IOB Recruitment 2026: 20 Cyber Security and Information Security Officer Posts, Apply by 15 September

Indian Overseas Bank is hiring 20 information security, IS audit and cyber security officers among 291 total posts. Registration runs 29 August to 15 September 2026. Notably, AI and LLM security testing is listed as a qualifying experience domain. Full eligibility, certifications, fees and how to apply.
Indian Overseas Bank has opened applications for 291 officer posts, and 20 of them are dedicated information security and cyber security roles. The window is short: online registration runs from 29 August to 15 September 2026. What makes this notification worth a close read is not the headline count but the job description. Alongside the usual VAPT and SOC work, IOB has written AI and LLM security testing into the required experience for its information security officers, which is an unusual thing to see in a public sector bank recruitment advertisement.
Primary source: Indian Overseas Bank, Advt. No. HRDD/RECT/04/2026-27, dated 28.08.2026 (PDF, 35 pages)
On this page
The 20 security posts
These are the five post codes that are security roles in the information security sense. Scale II is Middle Management Grade Scale II (Manager), Scale III is MMGS III (Senior Manager).
| Code | Post | Grade | Vacancies | Age | Minimum experience |
|---|---|---|---|---|---|
| 03 | Manager, Information Security | MMGS II | 5 | 22 to 32 | 2 years |
| 04 | Manager, IS Audit | MMGS II | 5 | 22 to 32 | 2 years |
| 06 | Senior Manager, Information Security | MMGS III | 3 | 25 to 35 | 5 years |
| 07 | Senior Manager, IS Audit | MMGS III | 2 | 25 to 35 | 5 years |
| 10 | Senior Manager, Cyber Security Administrator | MMGS III | 5 | 25 to 35 | 5 years |
One clarification worth making, because the post name misleads. Post code 14, Assistant Manager (Security), with 25 vacancies, is a physical security role. It is open to retired Junior Commissioned Officers, paramilitary personnel of Inspector rank equivalent, and police officers. It is not a cyber security post, so it is excluded from the count of 20 above.
If you are interested in the adjacent technology roles rather than security specifically, the same notification carries Manager (IT) with 65 vacancies, Senior Manager (IT) with 10, Senior Manager (Database Administrator) with 10, and Senior Manager (Network Administrator) with 5.
What the bank actually wants
The two families of security post ask for quite different things, and applying to the wrong one is an easy mistake.
Information Security (post codes 03 and 06) is an offensive and application security profile. The bank asks for experience in at least three of the following domains:
- Web application security testing
- Mobile application security testing (Android and iOS)
- API security assessment
- Source code review (SAST)
- Dynamic application security testing (DAST)
- AI and LLM security testing
- Red team activities
That sixth item is the notable one. A public sector bank listing AI and LLM security testing as a qualifying domain, on equal footing with SAST and red teaming, is a signal about where bank security work is heading. If you have done prompt injection, model extraction or agent sandbox testing and assumed it was too niche for a PSU application, this notification says otherwise.
Cyber Security Administrator (post code 10) is a defensive and operations profile. It asks for experience in at least two of:
- Forensic analysis, incident response and management
- SIEM and XDR
- Web application and API security
- IAM, Active Directory and PAM
- AI security
- Network security
IS Audit (post codes 04 and 07) takes a different route in. You can qualify either through information security, IS audit or cyber security audit experience in banking and BFSI, or through IT experience in designing and developing banking applications following secure by design principles. That second path makes the audit roles reachable for application developers who have not held a formal security title.
Across the security posts, experience in banking, financial services, insurance, FinTech, IT or other regulated sectors is stated as preferred.
Certifications that count
Certifications are listed as a preference rather than a hard requirement, so a strong profile without them is still worth submitting. For the information security posts the bank names GIAC, EJPT, EWPT, CISSP, GIAC GPEN, GIAC GWAPT, OSWE, OSCP, OSWA, CASE, CMWAPT, OSEP, CRTP, GXPN, BSCP, eWPTX and C|PENT.
For the Cyber Security Administrator post the preferred list is CISSP, OSCP, CCNP, CCNP Security, CCIE, CCSP, CHFI, OSAI, and vendor certifications in SIEM, UEBA, SOAR, XDR and WAF technologies.
Eligibility and age
All eligibility, including age, qualifications and post qualification experience, is computed as on 1 August 2026, and certification courses must be valid as on that date.
The educational requirement for every security post is a B.E. or B.Tech, or an M.E. or M.Tech, in Computer Science, Information Technology, Electronics and Communication, Cyber Security or Information Security. The IS Audit posts also accept MCA.
Upper age relaxation follows government norms, including five years for SC and ST candidates. Selection is by online examination followed by an interview. Meeting the eligibility bar does not by itself guarantee a call for either stage, since the bank shortlists.
How to apply, fees and deadline
- Apply online only, through www.iob.bank.in. No other mode of application is accepted.
- Register between 29 August and 15 September 2026. Fee payment closes on the same date.
- Pay the fee: ₹1,000 inclusive of GST for all candidates including OBC and EWS, or ₹175 intimation charges for SC, ST and PwBD candidates. Payment is by debit card, credit card, internet banking, BHIM or UPI.
- Upload the extras. The application requires a left thumb impression and a handwritten declaration, which catches people out at the last minute.
- Save the printed form and e-receipt. The fee is non-refundable and applications cannot be withdrawn once submitted.
The bank notes that vacancy numbers are provisional and may change according to actual requirements, and that selected candidates may be posted anywhere in India.
FAQs
How many cyber security posts are there in the IOB 2026 recruitment?
Twenty, across five post codes: Manager Information Security (5), Manager IS Audit (5), Senior Manager Information Security (3), Senior Manager IS Audit (2) and Senior Manager Cyber Security Administrator (5).
What is the last date to apply?
15 September 2026, for both registration and fee payment. Registration opened on 29 August 2026.
Do I need a certification like OSCP or CISSP?
No. Certifications are stated as a preference, not a mandatory requirement. Domain experience is what the eligibility criteria actually test.
Can I apply with an MCA instead of a B.Tech?
For the IS Audit posts, yes. The pure Information Security and Cyber Security Administrator posts specify B.E., B.Tech, M.E. or M.Tech in the listed disciplines.
Is Assistant Manager (Security) a cyber security job?
No. It is a physical security role reserved for retired JCOs, paramilitary personnel and police officers.
What is the selection process?
An online examination, followed by an interview for those who qualify.
Source
- Indian Overseas Bank, Recruitment of Generalist / Specialist Officers in Various Scales 2026-27, Advt. No. HRDD/RECT/04/2026-27, dated 28 August 2026.
For the full list of all 291 posts across 14 roles, including the reservation split and application steps, see our complete guide to the Indian Overseas Bank Recruitment 2026: 291 Generalist and Specialist Officer Posts.