Information Security

2 days ago


Pune, India Antal International Full time

Job Description Position: Information Security & Control Analyst II Location: Pune, MH Experience Range: Relevant 3 to 5 years Mode of work: 5 days (office) Job Mission: The Information Security & Control Analyst II or IT Security Officer (ISO) is responsible for implementing, continuously improving, and maintaining the HPS Payment Services information security program. The position requires strong expertise in information security management, as well as in-depth knowledge of security standards and best practices, such as ISO 27001. Job Purpose: 1) Information Security Management System: Implement, continuously improve, and maintain the information security program for HPS Payment services Support the CISO by contributing to the development, implementation, and maintenance of information security policies, processes, procedures, and controls to protect HPS Payment Services' assets from internal and external threats. Identify risks, vulnerabilities, and potential threats to HPS Payment Services' assets and implement mitigation and contingency plans to minimize the impact on business operations. Develop and implement information security plans to ensure protection, confidentiality, integrity, and availability of HPS Payment Services' data. Regularly assess the effectiveness of security policies, processes, procedures, and controls and recommend risk treatment actions while ensuring follow-up. Monitor and manage IT risks and non-compliance with contractual requirements signed with clients. Update and review HPS Payment Services' risk register regularly. Ensure appropriate security measures based on process criticality and asset sensitivity, including: Assessing inherent and residual risk levels with asset owners. Guiding risk owners towards suitable options (risk reduction, acceptance, transfer, or rejection). Challenging proposed action plans to ensure realistic and implementable security measures. Prepare and lead IT Risk Committees and ensure proper implementation of Information Security Governance (ISG) 2) Security by Design: Ensuring Security in Projects Guide projects in implementing new security systems or integrating existing systems. Define and implement IT risk management requirements in HPS Payment Services' projects. Ensure the integration of security measures in the project lifecycle. Identify security-related risks, vulnerabilities, and potential threats in projects and define and monitor treatment plans. Ensure compliance with security regulations and standards. Evaluate technological solutions in projects to guarantee compliance with security requirements. Assess and track security performance in projects using key performance indicators (KPIs). 3) Security Assurance: Maintaining Security Certifications Manage certification schedules and anticipate recertification exercises. Coordinate with internal teams to organize regular reviews and collect certification deliverables. Oversee action plans derived from certification exercises. 4) Monitoring Operational Security and Risk Treatment Plans. Track IT security risk and performance indicators. Monitor the operational implementation of information security. Oversee access reviews within the security perimeter. Monitor, investigate, and resolve security incidents while ensuring proper escalation. Follow up on action plans after security incidents. Monitor security clauses in outsourcing contracts. Conduct technology watch and stay updated on emerging threats and security solutions. Work with the operational security team to deploy and maintain security solutions while ensuring compliance with IS security policies. Analyse and assess risks from vulnerability scans and penetration testing results. 5) Permanent Control Support the Level 1 Permanent Control Manager in defining management surveillance controls related to IT security. Coordinate and manage control campaigns to meet deadlines. Depending on the implemented Target Operating Model (TOM), either: Support operational teams in executing controls and challenge their findings, or Perform managerial surveillance controls and document control results. Ensure action plans are well-defined to address risks identified during controls. Produce and track risk and performance indicators from control campaigns. Assist in updating the operational risk mapping related to IT security management. Ensure IT security-related operational risk incidents are escalated to the audit department and track associated reports. Technical Skills: Knowledge of Banking & Financial Services Internal Control & Risk Management IT & Security Functions Knowledge Information Security Management Security Governance & Risk Frameworks IT Development & Architecture IT Risk Management Frameworks ISO 27005, EBIOS, CRISC, NIST, CIS20 Managerial Skills: Client Focus Commitment to deadlines Initiative taking Problem anticipation Reporting & monitoring Quality Management Behavioural Skills: Interpersonal skills Initiatives Flexibility Support & assistance Confidentiality, Integrity, Objectivity Analytical & Synthesis skills Rigor & Organization KPIs: Quality of IT Risk & Security Management framework Vulnerability & Security Patch management Client reporting Quality, relevance, and consistency of security reports Compliance with control deadlines



  • Pune, Maharashtra, India Cortex Consultants Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Information Security & Control Analyst II Information Security & Control Analyst II 3-5 Years Experience We are looking for an Information Security Analyst II to join our dynamic team. You will be responsible for advising and assisting our clients in managing risks related to information systems, implementing security processes, ensuring regulatory...


  • pune, India Tekskills Inc. Full time

    Job Title:Information Security & Compliance AnalystLocation:Pune, MH (WFO)Skills Required: ISO 27001:2005~Cyber Security Digital: Risk Regulatory Compliance Analytics Cyber Security - Information Security Risk & ComplianceExperience: yearsJob Description:We seek a resourceful generalist with up to 7 years' experience, hands-on data sharing expertise, broad...


  • Pune, Maharashtra, India Davies Full time

    Application Deadline:31 December 2025Department:Risk and ComplianceLocation:PuneDescriptionWe are seeking a proactive and knowledgeable Information Security Officer to support the business across all aspects of information security. This role is essential in maintaining and strengthening our security posture, ensuring compliance with our regulatory and legal...


  • Pune, Maharashtra, India Agiliad Full time ₹ 8,00,000 - ₹ 18,00,000 per year

    Essential Responsibilities include (but are not limited to):Help to plan and carry out the organizations information security strategy. Prepare and execute actions based on an ISMS calendar.Develop a set of security standards, policies and best practices for the organization.Regularly monitor computer networks and systems for security issues, breaches, or...


  • Pune, India TIAA Full time

    Senior, Info Security The Senior, Information Security job works to prevent Information Technology based crime, hacking, intentional or inadvertent modification, disclosure, or destruction of the organization's information systems, assets and intellectual property. Under general supervision, this job monitors the organization's Information Technology...


  • Pune, India TAC Security Full time

    Job Description Key Responsibilities - Conduct security assessments by scanning applications and networks, performing penetration tests for further exploitation. - Execute Web Application SAST, DAST, Mobile Application Security testing, and API security testing. - Establish and maintain a Vulnerability Management framework including assessment, treatment,...


  • pune, India Easebuzz Full time

    About Easebuzz Private Limited:Easebuzz is a payment solutions (fintech organisation) company which enables online merchants to accept, process and disburse payments through developer friendly APIs. We are focusing on building plug n play products including the payment infrastructure to solve complete business problems. Definitely a wonderful place where all...


  • pune, India Threadneedle Software Full time

    We are seeking a proactive and detail-oriented Information Security Engineer to own and operate our information security program. This is a critical hybrid role responsible for maintaining our security and compliance posture across multiple frameworks (ISO 27001, ISO 27017, SOC 2) while also managing and implementing the technical security controls that...


  • Pune, Maharashtra, India Allianz Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    You will lead a team of dedicated security professionals, providing strategic direction and technical guidance. This position requires a strong blend of leadership, technical expertise, and a forward-thinking approach to security, including a keen understanding of how emerging technologies like Artificial Intelligence can be leveraged for both offense and...


  • Pune, India Verdantas Full time

    Join Verdantas – A Top #ENR 81 Firm,We at Verdantas are seeking a highly motivated and detail-oriented Information Security Analyst, to protect our company’s critical systems and sensitive data. You will be an integral part of our security team, responsible for implementing, maintaining, and monitoring our security posture. The ideal candidate will have...