Security and compliance analyst

3 weeks ago


Bangalore, India Anumana Full time

Position: Security and Compliance Analyst Experience Range: 3 to 5 yrs Job Location: Bangalore Work Mode: Hybrid (3 days in the office, 2 days remote) Job Summary Anumana is seeking a detail-oriented and proactive Security and Compliance Analyst to ensure our organization’s adherence to international security standards and regulatory requirements. The successful candidate will play a key role in the development, implementation, and continuous improvement of Anumana's Information Security Management System (ISMS) in compliance with ISO/IEC 27001, ISO/IEC 27002, and ISO 13485 standards. This role involves close collaboration with multiple departments—HR, Legal, IT, Engineering, and Quality/Regulatory teams—to maintain a robust security and compliance posture. The Security and Compliance Analyst will also be responsible for managing third-party risk assessments, ensuring compliance with global privacy regulations (such as GDPR), and supporting the overall Information Security Program. Key Responsibilities Compliance Management Maintain and continuously improve the Information Security Management System (ISMS) to comply with ISO/IEC 27001, ISO/IEC 27002, and ISO 13485 standards. Coordinate with the Quality and Regulatory team to align security controls with ISO 13485 requirements for medical device software. Develop and update policies, procedures, and documentation necessary for maintaining certification status. Conduct internal audits and prepare for external audits, ensuring that all necessary evidence is documented and accessible. Cross-Department Collaboration Work closely with HR, Legal, IT, Engineering, and other departments to ensure that information security requirements are consistently integrated across the organization. Provide guidance on security and compliance matters, including secure practices, policy enforcement, and risk mitigation. Assist in the development of training materials and conduct regular security awareness sessions for staff. Third-Party Risk Management Respond to third-party risk management questionnaires, ensuring that external parties meet Anumana’s security standards. Perform risk assessments on vendors, suppliers, and partners, evaluating their adherence to security requirements. Maintain and update a database of third-party risk assessments and ensure regular monitoring of vendor compliance. Privacy and Confidentiality Management Monitor and enforce privacy compliance across the organization, focusing on GDPR, CCPA, and other relevant global data protection regulations. Track data protection incidents and coordinate response and remediation activities. Work with Legal and HR teams to ensure confidentiality agreements are properly managed and enforced. Security Program Oversight Support the overall information security program by conducting risk assessments, tracking key performance indicators (KPIs), and managing security metrics. Develop and maintain security policies, standards, and guidelines based on best practices and relevant frameworks. Monitor and assess compliance with organizational policies, industry standards, and applicable regulations. Identify areas of improvement in security controls and recommend mitigation strategies. Audit Preparation & Evidence Management Gather, organize, and maintain documentation of control evidence required for internal and external audits. Track audit findings, follow up on remediation actions, and ensure they are completed on time. Prepare reports summarizing compliance activities, audit results, and risk assessments for management review. Qualifications Required: Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field (or equivalent experience). 3+ years of experience in information security, compliance, risk management, or related fields. Strong understanding of ISO/IEC 27001, ISO/IEC 27002, and ISO 13485 standards. Experience with information security frameworks (e.g., NIST, HITRUST) and best practices. Knowledge of data protection regulations, including GDPR, CCPA, and other privacy laws. Ability to respond to third-party risk assessments and manage vendor compliance. Familiarity with GRC (Governance, Risk, and Compliance) tools and methodologies. Preferred: Professional certifications such as CISSP, CISM, CRISC, CCSK, or ISO/IEC 27001 Lead Auditor/Implementer. Experience working in the medical device or healthcare sector, with familiarity in Software as a Medical Device (Saa MD). Knowledge of security assessment tools and vulnerability management practices. Understanding of secure software development and Dev Sec Ops practices. Skills: Strong analytical and problem-solving skills with attention to detail. Excellent communication skills, with the ability to present complex information clearly to technical and non-technical stakeholders. Highly organized, with strong project management skills and the ability to prioritize tasks effectively. Demonstrated ability to work collaboratively with cross-functional teams.


  • IT Security

    4 days ago


    bangalore, India Genpact Full time

    IT Security & Compliance LeadLocation: HyderabadExperience: 5-8 yearsOnly Immediate Joiners.ResponsibilitiesIT Security, Compliance and Administration the Security/Compliance Analyst works in compliance with all written and approved policies, rules and regulations. This also includes the review and audit of all required data and evidences presented to both...


  • Bangalore, India Signzy Full time

    Signzy is a digital trust system. We provide identification, background checks, forgery detection and contract management systems which enable contracting in a trustable, safe, legal, and convenient manner. Our biometric user authentication system and blockchain-based digital trail ensure non-repudiation. This increases compliance and enforceability in...


  • bangalore, India IBS Software Full time

    Senior Compliance Analyst Trivandrum Location Conduct regular risk assessments and gap analyses to identify areas for improvement. Coordinate the SOC 1, SOC 2, SOC 3 audit process, liaising with external auditors and ensuring timely completion. Oversee PCI DSS assessments, ensuring adherence to Payment Card Industry Data Security Standards. Ensure...


  • bangalore, India Signzy Full time

    Signzy is a digital trust system. We provide identification, background checks, forgery detectionand contract management systems which enable contracting in a trustable, safe, legal, andconvenient manner. Our biometric user authentication system and blockchain-based digital trailensure non-repudiation. This increases compliance and enforceability in the...


  • Bangalore, India Signzy Full time

    Signzy is a digital trust system. We provide identification, background checks, forgery detection and contract management systems which enable contracting in a trustable, safe, legal, and convenient manner. Our biometric user authentication system and blockchain-based digital trail ensure non-repudiation. This increases compliance and enforceability in...


  • Bangalore, Karnataka, India iManage Full time

    We offer a flexible working policy that supports the health and well-being of our iManage employees As an organization we value collaborating and learning from our peers in person while providing the necessary flexibility for our employees to have a meaningful work-life balance Please reach out to learn more Being a Security Compliance Analyst at iManage...


  • Bangalore, India Smarsh Full time

    Smarsh is the leader in communications compliance, archiving, and analytics. We provide compliance across the broadest set of communications channels with insights on what’s being captured. top 8 European, top 5 Canadian, and top 3 Asian banks. The Smarsh advantage is customers stay ahead of compliance and uncover patterns and relationships hidden within...


  • New Delhi, Mumbai, Bangalore, Chennai, Hyderabad, Ahmedabad, India Certify Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    About Certify: At CertifyOS, we're building the infrastructure that powers the next generation of provider data products, making healthcare more efficient, accessible, and innovative. Our platform is the ultimate source of truth for provider data, offering unparalleled ease and trust while making data easily accessible and actionable for the entire...

  • Tactical Analyst

    2 weeks ago


    bangalore, India MAX Security Full time

    Company Profile:Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai. Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret Services we operate in 160 countries across the globe. We have capabilities in every continent across the world and carry the experience of 25 +...


  • Bangalore, Karnataka, India everbridge Full time

    Everbridge is seeking an energetic multi-tasking and process focused Sales Security Analyst to support our nationwide sales team The Sales Security Analyst provides a wide range of security privacy and operational support to the Everbridge sales team The Sales Security Analyst will also become a strong user of and confidential messaging technologies ...