Senior Information Security Analyst

3 weeks ago


India Bread Financial Full time

Job Description Every career journey is personal. That's why we empower you with the tools and support to create your own success story. Be challenged. Be heard. Be valued. Be you ... be here. Job Summary The Sr. Analyst, Info Sec is responsible for overseeing and managing multiple risks, audits, and controls within the Information Technology Domain. This person is expected to be a strategic partner to control owners, second line of defense, and privacy leaders. The position reports to the Manager, Information Security and works closely with other Information Security Domain Champions. Essential Job Functions - Audit coordination and evidence collection Facilitate the collection of evidence for various audit and control activities such as PCIDSS, NIST CSF, GLBA 501-B, Sarbanes Oxley, etc. Review evidence for appropriateness and adequacy. Track and report on all evidence requests to ensure request deadlines are met. Coordinate and facilitate audit and/or control interviews as well as necessary follow up meetings between control owners and internal/external auditors. Publish meeting minutes and track action items to completion. Utilizes planning and organization tools to develop project/action plans. Meets deliverable deadlines as directed. - Payment Card Industry (PCI) Annual Audit - Possess in-depth knowledge of the PCI-DSS. Test PCI controls and work with control owners to resolve control design or operating effectiveness issues ahead of and during annual Company PCI Audit. Partner with external Qualified Security Assessor (QSA) to reduce scope and control testing where possible. Use knowledge of General IT Computing Controls and Cyber Security Tools to create PCI Compensating Control Matrices when required. - Control Coaching, Consulting, and Collaboration Partner with IT Control Owners to identify, resolve, mitigate, or compensate for control failures identified through risk assessments, internal/external audits, or cyber security tools and processes. Develop proactive risk and control assessment strategies to stay ahead of emerging risks and regulatory requirements. Collaborate with the IT Risk Second Line of Defense and Privacy Partners when formulating strategies to maximize coverage and work paper reuse. - General Information Technology - Foundational to intermediate knowledge of IT tools and practices including, but not limited to: Networking, LDAP Directories, Vulnerability/Patch Management, Change Management, Incident Management, Server and Desktop Management, Mainframe Technologies, Encryption and Key Management, Cloud Architecture and Computing, Software Application General Computing Controls, Business Continuity/Disaster Recovery, Software Development Lifecycle, Access Management, and Cyber Security Tooling. - Metrics and Presentation Skills Ability to produce meaningful and actionable metrics through data analysis. Conduct data analysis exercises using Excel Pivot Tables, Microsoft Access Queries, and other data driven analysis tools. Produces presentations at various levels of abstraction dependent on intended audience using Microsoft Power Point, Microsoft Visio, or equivalent tools. Intermediate to expert English writing skills expected. - Human Relations Ability to diffuse problematic situations and manage through conflict resolution. Utilizes soft skills such as: Selective Agreement, Reflective Listening, Voice Inflection, and Empathy. Ability to take complex concepts and break down into laymen's terms or analogies that help with other's understanding. Viewed as an enabling partner that provides options or information when saying no to business or IT requests. Seen by leadership and peers as creditable, trustworthy and respectful. Utilizes subject matter expertise to guide and coach less experienced team members. Reports to: Manager, IT Security Admin/Lead Working Conditions/ Physical Requirements: Normal office environment. As the need of the business continue to evolve, this role may be asked to work an on-call rotation to include evenings or weekends. Direct Reports: None Work Shift Required: Normal Office Work Timings: 11am to 8pm IST or 1pm to 10pm IST / Flexible to work in shifts as needed Minimum Qualifications - Bachelors Degree - Six or more years in Risk Management, Audit, Compliance, Information Technology Preferred Experience - Graduate or Post Graduate in Computer Science, Networking or Information Technology - Certifications: One or more relevant professional technical certifications (examples: CISSP, CISA, CISM, OR Security+) Other Duties This job description is illustrative of the types of duties typically performed by this job. It is not intended to be an exhaustive listing of each and every essential function of the job. Because job content may change from time to time, the Company reserves the right to add and/or delete essential functions from this job at any time. About Bread Financial At Bread Financial, you'll have the opportunity to grow your career, give back to your community, and be part of our award-winning culture. We've been consistently recognized as a best place to work nationally and in many markets and we're proud to promote an environment where you feel appreciated, accepted, valued, and fulfilledboth personally and professionally. Bread Financial supports the overall wellness of our associates with a diverse suite of benefits and offers boundless opportunities for career development and non-traditional career progression. Bread Financial (NYSE: BFH) is a tech-forward financial services company that provides simple, personalized payment, lending, and saving solutions to millions of U.S consumers. Our payment solutions, including Bread Financial general purpose credit cards and savings products, empower our customers and their passions for a better life. Additionally, we deliver growth for some of the most recognized brands in travel & entertainment, health & beauty, jewelry and specialty apparel through our private label and co-brand credit cards and pay-over-time products providing choice and value to our shared customers. To learn more about Bread Financial, our global associates and our sustainability commitments, visit breadfinancial.com or follow us on Instagram and LinkedIn. - All job offers are contingent upon successful completion of credit and background checks. - Bread Financial is an Equal Opportunity Employer. Job Family Information Technology Job Type Regular



  • India Cyber X Full time

    Job Description Company Description Cyber X Academy is committed to providing practical and transformative cybersecurity education. Through our Zero-to-Hero programs, we prepare students for high-demand roles such as SOC Analyst, Ethical Hacker, and Cybersecurity Analyst by combining real-world learning, personalized mentorship, and hands-on experience with...


  • India Transact Campus Full time

    Who We Are CBORD and Transact have come together as industry leaders in integrated technology solutions powering housing access foodservice nutrition eCommerce card systems and innovative payment mobile credential and commerce solutions Our technology supports K-12 and higher education healthcare senior living and business campuses creating connected campus...


  • Gurugram, Gurugram, India Connor, Clark & Lunn Financial Group (CC&L) Full time

    Job Description Information Security Analyst Connor, Clark & Lunn Financial Group Ltd. Gurugram (Hybrid), India Connor, Clark & Lunn Financial Group (CCLFG), one of Canada's leading asset managers, is seeking an Information Security Analyst to join our Center of Excellence (CoE) Information Security in Gurugram. The Information Security Team is responsible...


  • India Ameriprise Financial Full time

    Risk Control Analysis will support the risk identification control evaluation and process documentation across key business functions The role involves conducting risk assessments testing control effectiveness and maintaining Key Risk Indicators KRIs Ideal candidates will have expertise in internal controls information security and compliance frameworks such...


  • india HMH Full time

    HMH is a learning technology company committed to delivering connected solutions that engage learners, empower educators and improve student outcomes. As a leading provider of K–12 core curriculum, supplemental and intervention solutions, and professional learning services, HMH partners with educators and school districts to uncover solutions that unlock...


  • Noida, Uttar Pradesh, India, Ghaziabad Cognex Corporation Full time

    Job DescriptionThe Role: As a Senior Information Security Operations Analyst, you will lead the strategic development, implementation, and adoption of the overall Information Security Program.You will lead the investigation and resolution of security events and incidents sourced from log management tools and end-user initiated inquiries and incidents.An...


  • Noida, India hackajob Full time

    Job Description hackajob is collaborating with UnitedHealth Group to connect them with exceptional tech professionals for this role. Senior Information Security Engineering Analyst Requisition Number: 2307070 Job Category: Technology Primary Location: Noida, Uttar Pradesh, IN (Remote considered) Optum is a global organization that delivers care, aided by...


  • India Ameriprise Financial Full time

    Evaluate and support the delivery of business solutions that align with Ameriprise Information Security policies standards and best practices Candidate will be the single point of contact for assigned business projects for information security consulting engagements Performing internal audits supporting external audits and closing the identified gaps...


  • India Information Security Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    (Senior) Cloud DevOps Engineer - Persistent ABOUT UTIMACOUtimaco is a worldwide supplier of professional cyber-security solutions and is based in Aachen, Germany. Since 1983, Utimaco develops hardware security modules and compliance solutions for telecommunication provider regulations. Utimaco is a world-market leader in both segments. Customers and parters...


  • Chennai, India Virtusa Full time

    Job Description As a Junior Information Protection Analyst, you will be a vital part of our Information Protection team within the Enterprise Data Office (EDO). Your primary responsibility will be to safeguard Organizations data by triaging and reviewing data loss alerts and assisting in the testing and refinement of the playbooks, with a foundational...