IT Analyst, Security, Risk and Compliance

2 days ago


Chennai, Tamil Nadu, India The World Bank Full time ₹ 20,00,000 - ₹ 28,00,000 per year

IT Analyst, Security, Risk and Compliance
Job #: req34310

Organization: World Bank

Sector: Information Technology

Grade: GE

Term Duration: 3 years 0 months

Recruitment Type: Local Recruitment

Location: Chennai,India

Required Language(s)
Preferred Language(s):

Closing Date: 9/24/2025 (MM/DD/YYYY) at 11:59pm UTC

Description
Do you want to build a career that is truly worthwhile? Working at the World Bank Group provides a unique opportunity for you to help our clients solve their greatest development challenges. The World Bank Group is one of the largest sources of funding and knowledge for developing countries; a unique global partnership of five institutions dedicated to ending extreme poverty, increasing shared prosperity and promoting sustainable development. With 189 member countries and more than 120 offices worldwide, we work with public and private sector partners, investing in groundbreaking projects and using data, research, and technology to develop solutions to the most urgent global challenges. For more information, visit

Vice Presidency Context
Information and Technology Solutions (ITS) enables the WBG to achieve its mission of ending extreme poverty by 2030 and boosting shared prosperity in a sustainable manner by delivering transformative information and technologies to its staff working in over 130 client countries.

ITS services range from: establishing the infrastructure to reach and connect staff and development stakeholders; providing the devices and agile technology and information applications to facilitate the science of delivery through decentralized services; creating and maintaining tools to integrate information across the World Bank Group, the clients we serve and the countries where we operate; and delivering the computing power staff need to analyze development challenges and identify solutions.

The ITS business model combines dedicated business solutions centers that provide services tailored to specific World Bank Group business needs and shared services that provide infrastructure, applications and platforms for the entire Group. ITS is one of three VPUs that have been brought together as the World Bank Group Integrated Services (WBGIS), to provide enhanced corporate core services and enable the institution to operate as one strategic and coordinated entity.

Unit Context
The ITS Information Security and Risk Management (ITSSR) unit, headed by the Chief Information Security Officer (CISO), is responsible for providing leadership in managing the functions and activities of information security and risk across the World Bank Group, enabling the achievement of WBG's business objectives. ITSSR enables and facilitates a risk aware culture, ensures that WBG information assets are protected in an effective, efficient, and balanced manner; and IT security and risk management efforts throughout the World Bank Group are coordinated and aligned to the Bank's business and IT strategy. ITSSR establishes and maintains the World Bank Group's IT and InfoSec policies and standards; develops and engineers the WBG's information security plans and solutions; responds to security incidents; and ensures that the information risks are identified, assessed, and managed in consistent with the overall risk management approach and with the established appetite and tolerance.

Duties And Accountabilities
ITSIS is seeking to fill the position of IT Analyst, Security, Risk and Compliance within ISOC. The IT Analyst serves across all areas of threat intelligence to help inform and defend the business and protect brand reputation. As a trusted member of the cybersecurity team and industry community, the analyst works closely with internal technical teams, business units and external entities aligned with the business, including private intelligence-sharing groups, law enforcement, government agencies and public affiliation peers. The IT Analyst is responsible for conducting in-depth research, documenting threats, understanding the risk to the business, and sharing information with those who need to know. The analyst will also distill threat intelligence so technical and non-technical contacts can understand it and make educated decisions about next-step actions. In addition to applied experience, the individual will bring excellent problem solving, communication and teamwork skills, along with agile ways of working, strong business insight, an inclusive leadership attitude and a continuous learning focus.

Note: If the selected candidate is a current Bank Group staff member with a Regular or Open-Ended appointment, s/he will retain his/her Regular or Open-Ended appointment. All others will be offered a 3 year term appointment.

Scope of Work

  • Research current and emerging threats facing the business and industry sector.
  • Lead production and delivery of recurring threat intelligence products including reports, one pager, threat briefs etc.
  • Deliver threat briefings and awareness sessions to internal staff.
  • Conduct and publish in-depth risk assessments to evaluate and categorize the risk posture of detected cyber threats while supporting development and refinement of risk assessment methodologies and tools used for threat categorization
  • Collaborate with internal and external stakeholders, to gather and share relevant threat intelligence.
  • Develop and maintain threat profiles and reports to enhance detection and response capabilities.
  • Continuously update and refine existing threat intelligence processes and methodologies to ensure the organization remains at the forefront of cyber defense.
  • Centralize multiple threat sources (premium, industry-shared, open-source, dark web), correlate indicators and threats, and distill actionable intelligence.
  • Deliver on the digital risk management portfolio covering social media, brand protection etc.Develop and maintain high quality PowerBI dashboards to show coverage and effectiveness.
  • Automate routine tasks for efficient operations and support of the team.
  • Document threats into contextual reports outlining severity, urgency and impact, and ensure they can be understood by both management and technical teams.
  • Participate, implement and maintain deception technology
  • Be readily available to participate in collaborative threat analysis meetings with internal and external trusted entities.
  • Liaison with threat hunting, infrastructure, IT, vulnerability management, threat intelligence and software engineer team members.
  • Understanding of various generative models (e.g., GPT, GANs) and their applications.
  • Plan and execute the implementation of threat management solutions through a data driven and agile approach.
  • Perform other duties as assigned.

Selection Criteria

  • Bachelor's degree in computer science, information technology, systems engineering, or a related field.
  • Minimum 5 years of Information Security experience required with majority of time in a SOC.
  • Strong written and verbal communication skills across all levels of the organization.
  • Maintain a current understanding of advanced persistent threats (APTs), threat actor tactics, techniques, and procedures (TTPs), and cyber threat trends.
  • Applicable knowledge of adversary tactics, techniques and procedures (TTPs), MITRE ATT&ACK framework, CVSS, open source intelligence (OSINT) and deception techniques.
  • Demonstrated ability to investigate, handle and track incidents.
  • Proficient in SIEM, intrusion detection and prevention systems (IDS/IPS), threat intelligence platforms and security orchestration, automation and response (SOAR) solutions to centralize and manage incident and remediation workflow.
  • Ability to analyze incident logs, assess malware, and understand vulnerabilities and exploits, along with strong operating systems knowledge.
  • Experience in incident handling, vulnerability management, hacking tools, intelligence gathering and kill chain methodology.
  • Capable of working with diverse teams and promoting an enterprise-wide positive security culture.
  • Ability to maintain a high level of integrity, trustworthiness and confidence, with the highest level of professionalism.
  • Strong project management, multitasking and organizational skills.
  • Ability to preserve credibility with the team and external constituents through sustained industry knowledge.
  • Ability to motivate teammates to achieve excellence and willingly shares knowledge.
  • Proven experience executing cyber threat hunting, incident response, or other relevant security operations.
  • Familiarity with common enterprise scripting languages (PowerShell, Python, Bash, etc.).
  • Leverage diverse ideas, experiences, thoughts, and perspectives to the benefit of the organization.
  • Excellent problem solving, communication and collaboration skills.
  • Understanding of how operating systems work and how malware exploits them.
  • Past exposure to handle malware and financial crime malware related incidents.
  • Familiarity with industry-standard processes defined for systems design, database design, development, testing, and integration phases of a project, including Agile-based implementations.
  • Experience working in Agile environments, participating in Agile ceremonies, and utilizing Agile methodologies for security operations and threat investigations.
  • Knowledge of common hacking tools and techniques

Preferred Skillsets / Requirements

  • GIAC Certified Incident Handler (GCIH), GIAC Cyber Threat Intelligence (GCTI), GIAC Reverse Engineering Malware Certification (GREM) preferred, but not required.

Competencies

  • Client Understanding and Advising - Looks at issues from the client's perspective and takes action beyond normal expectations to ensure client satisfaction.
  • Learning Orientation - Stays abreast of new trends and developments in own specialty area, the broader industry, and exposes self to increasingly more challenging projects and opportunities to learn.
  • Broad Business Thinking - Maintains an in-depth understanding of the long term implications of decisions both for department and the client's business. Ensures that decisions are supported by relevant stakeholders as well as sound performance data.
  • Compliance with Standards - Monitors and maintains records on requests for information and assistance.
  • Knowledge of Emerging Technology - Tests new technology to evaluate capability compared to specifications.

WBG Culture Attributes

  • Sense of Urgency – Anticipating and quickly reacting to the needs of internal and external stakeholders.
  • Thoughtful Risk Taking – Taking informed and thoughtful risks and making courageous decisions to push boundaries for greater impact.
  • Empowerment and Accountability – Engaging with others in an empowered and accountable manner for impactful results.

World Bank Group Core Competencies

The World Bank Group offers comprehensive benefits, including a retirement plan; medical, life and disability insurance; and paid leave, including parental leave, as well as reasonable accommodations for individuals with disabilities.

We are proud to be an equal opportunity and inclusive employer with a dedicated and committed workforce, and do not discriminate based on gender, gender identity, religion, race, ethnicity, sexual orientation, or disability.

Learn more about working at the
World Bank
and
IFC
, including our values and inspiring stories.



  • Chennai, Tamil Nadu, India World Bank Group Full time ₹ 15,00,000 - ₹ 28,00,000 per year

    IT Analyst, Security, Risk and Compliance Job #: req34310Organization: World BankSector: Information TechnologyGrade: GE Term Duration: 3 years 0 months Recruitment Type: Local RecruitmentLocation: Chennai,IndiaRequired Language(s):Preferred Language(s):Closing Date: 9/24/2025 (MM/DD/YYYY) at 11:59pm UTC DescriptionDo you want to...


  • Chennai, Tamil Nadu, India JR Compliance Full time ₹ 6,00,000 - ₹ 12,00,000 per year

    We are looking for a highly motivated and detail-oriented Jr. Compliance Analyst to join our team at JR Compliance, with 1-2 years of experience in compliance or related fields.Roles and ResponsibilityConduct thorough reviews of compliance documents and records to ensure accuracy and completeness.Develop and implement effective compliance procedures and...


  • Chennai, Tamil Nadu, India beBeeCyberSecurity Full time ₹ 18,00,000 - ₹ 1,98,30,000

    Job Title: Cyber Security Risk Analyst">">Cyber Security is a growing concern for any organisation. As a Cyber Security Risk Analyst, you will be responsible for assessing and managing risks to our IT systems, data, and applications.">">Key Responsibilities:">We are looking for a highly motivated and experienced individual to join our team as a Cyber...

  • Security Risk Manager

    11 hours ago


    Chennai, Tamil Nadu, India beBeeCybersecurity Full time ₹ 1,50,000 - ₹ 28,00,000

    Job Title: Lead Info Security AnalystWe are seeking a skilled and experienced Lead Info Security Analyst to join our team. As a Lead Info Security Analyst, you will play a crucial role in conducting Security Risk Assessments, identifying risks and control gaps, and providing independent assurance to leadership.The ideal candidate will have excellent...


  • Chennai, Tamil Nadu, India Digitalxc Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    Job Summary:We are seeking a detail-oriented and proactive Security Analyst to join our Information Security team. The Security Analyst will be responsible for monitoring, analyzing, and responding to security threats and incidents across the organization's IT infrastructure. This role involves safeguarding company data, identifying vulnerabilities, ensuring...


  • Chennai, Tamil Nadu, India beBeerisk Full time

    Risk Compliance Analysts play a critical role in ensuring organizations remain compliant with regulatory requirements.">A Risk Compliance Analyst analyzes data and develops models to identify potential risks and ensure compliance.This analyst must have strong analytical skills, including the ability to interpret complex data and develop recommendations for...


  • Chennai, Tamil Nadu, India Five-Star Business Finance Limited Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    Key Responsibilities:Assist in updating and maintaining security policies, standards, and procedures to align with compliance requirements.Coordinate with external auditors and internal stakeholders during compliance assessments, audits.Monitor security controls, perform regular assessments, and report compliance status.Track and follow up on Vulnerability...


  • Chennai, Tamil Nadu, India beBeeCybersecurity Full time ₹ 5,00,000 - ₹ 8,00,000

    Job TitleInformation Security Risk SpecialistJob DescriptionThe Information Security Risk Specialist will be responsible for conducting comprehensive risk assessments to identify potential cybersecurity threats and vulnerabilities across infrastructure, data, applications, mobile, and networks. Utilizing security tools and threat modeling techniques, the...

  • Analyst, IT Risk

    4 weeks ago


    Chennai, Tamil Nadu, India Celestica Electronics S Pte Ltd Full time

    Job DescriptionSummaryThe Analyst, IT Risk & Compliance will support their team members in ensuring the IT Controls are working as designed and Compliance is met. The incumbent will manage the IT SOX monitoring activities and respond to any request around control validation and improvements. They are also responsible for providing the assistance to internal...

  • Compliance Analyst

    2 hours ago


    Chennai, Tamil Nadu, India reveleer Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    About ReveleerReveleer is a healthcare data and analytics company that uses Artificial Intelligence to give health plans across all business lines greater control over their Quality Improvement, Risk Adjustment, and Member Management programs. With one transformative solution, the Reveleer platform enables plans to independently execute and manage every...