Information Security Compliance Analyst

4 weeks ago


Bangalore, India Sumeru Global Technologies Full time

Job Brief :

- Compliance Analyst.

Responsibilities :

What you'll do :

- Assist with the implementation and management of Clients common/unified controls framework.

- Work as a subject matter expert on the process to interpret compliance regulations such as ISO27001, SOC1, SOC2, NIST 800-53 and NIST800-171 into actionable controls, with corresponding processes, policies, oversight.

- Ability to deep dive into the various Client control environments to develop technical understanding of control implementation, and articulate compliance implications to internal control owners and external audit functions.

- Build capabilities for automation of evidence and integration into GRC platforms.

- Work with external auditors on regulatory and compliance program audits and assessments.

- GRC and automation tooling API Integration: Collaborate with cross-functional teams to identify integration requirements and design solutions that connect our Technical Compliance platforms with third-party services, ensuring seamless data flow and functionality.

- Assist in the continuous effort of implementing and executing continuous monitoring activities to maintain a real time conformance view for Client SaaS environments.

- Assess: Seek out opportunities to improve verification of controls compliance, such as through automation of tests.

- Assess: Evaluate, document, and communicate business risk in the context of control designs and gaps.

- Assess: Evaluate and assess the effectiveness of management, operational, and technical security controls.

- Assess: Conducting walkthroughs and audits to assess the adequacy of controls for adherence to established policies, procedures, business practices, and compliance with the Client Unified Controls Framework.

- Assess: Obtaining and reviewing evidence, ensuring audit conclusions are well documented and based on a complete understanding of the processes and risks.

- Monitor compliance-led initiatives against KPIs, managing project risks, stakeholders, and excellent project delivery.

Requirements :

What we're looking for :

- Strong familiarity with risk management methodologies and common security controls frameworks, such as OX, ISO 27001, SOC I & II, NIST, CMMC, FedRamp, etc.

- Experience with security compliance monitoring tools/solutions offered natively in AWS, SIEM tools, GRC platforms, vulnerability scanning tools and log analysis, PAM (Privileged Access Management), and other infrastructure security tools.

- Ability to clearly communicate technical issues to non-technical audiences and others with varying backgrounds.

- Experience in performing and/or participating in technical assessments in direct support of other I.

- Security and Management Standards (such as, NIST 800-53, FedRAMP/StateRAMP, SOC 2).

- Relevant professional certifications, such as CISA, CISM, CISSP, GCCC, ISO 27001 Auditor.

- Experience in cloud technologies, cloud deployment models (IaaS/PaaS/SaaS), and audit of cloud environments.

- Bachelor's degree in Engineering, Information Systems, Business or related disciplines; Masters preferred with 2+ years of experience at a Big 4 consulting firms or similar.

- 5+ years as a technical compliance specialist, preferably at a late-stage tech startup/newly-public company; along with 5+ years of experience as a technical manager preferred.

- Self-sufficient and self-motivated; capable of working with ambiguity in a dynamic environment.

- Outstanding written and verbal communication skills will need to document policies and procedures, and articulate them well across all levels at Client.

- Strong collaboration and negotiation skills and demonstrated ability to manage multiple projects and priorities.

- Creative, business first approach to GRC with CISA, CISM, CISSP and other certifications a plus.

- A detailed understanding of evaluating the design and effectiveness of IT controls and experience working with auditors/regulators for these types of assessments.

Must Haves :

- 5+ experience.

(ref:hirist.tech)

  • bangalore, India HeadPro Consulting LLP Full time

    Job Title : Senior InfoSec Quality & Compliance Analyst Location : BangaloreExperience : 3 - 7 YearsBudget : 17 - 22 LPAMandatory skills :1. Require someone who have good experience in Third Party Risk management2. Need someone who have good knowledge with Cloud infrastructure & general IT Clouds is Preferred 3. Candidate having good Knowledge on One Trust...


  • Bangalore, India HeadPro Consulting LLP Full time

    Job Title : Senior InfoSec Quality & Compliance Analyst Location : BangaloreExperience : 3 - 7 YearsBudget : 17 - 22 LPAMandatory skills :1. Require someone who have good experience in Third Party Risk management2. Need someone who have good knowledge with Cloud infrastructure & general IT Clouds is Preferred 3. Candidate having good Knowledge on One Trust...


  • bangalore, India Amadeus Full time

    Job Title Information Security AnalystThe Junior Communication Analyst will fulfill the following tasks: Communication Campaigns Develop and maintain our community on the intranet. Connect and engage with our colleagues globally on our internal social network (Viva Engage) through compelling posts and infographics. Create and manage a metrics framework to...


  • bangalore, India Decision Foundry Full time

    Welcome to Decision Foundry! We are both a high growth startup and one of the longest tenured Salesforce Marketing Cloud Implementation Partners in the ecosystem. Forged from a 19-year-old web analytics company, Decision Foundry is the leader in Salesforce intelligence solutions. We win as an organization through our core tenets. They include: One Team....


  • bangalore, India Talent Ocean Full time

    Client : MNCPayroll: Third partyBudget : As per marketstandardsExperience : 36 YearsNP : Immediate to April joinersonlyLocation : BangaloreWFORisk Security &Compliance Analyst Certification : ISO 27001 LI CISSP / CISM / CISA IAMConsultant JobResponsibilities: Implementation of ISMSacross the organization working in European time zone driving thetopics and...

  • Compliance Manager

    1 month ago


    bangalore, India LeadSquared Full time

    Location: BangaloreReports to: Director - ITPosition Overview: As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least 8 years of hands-on experience in managing compliance with ISO 27001, SOC 2, and HIPAA...

  • Compliance Manager

    1 month ago


    Bangalore Urban, India LeadSquared Full time

    Location: BangaloreReports to: Director - ITPosition Overview: As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least 8 years of hands-on experience in managing compliance with ISO 27001, SOC 2, and HIPAA...

  • Compliance Manager

    1 month ago


    Bangalore Urban, India LeadSquared Full time

    Location: Bangalore Reports to: Director - IT Position Overview: As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least 8 years of hands-on experience in managing compliance with ISO 27001, SOC 2, and...


  • bangalore, India Koch Global Services Full time

    Your Job Cyber Security - Information Security analysts are ultimately responsible for ensuring that the company's digital assets are protected from unauthorized access.This includes securing both online and on-premises infrastructures, weeding through metrics and data to filter out suspicious activity, and finding and mitigating risks before breaches...


  • bangalore, India Virtusa Full time

    Information Security Analyst - CREQ188067 Description P1-C3-STSInformation Security Managers know security is a top priority for our business, our partners, and customers. As cyber-attacks increase and compliance is rigorously implemented, they strive to stay ahead of what is next to protect our brand and future. The IT Risk Assessment Operational Risk Event...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • bangalore, India Eurofins Full time

    Job Description POSITION TITLE (ENGLISH): Information Security Analyst (L1 SOC) REPORTING TO: Manager REPORTING LOCATION: Bangalore POSITION & OBJECTIVES : Eurofins is ramping up the Security Operations Center and has a need to extend the L1 incident response team. The person working in L1 SOC team operates the security...


  • Bangalore, India Allime Tech Solutions Full time

    Job Summary :Privacy Compliance Analyst with experience in data security technologies such as Classification, DLP, DRM along with exposure to implementation of data privacy and security frameworks. A continuous learner who is self-driven, team player and zeal to bring security transformation by reducing the exposure surface.Key Responsibilities :- Lead the...


  • Bangalore, Karnataka, India Allime Tech Solutions Full time

    Job Summary :Privacy Compliance Analyst with experience in data security technologies such as Classification, DLP, DRM along with exposure to implementation of data privacy and security frameworks.A continuous learner who is self-driven, team player and zeal to bring security transformation by reducing the exposure surface.Key Responsibilities :- Lead the...


  • bangalore, India Virtusa Full time

    Lead Information Security Analyst - CREQ188070 Description P1-C3_STSExperience with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.Experience with application security controls (Web, API, Mobile, AI).Experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP...

  • Data Analyst

    5 days ago


    bangalore, India Flexi Analyst Full time

    Company DescriptionFlexi Analyst is a leading organization in Bengaluru that specializes in business, quality, data, and content analysis. With a leadership team from renowned companies such as Accenture, Amazon, Flipkart, Apple, and Inmobi, Flexi Analyst is building the largest community of analysts worldwide. Our main focus is on delivering value to our...

  • Data Analyst

    5 days ago


    bangalore, India Flexi Analyst Full time

    Company Description Flexi Analyst is a leading organization in Bengaluru that specializes in business, quality, data, and content analysis. With a leadership team from renowned companies such as Accenture, Amazon, Flipkart, Apple, and Inmobi, Flexi Analyst is building the largest community of analysts worldwide. Our main focus is on delivering value to our...


  • bangalore, India Unisys Full time

    What success looks like in this role: Perform risk and vulnerability assessments, partnering with system owners to remediate risks in our environment. Develop information security policies, standards, and procedures for the ISMS. Define metrics and regular reporting mechanisms for measuring compliance and performance of security controls. ...


  • bangalore, India Barracuda Full time

    Req ID Come Join Our Passionate Team! At Barracuda, we make the world a safer place. We believe every business deserves access to cloud-enabled, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect email, networks, data and applications with innovative solutions that grow and adapt with our customers’ journey. More than...