Sr Security Analyst

Cerebraix Technologies
Posted on

Experience
9 - 14 yrs
Job Location
Sahibzada Ajit Singh Nagar, India
Vacancy
1
Designation
Senior Security Analyst
Job Type
Not specified

Job Description

Project Highlights:

  • Prestigious Client / Project: This project plays a key role in strengthening enterprise-wide security posture through end-to-end risk management, control validation, compliance programs, vendor risk assurance and continuous improvement of information security standards.
  • Revolutionizing Technologies: The initiative leverages modern security frameworks & advanced GRC technologies (NIST, SOC2, PCI, ISO 27001, COBIT, ITIL) to enable scalable risk mitigation strategies, data-driven decisioning, and future-ready compliance maturity across the organization.
  • Agile Development: The delivery follows Agile development methodology with iterative execution, stakeholder collaboration, periodic committee reviews, and continuous feedback-driven enhancements to security controls, ensuring progressive improvements and operational resilience throughout the lifecycle.

Roles and Responsibilities:

  1. In these roles, you are part analyst, engineer, and advisor. You can ramp up quickly into a solid, productive member of the Security Team
  2. You are organized and have the ability to innovate and automate as we continually improve our processes and tools - you may own process areas, projects, or technologies for governance, risk, and compliance purposes.
  3. You create and maintain relationships with business and technical experts through the company who provide expertise in security requirements and solution management.
  4. Ensure compliance with laws, regulations, industry standards, and compliance programs (e.g., SOC2, PCI, ISO 27001, NIST 800-X).
  5. Create processes to support effective risk identification, evaluation, communication and remediation.
  6. Participate in Risk Management Committee meetings
  7. Work with risk owners to develop plans of action to reduce or mitigate risks
  8. Analyze security controls for the effectiveness of design by evaluation of control documentation and process
  9. Analyze security controls for operational effectiveness by evaluation of control evidence
  10. Contribute to corporate information risk management strategy, policies, standards, and tactical plans
  11. Operate and maintain vendor security risk management procedures to evaluate and document vendor and supply chain risks
  12. Contribute to a comprehensive internal security audit program that validates existing security controls
  13. Contribute to the company-wide security awareness program and compliance training
  14. Coordinate annual enterprise risk assessment and PCI assessment activities
  15. Work closely with internal and external auditors, regulators, and examiners, including coordination and compilation of technology documentation requests, reports, and assurance letters to ensure security compliance
  16. Maintain the Risk Register and support processes to define and measure risks, then plan risk responses with company leadership

Requirements:

  1. Bachelor s degree in technology or business-related field (BSc or BBA preferred).
  2. 9 years overall experience in Information Security, Risk Management, or IT audit.
  3. 5 years of hands-on experience supporting one of more of the following programs:
  4. Risk Management
  5. Vendor Risk Management
  6. Security Audits and Compliance
  7. Vulnerability Management
  8. Understanding of controls and risks sufficient to identify and evaluate control effectiveness and identify gaps between risks and controls.
  9. Working knowledge of business and risk assessment methodologies/ mitigation strategies using industry standards (e.g., COBIT, ITIL, ISO 27001:2013, NIST,OWASP, etc.)
  10. Experience working with asset management systems and databases
  11. Demonstrable conceptual, analytical, and innovative problem-solving and evaluative skills
  12. Very high attention to detail, with strong skills in managing/presenting data and information.
  13. Very strong skills in documentation, including policies, standards, processes, and procedures.
  14. Ability to work independently and productively without constant supervision
  15. Critical thinking and analytical ability
  16. Excellent verbal and written communication skills
  17. Certification such as SANS GIAC, CISA, or CISSP preferred
  18. Previous experience in a software development company is preferred
  19. Experience using a GRC management platform (e.g. Archer, ZenGRC, etc.) preferred.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.