Information Security Compliance Analyst

1 week ago


Bengaluru, Karnataka, India Sumeru Global Technologies Full time

Job Brief :

  • Compliance Analyst.

Responsibilities :

What you'll do :

  • Assist with the implementation and management of Clients common/unified controls framework.
  • Work as a subject matter expert on the process to interpret compliance regulations such as ISO27001, SOC1, SOC2, NIST and NIST into actionable controls, with corresponding processes, policies, oversight.
  • Ability to deep dive into the various Client control environments to develop technical understanding of control implementation, and articulate compliance implications to internal control owners and external audit functions.
  • Build capabilities for automation of evidence and integration into GRC platforms.
  • Work with external auditors on regulatory and compliance program audits and assessments.
  • GRC and automation tooling API Integration: Collaborate with crossfunctional teams to identify integration requirements and design solutions that connect our Technical Compliance platforms with thirdparty services, ensuring seamless data flow and functionality.
  • Assist in the continuous effort of implementing and executing continuous monitoring activities to maintain a real time conformance view for Client SaaS environments.
  • Assess: Seek out opportunities to improve verification of controls compliance, such as through automation of tests.
  • Assess: Evaluate, document, and communicate business risk in the context of control designs and gaps.
  • Assess: Evaluate and assess the effectiveness of management, operational, and technical security controls.
  • Assess: Conducting walkthroughs and audits to assess the adequacy of controls for adherence to established policies, procedures, business practices, and compliance with the Client Unified Controls Framework.
  • Assess: Obtaining and reviewing evidence, ensuring audit conclusions are well documented and based on a complete understanding of the processes and risks.
  • Monitor complianceled initiatives against KPIs, managing project risks, stakeholders, and excellent project delivery.

Requirements :

What we're looking for :

  • Strong familiarity with risk management methodologies and common security controls frameworks, such as OX, ISO 27001, SOC I & II, NIST, CMMC, FedRamp, etc.
  • Experience with security compliance monitoring tools/solutions offered natively in AWS, SIEM tools, GRC platforms, vulnerability scanning tools and log analysis, PAM (Privileged Access Management), and other infrastructure security tools.
  • Ability to clearly communicate technical issues to nontechnical audiences and others with varying backgrounds.
  • Experience in performing and/or participating in technical assessments in direct support of other I.
  • Security and Management Standards (such as, NIST 80053, FedRAMP/StateRAMP, SOC 2).
  • Relevant professional certifications, such as CISA, CISM, CISSP, GCCC, ISO 27001 Auditor.
  • Experience in cloud technologies, cloud deployment models (IaaS/PaaS/SaaS), and audit of cloud environments.
  • Bachelor's degree in Engineering, Information Systems, Business or related disciplines; Masters preferred with 2+ years of experience at a Big 4 consulting firms or similar.
  • 5+ years as a technical compliance specialist, preferably at a latestage tech startup/newlypublic company; along with 5+ years of experience as a technical manager preferred.
  • Selfsufficient and selfmotivated; capable of working with ambiguity in a dynamic environment.
  • Outstanding written and verbal communication skills will need to document policies and procedures, and articulate them well across all levels at Client.
  • Strong collaboration and negotiation skills and demonstrated ability to manage multiple projects and priorities.
  • Creative, business first approach to GRC with CISA, CISM, CISSP and other certifications a plus.
  • A detailed understanding of evaluating the design and effectiveness of IT controls and experience working with auditors/regulators for these types of assessments.

Must Haves :

  • 5+ experience.
)

  • Bengaluru, Karnataka, India Amadeus Full time

    Job TitleInformation Security Analyst TheJunior Communication Analystwill fulfill the following tasks:Communication CampaignsDevelop and maintain our community on the intranet.Connect and engage with our colleagues globally on our internal social network (Viva Engage) through compelling posts and infographics.Create and manage a metrics framework to...


  • Bengaluru, Karnataka, India Amadeus Full time

    Job Title Information Security AnalystThe Junior Communication Analyst will fulfill the following tasks: Communication Campaigns Develop and maintain our community on the intranet. Connect and engage with our colleagues globally on our internal social network (Viva Engage) through compelling posts and infographics. Create and manage a metrics framework to...


  • Bengaluru, Karnataka, India Decision Foundry Full time

    Welcome to Decision Foundry We are both a high growth startup and one of the longest tenured Salesforce Marketing Cloud Implementation Partners in the ecosystem. Forged from a 19-year-old web analytics company, Decision Foundry is the leader in Salesforce intelligence solutions. We win as an organization through our core tenets. They include: One Team. One...


  • Bengaluru, Karnataka, India Rakuten India Full time

    JOB TITLE: INFORMATION SECURITY ANALYST EXPERIENCE: 2-3 Years. Knowledge, Skills RequirementAdministration of the DLP tools which includes configuring policies, upgrading and patching, etc.2-3 years of experience in data leakage analysis or data loss prevention for an enterprise network.Knowledge of core Information Security concepts related to Governance,...


  • Bengaluru, Karnataka, India Nike Full time

    Rejoignez l'équipe NIKE, Inc. Loin de se contenter d'équiper les plus grands athlètes mondiaux, NIKE, Inc. explore les potentiels, abolit les frontières et repousse les limites du possible. L'entreprise recherche des personnes capables d'évoluer, de réfléchir, de rêver et de créer. L'épanouissement de sa culture repose sur son ouverture à la...


  • Bengaluru, Karnataka, India WELLS FARGO BANK Full time

    About this role:Wells Fargo is seeking a Lead Information Security AnalystIn this role, you will:Support issue management lifecycleProvide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediationDirect information security risk assessment and research, and recommend remediation...


  • Bengaluru, Karnataka, India WELLS FARGO BANK Full time

    About this role: Wells Fargo is seeking a Senior Information Security Analyst...In this role, you will: Provide information security consultation to improve awareness and compliance with Enterprise Information Security policy, processes and standards Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support...


  • Bengaluru, Karnataka, India WELLS FARGO BANK Full time

    About this role:Wells Fargo is seeking a Lead Information Security Analyst...In this role, you will:Support issue management lifecycleProvide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediationDirect information security risk assessment and research, and recommend remediation...


  • Bengaluru, Karnataka, India Take-Two Interactive Full time

    Job Title: Information Security Risk AnalystWho We Are:Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially successful entertainment experiences,...

  • Security Analyst

    1 week ago


    Bengaluru, Karnataka, India Dimiour Full time

    A Security Analyst, also known as an Information Security Analyst or Cybersecurity Analyst, is a professional responsible for protecting an organization's computer systems and networks. This role involves identifying and mitigating potential security threats, managing security tools, and ensuring compliance with security policies and regulations. Below is a...


  • Bengaluru, Karnataka, India Virtusa Full time

    Information Security Analyst - CREQ188067 Description P1-C3-STSInformation Security Managers know security is a top priority for our business, our partners, and customers. As cyber-attacks increase and compliance is rigorously implemented, they strive to stay ahead of what is next to protect our brand and future. The IT Risk Assessment Operational Risk Event...


  • Bengaluru, Karnataka, India ResMed Full time

    The Information Technology (IT) team plays a key role in providing business enablement throughout ResMed. We are focused on application, infrastructure, and user productivity solutions, with innovation, efficiency and security. Our goal is providing customer oriented agile delivery, effective business partnership and state-of-the-art technology solutions. ...


  • Bengaluru, Karnataka, India ResMed Full time

    The Information Technology (IT) team plays a key role in providing business enablement throughout ResMed. We are focused on application, infrastructure, and user productivity solutions, with innovation, efficiency and security. Our goal is providing customer oriented agile delivery, effective business partnership and state-of-the-art technology...


  • Bengaluru, Karnataka, India WELLS FARGO BANK Full time

    About this role:Wells Fargo is seeking an Analyst in the area of Information and Cyber Security for the Technology Third Governance function. The role activities includes Identifying, Analyzing and responding to Incidents related to third party service providersIn this role, you will:Provide information security consultation to improve awareness and...


  • Bengaluru, Karnataka, India Rakuten India Full time

    JOB TITLE:INFORMATION SECURITY ANALYSTEXPERIENCE:2-3 Years.Knowledge, Skills RequirementAdministration of the DLP tools which includes configuring policies, upgrading and patching, etc.2-3 years of experience in data leakage analysis or data loss prevention for an enterprise network.Knowledge of core Information Security concepts related to Governance, Risk...


  • Bengaluru, Karnataka, India Take-Two Interactive Software Full time

    About the PositionJob Title:Information Security Risk AnalystWho We Are:Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially successful entertainment...


  • Bengaluru, Karnataka, India Eurofins Full time

    Job Description POSITION TITLE (ENGLISH): Information Security Analyst (L1 SOC) REPORTING TO: Manager REPORTING LOCATION: Bangalore POSITION & OBJECTIVES : Eurofins is ramping up the Security Operations Center and has a need to extend the L1 incident response team. The person working in L1 SOC team operates the security monitoring...


  • Bengaluru, Karnataka, India Allime Tech Solutions Full time

    Job Title: Privacy Compliance AnalystCompany: Security Solutions Ltd.About the Role: Are you a Privacy Compliance Analyst with a passion for data security technologies? We are looking for someone experienced in Classification, DLP, DRM, and familiar with implementing data privacy and security frameworks. We need a continuous learner who is self-driven, a...


  • Bengaluru, Karnataka, India Whatfix Full time

    Position Summary: The Security Compliance Specialist is responsible for managing all compliance related activities within the Whatfix platform and supporting other global compliance related initiatives. Compliance activities will include coordinating internal and external assessments/audits, contributing to policy and standards updates, developing...


  • Bengaluru, Karnataka, India Virtusa Full time

    Lead Information Security Analyst - CREQ188070 Description P1-C3_STSExperience with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.Experience with application security controls (Web, API, Mobile, AI).Experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP...