Cyber Security Lead Analyst

Societe Generale Global Solution Centre

Bengaluru

On-site

INR 1,800,000 - 3,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Societe Generale Global Solution Centre in Bengaluru seeks an Information Security Lead with 6-7 years of experience specializing in GRC, risk management, and operational security. The role requires driving security controls, incident management, and adherence to NIST, ISO 27034, and GDPR standards across SG groups.

Collaborate with application owners and developers to embed security in the SDLC, manage RAF and security exceptions for the Nordics, and deliver security awareness initiatives

Qualifications

  • Experience leading information security governance, risk & compliance (GRC).
  • Hands-on with ASA/SBD assessments and risk awareness delivery.
  • Knowledge of ISO 27001, NIST, CIS and regulatory requirements (GDPR, etc).

Responsibilities

  • Support day-to-day InfoSec operations for a SG customer unit.
  • Perform risk analysis of new processes and solutions with security recommendations.
  • Collaborate with application owners to embed Secure by Design.
  • Ensure compliance with group KRIs and security standards across entities.
  • Manage security incidents in collaboration with global teams.
  • Conduct RAF and exception management workflows.
  • Deliver security awareness programs and campaigns.

Skills

Cybersecurity concepts
Risk management
Audit processes
GRC
Security standards
NIST Barometer
Vulnerability management
Security incident management
RAF management
Policy coordination

Education

CISM
CISSP
ISO 27001

Job description

  • Support the day-to-day operational InfoSec activities for a customer unit, aligned to SG global standards and security policies.
  • Perform risk analysis of new business processes and solutions, providing practical security recommendations.
  • Conduct and support Application Sensitivity Assessments (ASA) and Secure by Design (SBD) evaluations.
  • Collaborate with Application owners to complete Secure by Design (SBD) process prior to production deployment.
  • Support the Entity ISOs and Application Owners & Managers for compliance to meet Group KRIs by providing expertise support, collaborative follow-ups.
  • Ensure adherence to industry standards such as NIST, ISO/IEC 27034, OWASP Top10, etc and regulatory requirements such as GDPR, AAS.
  • Efficient enough to manage NIST Barometer Assessments for NORDICS and to meet Group Target for 2026 .
  • Collaborate with development Teams to embed security best practices into software development life cycle (SDLC)
  • Manage and respond to Information Security Incidents, in collaboration with internal and global teams.
  • Perform RAF (Risk Acceptance Framework) and exception management workflows.
  • Deliver and support security awareness programs, including sessions and campaign planning.
  • Liaise with application, infrastructure, and business teams to drive Infrastructure/Hardening and application security control implementations.

Reference 26000D4O

Responsibilities
  • Support the day-to-day operational InfoSec activities for a customer unit, aligned to SG global standards and security policies.
  • Perform risk analysis of new business processes and solutions, providing practical security recommendations.
  • Conduct and support Application Sensitivity Assessments (ASA) and Secure by Design (SBD) evaluations.
  • Collaborate with Application owners to complete Secure by Design (SBD) process prior to production deployment.
  • Support the Entity ISOs and Application Owners & Managers for compliance to meet Group KRIs by providing expertise support, collaborative follow-ups.
  • Ensure adherence to industry standards such as NIST, ISO/IEC 27034, OWASP Top10, etc and regulatory requirements such as GDPR, AAS.
  • Efficient enough to manage NIST Barometer Assessments for NORDICS and to meet Group Target for 2026 .
  • Collaborate with development Teams to embed security best practices into software development life cycle (SDLC)
  • Manage and respond to Information Security Incidents, in collaboration with internal and global teams.
  • Perform RAF (Risk Acceptance Framework) and exception management workflows.
  • Deliver and support security awareness programs, including sessions and campaign planning.
  • Liaise with application, infrastructure, and business teams to drive Infrastructure/Hardening and application security control implementations.
Required
Profile required
Minimum Qualification:
  • Information Security Lead with 6-7 years of experience in Information Security, with a strong focus on GRC and operational security.
  • Sound understanding of Cybersecurity concepts, application security, foundational security controls, risk management, and audit processes.
  • Strong understanding & Working knowledge of ASA/SBD assessments, TPRM processes, and Risk awareness delivery.
  • Strong understanding & ability to manage security standards/frameworks (e.g., ISO 27001, NIST, CIS).
  • Should own management of NIST Barometer Assessments for NORDICS and drive to reach 2026 Target .
  • Ability to manage security exceptions & RAF Management for NORDICS.
  • Ability to govern Vulnerability Management, Security Incident Management , CERT Alerts etc for NORDICS .
  • Strong analytical and communication skills with the ability to evaluate risk and recommend controls quickly.
  • Identify & evaluate security risks & report appropriately.
  • Coordinate with LOD2 to review/create policies, standards & Procedures.
  • Relevant certifications related to Cybersecurity like CISM, IS027001, CISSP etc is an added advantage.
Why join us

We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Business insight
Environment

At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious.

Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating and taking action are part of our DNA.

If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!

Still hesitating?

You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices and sharing their skills with charities. There are many ways to get involved.

We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Lead Analys
Cyber Security Lead Analys

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 800,000 - 1,500,000
Cyber Security Senior Analyst
Cyber Security Senior Analyst

SGS Société Générale de Surveillance SA • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Security Architect
Security Architect

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 3,000,000 - 4,200,000
Cyber Security Senior Analyst - Pentesting
Cyber Security Senior Analyst - Pentesting

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Lead Systems Engineer - Network Security
Lead Systems Engineer - Network Security

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Expert - Market Risk/PNL
Expert - Market Risk/PNL

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 800,000 - 1,200,000
Specialist Software Engineer - Java
Specialist Software Engineer - Java

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Lead Systems Engineer - Networking
Lead Systems Engineer - Networking

Societe Generale Global Solution Centre • Chennai District

On-site
INR 900,000 - 1,300,000
Lead AI GRC- Cybersecurity- CFU
Lead AI GRC- Cybersecurity- CFU

SGS Société Générale de Surveillance SA • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Auditor - Business Audit
Senior Auditor - Business Audit

Societe Generale Global Solution Centre • Bengaluru

On-site
INR 3,500,000 - 7,000,000