Cyber Security Risk Analyst

8 hours ago


Gurgaon, Haryana, India Sage Publication Full time ₹ 12,00,000 - ₹ 36,00,000 per year
Job purpose

The purpose of the Cyber Security Risk Analyst is to own the risk assessment lifecycle and lead detailed technical security audits across cloud and om-prem environments. This position will also be responsible for design and execution of IT controls testing, the evaluation of technical controls effectiveness, and for driving remediation with engineering and product teams.

key accountabilities
  • Lead technology and cyber risk assessments, maintaining a risk register with clear impact/likelihood rationales and treatment plans.

  • Map controls to frameworks (ISO/IEC 27001:2022/27002, NIST CSF 2.0, NIST 800‑53, CIS Controls, PCI DSS 4.0) and regulatory obligations (GovRAMP, EU AI Act, GDPR, CCPA).

  • Support policy/standard updates and control design reviews; advise on risk appetite, KRIs, and control maturity targets.

  • Conduct security risk assessments, identifying threats, vulnerabilities, and control gaps.

  • Maintain the security risk register, define treatment plans, and monitor remediation progress.

  • Support quantitative or qualitative risk analysis (e.g., FAIR-lite) for critical assets and processes.

  • Conduct deep dive security reviews, identifying threats, vulnerabilities and control gaps.

  • Plan and execute end-to-end technical audits including scope, testing plans, evidence requests, fieldwork, sampling, walkthroughs, and issue rating.

  • Develop control frameworks for secure software development and execute audits having a good understanding of agile software development practices and security by design principles (DevSecOps).

  • Produce clear, actionable audit reports and present findings to engineering leadership and risk committees.

  • Test design and operating effectiveness of Access Control, Application and Data Security, IT Service Operations, Technology Architecture, Logical and Physical Security.

  • Validate evidence, perform re-performance/inspection, and document results according to audit best practices.

  • Track remediation to closure; verify fixes and update control matrices.

  • Perform third-party risk assessments, reviewing security posture, contractual controls, and data flows.

  • Contribute to AI governance and data protection audits where relevant.

  • Partner with security engineering, IT, data, and product teams to translate requirements into technical controls and pragmatic remediation.

  • Create playbooks, control testing procedures, and knowledge articles; run enablement sessions to raise control maturity.

  • To combine a risk and compliance mindset with strong technical depth in modern enterprise security tooling.

  • Proven experience in cyber security with demonstrable experience in risk assessment and security auditing.

  • Audit and security certifications such as CISA, CISSP, CISM, ISO 27001 Lead Auditor/Implementer or equivalent experience.

  • Strong knowledge of ISO 27001/27002 and NIST CSF, with familiarity across NIST 800‑53, CIS Controls, and SOC 2 or PCI DSS.

  • Hands-on experience assessing Microsoft and Azure security including Entra ID, Defender suite, Sentinel, Intune, Azure Policy, and Purview.

  • Experience with Identity and Access, Cloud Security (Azure, AWS), Data Protection, SecOps, Agile Software Development (DevSecOps), Security by Design.

  • Solid grasp of ITGCs and evidence-based testing methods; excellent audit documentation and reporting skills.

  • Technical literacy across networks, identity, cloud, endpoints, logging/monitoring, and secure configuration.

  • Competence in using GenAI to enhance work practices and have experience in using Agentic AI to automate GRC processes.

  • Ability to develop relationships with key technical position holders across locations and functions

  • Excellent communication skills with the ability to express ideas and messages clearly, both written and verbally

Skills, Qualifications & Experience
  • To combine a risk and compliance mindset with strong technical depth in modern enterprise security tooling.

  • Proven experience in cyber security with demonstrable experience in risk assessment and security auditing.

  • Audit and security certifications such as CISA, CISSP, CISM, ISO 27001 Lead Auditor/Implementer or equivalent experience.

  • Strong knowledge of ISO 27001/27002 and NIST CSF, with familiarity across NIST 800‑53, CIS Controls, and SOC 2 or PCI DSS.

  • Hands-on experience assessing Microsoft and Azure security including Entra ID, Defender suite, Sentinel, Intune, Azure Policy, and Purview.

  • Experience with Identity and Access, Cloud Security (Azure, AWS), Data Protection, SecOps, Agile Software Development (DevSecOps), Security by Design.

  • Solid grasp of ITGCs and evidence-based testing methods; excellent audit documentation and reporting skills.

  • Technical literacy across networks, identity, cloud, endpoints, logging/monitoring, and secure configuration.

  • Competence in using GenAI to enhance work practices and have experience in using Agentic AI to automate GRC processes.

  • Ability to develop relationships with key technical position holders across locations and functions

  • Excellent communication skills with the ability to express ideas and messages clearly, both written and verbally

Diversity, Equity, and Inclusion

At Sage we are committed to building a diverse and inclusive team that is representative of all sections of society and to sustaining a culture that celebrates difference, encourages authenticity, and creates a deep sense of belonging. We welcome applications from all members of society irrespective of age, disability, sex or gender identity, sexual orientation, color, race, nationality, ethnic or national origin, religion or belief as creating value through diversity is what makes us strong.



  • Gurgaon, Haryana, India SAGE Full time ₹ 8,00,000 - ₹ 24,00,000 per year

    Job purpose:The purpose of the Cyber Security Risk Analyst is to own the risk assessment lifecycle and lead detailed technical security audits across cloud and om-prem environments. This position will also be responsible for design and execution of IT controls testing, the evaluation of technical controls effectiveness, and for driving remediation with...


  • Gurgaon, Haryana, India Amor Management Consultants Full time ₹ 1,00,000 - ₹ 3,00,000 per year

    Security Analyst IT & OT Cyber SecurityLevel – Assistant/Deputy ManagerBudget – 15 LPA (Max 30% Hike on current ctc)Location – Gurgaon, Sec-355 Days working , 17 Saturday working in a yearJob Summary:The Security Analyst is responsible for ensuring the security and compliance of IT and OT environments. This includes managing cyber security operations,...

  • Security Analyst

    2 weeks ago


    Gurgaon, Haryana, India Serigor Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Title: Security AnalystLocation: Gurgaon, IndiaType of job: Full-timeTHIS IS NOT A 100% REMOTE ROLE; CANDIDATE MUST BE WILLING TO WORK FROM OFFICE (GURGAON) WHEN REQUIRED About The PositionOur client is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready...


  • Gurgaon, Haryana, India SIS Certifications Full time ₹ 8,00,000 - ₹ 18,00,000 per year

    Job Title: Cyber Security Specialist – Information Security & ISO ImplementationLocation: Gurgaon (Work from Office)Department: Information Security / Audit & ImplementationAbout SIS CertificationsSIS Certifications Pvt. Ltd. is a globally recognized and accredited certification body, operating in more than 50 countrieswith over 10,000 certified...


  • Gurgaon, Haryana, India eSec Forte® Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Experiene:2-5 yearsRole DescriptionThis is a full-time on-site role for a Security Operations Center Analyst located in Gurugram. The Security Operations Center Analyst will be responsible for monitoring and analyzing security events, conducting cyber threat hunting, generating cyber threat intelligence reports, and responding to security incidents. Other...


  • Gurgaon, Haryana, India Max Healthcare Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    Roles and ResponsibilitiesThreat Intelligence and Research:Stay informed about the latest cyber threats, attack techniques, and security technologies.Analyze threat intelligence feeds to identify potential risks to the organization.Proactively recommend security enhancements and adjustments based on threat intelligence.Security Monitoring and Incident...


  • Gurgaon, Haryana, India BT Group Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Security isn't always the first thing that comes to mind when you think of BT, but when it comes to keeping everyone safely connected, We Are The Protectors. We deal with thousands of cyber-attacks every day, so that millions of people can safely go about their daily lives and run their businesses. We deliver vital work at scale, with real breadth and...


  • Gurgaon, Haryana, India Talent Worx Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    SOAR, Cyber SecurityRequirementsQualifications: BE / M.Tech / MSc (IT, Computer Science) / MCA Key Responsibilities: Develop and optimize Security Orchestration, Automation, and Response (SOAR) solutions to enhance organizational security posture. Integrate various security tools and technologies into cohesive systems that support automated response to...


  • Gurgaon, Haryana, India Airtel Full time ₹ 1,20,000 - ₹ 1,80,000 per year

    Information Security Risk Management and Compliance (GRC)Details : JD for Consultant (Information Security Risk & Compliance)POSITION Information Security Risk Management and Compliance (GRC) EXPERIENCE 4-5 Years KEY RESPONSIBILITIES & JOB DESCRIPTIONReview of policy and procedure with implementation across organization In depth knowledge of risk...


  • Gurgaon, Haryana, India Whirlpool Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Role & responsibilitiesPerform Security and Privacy review of existing and new business process and solution implementations.Review product architectures for IT control security design gaps and vulnerabilities and consult with product teams and cyber security to remediate or mitigate cyber risk. Identify IT application end to end security deficiencies and...