Source description
About the role
As an Information Security Analyst at Smarsh, your role involves evaluating the cybersecurity and third-party risk posture of clients within highly regulated industries. Utilizing advanced Vendor Risk Management (VRM) and Cybersecurity Compliance platforms, you ensure that vendor environments meet rigorous security standards. Your primary responsibilities include: - Strategic Risk Advisory: - Review vendor risk by evaluating security assessments and documentation. - Deliver actionable recommendations to strengthen client risk postures. - Technical Security Assessments: - Conduct comprehensive vulnerability scans and penetration tests for clients using industry-leading security tools. - Vulnerability Reporting: - Produce detailed technical reports categorizing vulnerabilities and providing remediation strategies for clients. - Client Relationship Management: - Serve as a subject matter expert and primary point of contact for clients. - Guide clients through platform features and cybersecurity best practices via phone and email. - Operational Leadership: - Manage regular client engagements and deliver high-quality due diligence reports. - Contribute to the continuous improvement of Smarsh VRM team operations. Requirements & Qualifications: - Experience & Certifications: - 35 years of professional experience in Vendor Risk Management or Information Security. - Relevant industry certifications such as CTPRP, CISA, CISM, or CRISC are highly desirable. - Technical Proficiency: - Familiarity with security tools like Nessus, Metasploit, or Cobalt Strike. - Strong understanding of TCP/IP networking, server administration, and cybersecurity controls. - Proficiency in Salesforce CRM, Microsoft Office Suite, and MS Teams. - AI Usage & Innovation: - Ability to use AI tools to automate tasks like data mapping and report drafting. - Utilize and recommend enhancements to AI review tools for automating data extraction. - Collaborate with product teams to refine AI prompts and workflows. - Professional Skills: - Proven ability in risk analysis and reviewing security assessments. - Exceptional written and verbal communication skills. - Project management skills for handling multiple workstreams under deadlines. - Self-directed and motivated to work independently while maintaining high standards. The company Smarsh values lifelong learners who innovate with purpose, humility, and humor. Collaboration is central to their culture, working closely with popular communications and cloud infrastructure platforms, and leveraging AI/ML technology for customer solutions. Diversity is valued, and opportunities for being authentic are encouraged. Smarsh's leadership, culture, and commitment to employee development have earned accolades as one of the Best Places to Work. Join Smarsh to experience the best work of your career. As an Information Security Analyst at Smarsh, your role involves evaluating the cybersecurity and third-party risk posture of clients within highly regulated industries. Utilizing advanced Vendor Risk Management (VRM) and Cybersecurity Compliance platforms, you ensure that vendor environments meet rigorous security standards. Your primary responsibilities include: - Strategic Risk Advisory: - Review vendor risk by evaluating security assessments and documentation. - Deliver actionable recommendations to strengthen client risk postures. - Technical Security Assessments: - Conduct comprehensive vulnerability scans and penetration tests for clients using industry-leading security tools. - Vulnerability Reporting: - Produce detailed technical reports categorizing vulnerabilities and providing remediation strategies for clients. - Client Relationship Management: - Serve as a subject matter expert and primary point of contact for clients. - Guide clients through platform features and cybersecurity best practices via phone and email. - Operational Leadership: - Manage regular client engagements and deliver high-quality due diligence reports. - Contribute to the continuous improvement of Smarsh VRM team operations. Requirements & Qualifications: - Experience & Certifications: - 35 years of professional experience in Vendor Risk Management or Information Security. - Relevant industry certifications such as CTPRP, CISA, CISM, or CRISC are highly desirable. - Technical Proficiency: - Familiarity with security tools like Nessus, Metasploit, or Cobalt Strike. - Strong understanding of TCP/IP networking, server administration, and cybersecurity controls. - Proficiency in Salesforce CRM, Microsoft Office Suite, and MS Teams. - AI Usage & Innovation: - Ability to use AI tools to automate tasks like data mapping and report drafting. - Utilize and recommend enhancements to AI review tools for automating data extraction. - Collaborate with product teams to refine AI prompts and workflows. - Professional Skills: - Proven ability in risk analys
More at Smarsh
Related open roles
Information Security Analyst (Vendor Risk & Cyber Compliance) (Bengaluru)
Bangalore
Governance, Risk & Compliance - Lead
Bangalore
Sr. Security Operations Analyst
Bangalore
Sr. Security Operations Analyst
Bangalore · Hybrid
Governance, Risk & Compliance - Lead
Bangalore · Hybrid
Lead Security Operations Analyst
Bangalore
