Padmi

Senior Info Security Analyst

Delhi NCRPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at FM

Opens the source posting on shine.com

Source description

About the role

View original

You will be working as a Senior Information Security Analyst at FM, focusing on Third-Party Risk Management (TPRM) and Security Controls Testing. Your role will involve assessing risks across external vendors, SaaS platforms, cloud solutions, and internal control environments to safeguard FM's systems and data. You will collaborate with various stakeholders to identify risks, assess control effectiveness, and recommend mitigation strategies. Key Responsibilities: - Lead end-to-end third-party risk assessments and security control testing activities. - Independently validate control design and operating effectiveness across internal systems and external vendors. - Evaluate vendor security programs, governance, and control environments. - Assess solution architecture, cloud environments, data flows, and integration points. - Identify and communicate cyber risks related to data protection, identity & access management, and system connectivity. - Review security documentation and execute control testing procedures. - Document findings clearly, including control gaps and improvement opportunities. - Recommend practical risk mitigation strategies and support remediation tracking. - Partner with various teams to support risk acceptance and governance activities. Skills and Experience: Technical: - 2-4 years of experience in cybersecurity, information security, or cyber risk. - Knowledge of operating systems, networks, databases, and application development. - Understanding of IT General Controls (ITGCs) and security frameworks like NIST CSF and ISO 27001. Soft Skills: - Strong communication skills, both verbal and written. - Interpersonal skills to work across different stakeholders. - Ability to manage multiple priorities and attention to detail. Must Have Skills: Third-Party: - Experience in Third-Party Security Assessment and Vendor Control Evaluation. - Reviewing SOC 1/SOC 2 reports and ISO certifications. - Understanding of third-party solutions integration risks. - Ability to identify and communicate vendor-related risks. - Effective coordination with procurement, legal, business, and technology teams. Education and Certifications: - A bachelors degree is required. - Preferred certifications: CISA, CISM, CISSP. This role is based in Bengaluru. You will be working as a Senior Information Security Analyst at FM, focusing on Third-Party Risk Management (TPRM) and Security Controls Testing. Your role will involve assessing risks across external vendors, SaaS platforms, cloud solutions, and internal control environments to safeguard FM's systems and data. You will collaborate with various stakeholders to identify risks, assess control effectiveness, and recommend mitigation strategies. Key Responsibilities: - Lead end-to-end third-party risk assessments and security control testing activities. - Independently validate control design and operating effectiveness across internal systems and external vendors. - Evaluate vendor security programs, governance, and control environments. - Assess solution architecture, cloud environments, data flows, and integration points. - Identify and communicate cyber risks related to data protection, identity & access management, and system connectivity. - Review security documentation and execute control testing procedures. - Document findings clearly, including control gaps and improvement opportunities. - Recommend practical risk mitigation strategies and support remediation tracking. - Partner with various teams to support risk acceptance and governance activities. Skills and Experience: Technical: - 2-4 years of experience in cybersecurity, information security, or cyber risk. - Knowledge of operating systems, networks, databases, and application development. - Understanding of IT General Controls (ITGCs) and security frameworks like NIST CSF and ISO 27001. Soft Skills: - Strong communication skills, both verbal and written. - Interpersonal skills to work across different stakeholders. - Ability to manage multiple priorities and attention to detail. Must Have Skills: Third-Party: - Experience in Third-Party Security Assessment and Vendor Control Evaluation. - Reviewing SOC 1/SOC 2 reports and ISO certifications. - Understanding of third-party solutions integration risks. - Ability to identify and communicate vendor-related risks. - Effective coordination with procurement, legal, business, and technology teams. Education and Certifications: - A bachelors degree is required. - Preferred certifications: CISA, CISM, CISSP. This role is based in Bengaluru.

One address, no account. We’ll tell you when matching roles go live.

More at FM

Related open roles

View all roles