Cyber Risk Security Analyst
1 day ago
Job purpose:
The purpose of the Cyber Security Risk Analyst is to own the risk assessment lifecycle and lead detailed technical security audits across cloud and om-prem environments. This position will also be responsible for design and execution of IT controls testing, the evaluation of technical controls effectiveness, and for driving remediation with engineering and product teams.
key accountabilities:
- Lead technology and cyber risk assessments, maintaining a risk register with clear impact/likelihood rationales and treatment plans.
- Map controls to frameworks (ISO/IEC 27001:2022/27002, NIST CSF 2.0, NIST 80053, CIS Controls, PCI DSS 4.0) and regulatory obligations (GovRAMP, EU AI Act, GDPR, CCPA).
- Support policy/standard updates and control design reviews; advise on risk appetite, KRIs, and control maturity targets.
- Conduct security risk assessments, identifying threats, vulnerabilities, and control gaps.
- Maintain the security risk register, define treatment plans, and monitor remediation progress.
- Support quantitative or qualitative risk analysis (e.g., FAIR-lite) for critical assets and processes.
- Conduct deep dive security reviews, identifying threats, vulnerabilities and control gaps.
- Plan and execute end-to-end technical audits including scope, testing plans, evidence requests, fieldwork, sampling, walkthroughs, and issue rating.
- Develop control frameworks for secure software development and execute audits having a good understanding of agile software development practices and security by design principles (DevSecOps).
- Produce clear, actionable audit reports and present findings to engineering leadership and risk committees.
- Test design and operating effectiveness of Access Control, Application and Data Security, IT Service Operations, Technology Architecture, Logical and Physical Security.
- Validate evidence, perform re-performance/inspection, and document results according to audit best practices.
- Track remediation to closure; verify fixes and update control matrices.
- Perform third-party risk assessments, reviewing security posture, contractual controls, and data flows.
- Contribute to AI governance and data protection audits where relevant.
- Partner with security engineering, IT, data, and product teams to translate requirements into technical controls and pragmatic remediation.
- Create playbooks, control testing procedures, and knowledge articles; run enablement sessions to raise control maturity.
Skills, Qualifications & Experience
- To combine a risk and compliance mindset with strong technical depth in modern enterprise security tooling.
- Proven experience in cyber security with demonstrable experience in risk assessment and security auditing.
- Audit and security certifications such as CISA, CISSP, CISM, ISO 27001 Lead Auditor/Implementer or equivalent experience.
- Strong knowledge of ISO 27001/27002 and NIST CSF, with familiarity across NIST 80053, CIS Controls, and SOC 2 or PCI DSS.
- Hands-on experience assessing Microsoft and Azure security including Entra ID, Defender suite, Sentinel, Intune, Azure Policy, and Purview.
- Experience with Identity and Access, Cloud Security (Azure, AWS), Data Protection, SecOps, Agile Software Development (DevSecOps), Security by Design.
- Solid grasp of ITGCs and evidence-based testing methods; excellent audit documentation and reporting skills.
- Technical literacy across networks, identity, cloud, endpoints, logging/monitoring, and secure configuration.
- Competence in using GenAI to enhance work practices and have experience in using Agentic AI to automate GRC processes.
- Ability to develop relationships with key technical position holders across locations and functions
- Excellent communication skills with the ability to express ideas and messages clearly, both written and verbally
Suitable candidates can share their resume
-
Cyber Security
1 week ago
Gurgaon, Haryana, India BlackRock Full time ₹ 9,00,000 - ₹ 12,00,000 per yearCyber Security - Data Protection, Tech & Ops, AnalystLocation:Gurgaon, HaryanaTeam:Information SecurityJob Requisition #: R256647Date posted: Sep. 09, 2025
-
L2 Cyber Security Analyst
1 week ago
Gurgaon, Haryana, India gtprod Full time ₹ 5,00,000 - ₹ 12,00,000 per yearJob Title: Level 2 Cyber Security AnalystExperience Required: 3-6 YearsLocation: Work from office (Gurugram)Shift Timing: 24x7Job Responsibilities:Incident Investigation: Conduct thorough investigations of security incidents using IBM QRadar, ensuring timely and accurate identification, analysis, and resolution of security threats.Support Level 1...
-
Cyber risk
4 days ago
Gurgaon, Haryana, India KPMG Assurance and Consulting Services LLP Full time ₹ 9,00,000 - ₹ 12,00,000 per year>>Technical SkillsExpertise in cyber security including standards such as ISO27001, PCI-DSS, ISO22301, Privacy etc.Knowledge of technical domains such as Cloud security, VAPT, Application security, Risk and control assessment, Technology risk assessments, IT or OT compliance, Data privacy, and Network securityKnowledge of concepts such as Shadow IT, Vendor...
-
Cyber Security
1 week ago
Gurgaon, Haryana, India BlackRock Full time ₹ 9,00,000 - ₹ 12,00,000 per yearAbout this roleOverviewJoin our distributed team of cyber security experts, protecting our business and developing exciting capabilities on the frontline of cyber defense. Apply your passion and knowledge of cyber security to assist in the investigation of incidents. This individual will be part of the Cyber Data Protection Operations team that is...
-
Cyber Threat Intelligence Analyst
1 week ago
Gurgaon, Haryana, India Rackspace Full time ₹ 15,00,000 - ₹ 25,00,000 per yearRackspace Cyber Defense Cyber Threat Intelligence Analyst, Security Operations About Rackspace Cyber Defence Rackspace Cyber Defence is our next generation cyber defense and security operations capability that builds on 20 years of securing customer environments to deliver proactive, risk-based, threat-informed and intelligence-driven security...
-
Cyber Threat Intelligence Analyst
1 week ago
Gurgaon, Haryana, India Rackspace Full time ₹ 1,04,000 - ₹ 1,30,878 per yearRackspace Cyber Defense Cyber Threat Intelligence Analyst, Security Operations About Rackspace Cyber DefenceRackspace Cyber Defence is our next generation cyber defense and security operations capability that builds on 20+ years of securing customer environments to deliver proactive, risk-based, threat-informed and intelligence-driven security services. ...
-
Cyber Threat Intelligence Analyst
1 week ago
Gurgaon, Haryana, India Rackspace Technology Full time ₹ 12,00,000 - ₹ 36,00,000 per yearRackspace Cyber DefenseCyber Threat Intelligence Analyst, Security OperationsAbout Rackspace Cyber DefenceRackspace Cyber Defence is our next generation cyber defense and security operations capability that builds on 20+ years of securing customer environments to deliver proactive, risk-based, threat-informed and intelligence-driven security services.Our...
-
Cyber Security
4 days ago
Gurgaon, Haryana, India Global Technology Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description Job Description: We are looking for a proactive and detail-oriented Cyber Security professional to protect our organization's systems, networks, and data from cyber threats. The candidate will be responsible for monitoring security operations, identifying vulnerabilities, implementing security measures, and ensuring compliance with...
-
Security Analyst III
1 week ago
Gurgaon, Haryana, India Rackspace Technology Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Profile SummaryPerform real-time monitoring and analysis of security events from multiple sources. Identify source or cause and provide recommendations for secure infrastructure through policy, practices, risk management, engineering, and improved operations. Responsible for adhering to company security policies and procedures and any other relevant...
-
Security Operations Center Analyst
1 week ago
Gurgaon, Haryana, India eSec Forte® Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per yearExperiene:2-5 yearsRole DescriptionThis is a full-time on-site role for a Security Operations Center Analyst located in Gurugram. The Security Operations Center Analyst will be responsible for monitoring and analyzing security events, conducting cyber threat hunting, generating cyber threat intelligence reports, and responding to security incidents. Other...