Source description
About the role
Who are we At Finastra, were a global leader in financial services software, dedicated to expanding access to financial services and shaping whats next for the industry. Our technology powers missioncritical solutions across Lending, Payments and Universal Banking, supporting over 7,000 customers, including 80% of the worlds top 50 banks, in more than 110 countries. Role OverviewThis role serves as the operational foundation for cybersecurity assurance activities across the organisation. As a Cyber Security Assurance Analyst, you will maintain the documentation, evidence repositories, control mappings, and governance records that demonstrate how cybersecurity controls satisfy business, customer, regulatory, and industry requirements. You will work closely with control owners to ensure documentation and evidence remain accurate, current, and readily available when needed. Success in this role comes from creating structure, maintaining high-quality records, understanding how controls satisfy requirements, and enabling rapid, defensible responses to assurance and compliance requests. What You Will Do Control Assurance & Compliance ReadinessUnderstand how cybersecurity controls satisfy requirements and maintain evidence demonstrating control effectivenessEnsure traceability between requirements, policies, standards, controls, procedures, and evidence artifactsIdentify documentation gaps, stale evidence, and control assurance improvement opportunitiesSupport continuous compliance initiatives and control governance activities Evidence & Knowledge Management Maintain centralized repositories for cybersecurity evidence, assessment responses, and assurance documentationDevelop reusable artifacts that enable rapid responses to audit, customer, and compliance requestsPartner with control owners to ensure documentation and evidence remain current and accurateMaintain audit-defensible records that demonstrate control effectiveness and compliance Governance Reporting & Improvement Track and report on assurance activities, compliance initiatives, and control health metricsSupport framework mapping activities across regulatory, customer, and industry requirementsIdentify recurring issues, inefficiencies, and opportunities to simplify assurance processesContribute to governance dashboards, reporting, and continuous improvement initiatives What Success Looks Like Evidence, control records, and assurance documentation remain current, organized, and readily accessibleMost information requests can be satisfied using existing documentation, evidence repositories, and reusable assurance artifacts with minimal rework from control ownersControl compliance evidence can be located, validated, and provided quickly without extensive investigation or stakeholder coordinationAssurance activities become increasingly standardized, repeatable, and scalable, reducing administrative effort for control owners and assurance teamsRequired Skills and Experience : 4+ YearExperience supporting cybersecurity compliance, assurance, governance, control management, or related activities, with an understanding of how controls, evidence, and documentation satisfy cybersecurity and compliance requirements Experience maintaining documentation, evidence repositories, control records, requirements traceability, or other compliance and assurance artifacts Strong organizational, analytical, and communication skills, with exceptional attention to detail and the ability to manage multiple priorities and deadlines simultaneously Ability to work independently, drive activities to completion through stakeholder engagement, and maintain accountability for deliverables in a fast-paced environment Preferred QualificationsBachelor's degree or equivalent practical experience 3+ Years, Experience with cybersecurity frameworks such as NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, or PCI DSS 3+Years ,Experience supporting customer assurance requests, audits, assessments, or regulatory reviews Relevant certifications such as CISM, CRISC, CGRC, or similar are considered an asset Who This Role Is For This role is a strong fit for individuals who: Enjoy organizing information, documentation, and complex requirementsNaturally create structure, consistency, and repeatable processesTake pride in producing accurate, defensible work productsAre comfortable becoming a subject matter expert in controls, evidence, and compliance requirementsCan balance detailed operational work with continuous improvement initiatives Who This Role Is Not For This role may not be a good fit for: Individuals seeking hands-on engineering, security operations, threat hunting, or penetration testing workIndividuals who become frustrated maintaining documentation, evidence repositories, or requirements traceabilityIndividuals who prefer building technology rather than governing and assuring itIndividuals seeking a purely technical cybersecurity role We Who
More at Finastra
Related open roles
Senior Enterprise ETL & Data Warehouse Developer
Bangalore
Expert AI Security Engineer AppSec (Pune)
Mumbai
Expert AI Security Engineer AppSec (Bengaluru)
Bangalore
Expert Cyber Security Assurance Analyst
Mumbai
Expert Security Engineer - Offensive Security
Bangalore
Principal DevSecOps Engineer - AI
Bangalore