Growth: Clear path to Practice Head role
Certification Support: Funding for advanced certifications
Diverse Portfolio: Work across banking, healthcare, technology, and government sectors
Thought Leadership: Opportunity to develop frameworks and methodologies
Location
Primary: Kochi/Kozhikode, Kerala (Remote work available with periodic travel for client audits)
How to Apply
Send your detailed CV along with:
List of ISO 27001 implementations you've led (with outcomes)
Brief case study of your most complex compliance project
Sample ISMS document you've developed (sanitized)
neXavault, the cybersecurity arm of John & Smith Solutions, is a CERT-In and CREST approved organization providing comprehensive security solutions across India and internationally. With our recent CERT-In empanelment as an Information Security Auditing Organization, we're positioned for exponential growth in government and enterprise segments. Our team delivers specialized cybersecurity services from offices in Kozhikode, Kochi, Trivandrum, Mumbai, Hyderabad, Noida, Bangalore, Middle East, and UK.
We're seeking a dynamic Technical Proposal Manager to spearhead our tender management and proposal development initiatives. With our CERT-In empanelment opening doors to high value government contracts and our expansion into PAN-India markets, this role is critical to capturing strategic opportunities. You'll be at the forefront of our business development, converting our technical expertise into winning proposals for projects.
Key Responsibilities
Tender & GeM Portal Management
Manage end-to-end tender lifecycle on GeM (Government e-Marketplace) portal
Monitor and identify relevant tenders from GeM, CPP Portal, and state government portals
Handle vendor registration, documentation, and compliance requirements
Manage bid submissions, clarifications, and post-tender negotiations
Maintain tender tracking database and submission calendar
Ensure timely EMD/tender fee submissions and documentation
Technical Proposal Development
Write compelling technical proposals for cybersecurity services including:
Vulnerability Assessment & Penetration Testing (VAPT)
ISO 27001 implementation and auditing
Security Operations Center (SOC) setup
Incident response and forensics services
Compliance audits (CERT-In, RBI, IRDAI guidelines)
Translate complex technical capabilities into clear value propositions
Develop case studies, project references, and credential presentations
Create solution architectures and implementation methodologies
Prepare competitive pricing strategies and commercial proposals
Stakeholder Coordination
Collaborate with technical teams to gather solution requirements
Coordinate with finance for pricing and commercial terms
Liaise with legal for contract reviews and compliance
Work with delivery teams for project timelines and resource planning
Interface with partners and OEMs for joint proposals
Essential Requirements
Experience: 4-7 years in proposal writing and tender management, preferably in IT/Cybersecurity domain
GeM Expertise: Hands-on experience with GeM portal operations, bidding processes, and vendor management
Technical Writing: Exceptional writing skills with ability to articulate complex technical solutions
Domain Knowledge:
Understanding of cybersecurity services and solutions
Familiarity with government procurement processes
Knowledge of tender documentation (RFP, RFQ, EOI analysis)
Skills:
Proficiency in MS Office suite, especially advanced Word and Excel
Experience with proposal management tools
Strong attention to detail and deadline management
Excellent communication and coordination abilities
Preferred Qualifications
Experience with CERT-In empanelled organizations
Knowledge of cybersecurity frameworks (ISO 27001, NIST, CIS)
Understanding of Indian regulatory landscape (IT Act, DPDP Act)
Experience with international tenders and proposals
Certification in proposal writing or business development
Track record of winning high-value tenders
What Makes You Successful
Proven ability to win government tenders with 30%+ success rate
Experience managing multiple proposals simultaneously (5-10 active bids)
Strategic thinking to identify and pursue right opportunities
Ability to work under pressure and meet strict deadlines
Self-motivated with strong ownership mindset
What We Offer
Competitive Package + performance incentives on successful bids
Growth Impact: Direct contribution to company's expansion strategy
Diverse Exposure: Work on tenders across banking, government, PSU, and enterprise sectors
Success Bonus: Attractive incentives for winning high-value contracts
Skill Development: Training on cybersecurity domains and advanced proposal techniques
Career Growth: Clear progression path to Business Development leadership roles
Strategic Role: Direct interaction with senior management on growth initiatives
Location
Primary: Kochi/Kozhikode, Kerala
(Office-based role with occasional travel for pre-bid meetings)
How to Apply
Send your detailed CV along with:
List of major tenders won (with contract values)
Sample technical proposal section you've written (2-3 pages, sanitized)
Your GeM portal experience and success stories
Subject Line: Technical Proposal Manager – “Your Name”
Why This Role Matters
As our Technical Proposal Manager, you'll be instrumental in leveraging our CERT-In empanelment to capture government and enterprise opportunities. Your work will directly impact our growth, making you a key player in neXavault's expansion story.
Join us in building India's most trusted cybersecurity consulting firm. Your proposals will shape how organizations protect their critical assets and data.
Application Deadline: Immediate requirement - Apply now!
neXavault, the cybersecurity arm of John & Smith Solutions, is a CERT-In and CREST approved organization leading India's offensive security landscape. With offices across India (Kozhikode, Kochi, Trivandrum, Bangalore, Hydrabad, Mumbai, Noida) and international presence in Middle East and UK, we're trusted by digital banking platforms, fintech innovators, and critical infrastructure providers for our advanced security testing capabilities.
We're seeking a highly skilled Senior Penetration Testing Specialist to lead our offensive security practice. You'll work on challenging engagements including critical infrastructure. This is a hands on technical role for someone passionate about breaking systems and finding vulnerabilities before malicious actors do.
Key Responsibilities
Execute advanced penetration testing across web applications, mobile apps, APIs, thick clients, and network infrastructure
Perform in-depth source code reviews for Java, .NET, Python, Node.js, and mobile applications
Conduct red team operations and adversary simulation exercises
Develop custom exploits and proof of concept code
Lead cloud security assessments (AWS, Azure, GCP)
Perform IoT and OT security testing for specialized clients
Mentor junior penetration testers and develop team capabilities
Create comprehensive technical reports with actionable remediation guidance
Research emerging attack vectors and developls
new testing methodologies
Essential Requirements
Experience: 6-10 years of hands-on penetration testing experience
Certifications: At least two from - OSCP, OSCE, OSWP, GPEN, GWAPT, GMOB, CRTP
Technical Mastery:
Expert-level proficiency with Burp Suite Pro, Metasploit, Cobalt Strike
Strong exploitation skills across Windows, Linux, and mobile platforms
Proficient in Python, Bash, PowerShell for tool development
Deep understanding of OWASP Top 10, SANS Top 25, MITRE ATT&CK
Experience with container and Kubernetes security
Specialized Skills:
Web application exploitation (SQLi, XXE, SSRF, Deserialization, etc.)
Mobile application security testing (iOS/Android)
Active Directory exploitation and lateral movement
Cloud-native application testing
Preferred Qualifications
CREST certification (CRT, CCT, CPSA)
Published CVEs or acknowledged bug bounties
Security research publications or conference presentations
Experience with automotive, IoT, or OT security testing
Exploit development and reverse engineering skills
DevSecOps and CI/CD pipeline security
What We Offer
Competitive Package
Cutting-edge Projects: Work on high-stakes VAPT engagements for banking and fintech clients
Tool Access: Licensed versions of premium security tools and cloud labs
Research Time: Dedicated time for security research and tool development
Continuous Learning: Funding for advanced certifications and training
Conference Participation: Support for attending and speaking at security conferences
Global Exposure: International client projects in Middle East, US and UK markets
Location
Primary: Kochi/Kozhikode, Kerala
How to Apply
Send your detailed CV along with:
Your HackTheBox/TryHackMe profile or CTF achievements
Brief write-up of your most interesting vulnerability discovery
GitHub link to any security tools you've developed
Key Responsibilities:
Create well-researched and engaging contents for the website, blogs, and social media platforms
Write content related to software development, cloud computing, cybersecurity, AI/ML, DevOps, SaaS products, and other IT solutions.
Collaborate with technical teams (developers, SEO Specialist) to ensure content accuracy and clarity.
Simplify complex technical concepts into easily understandable content for diverse audiences.
Produce SEO-optimized content using IT-industry keywords and current trends.
Develop scripts for product demos, explainer videos, and social media campaigns when needed.
Maintain consistency in tone, technical depth, and branding across all deliverables.
Conduct industry research to produce insightful and up-to-date content.
Proofread, edit, and ensure adherence to content guidelines and deadlines.
Skills & Qualifications
Bachelor’s degree in English, Computer Science, IT, Journalism, Communications, or related field.
3+ years of experience writing for IT or technology companies.
Strong understanding of IT concepts such as cloud, networking, cybersecurity, databases, APIs, SDLC, automation, AI, software products, etc.
Excellent writing, editing, and proofreading skills.
Ability to work closely with technical teams and understand product functionality.
Strong research skills and attention to detail.
Ability to manage multiple projects and meet deadlines.
Benefits:
Health insurance
Paid sick time
Provident Fund
Work from home
Work Location: In person