Information Security Analyst
Location: Chennai, India (Hybrid)
Job ID: 48705
Profile Summary
This role is primarily responsible for performing risk assessments, third‑party reviews, internal audit, information security control and system review and design. The successful candidate should have broad information security and risk experience, a high degree of professionalism, a friendly and collaborative demeanor, and strong verbal, written, and organizational skills. This position typically reports to the Manager of Information Security.
Responsibilities
- Support internal and external audit programs, including evidence collection, control validation, issue tracking, and remediation verification.
- Conduct Information Security Management System (ISMS) audits in alignment with standards and frameworks such as ISO 27001, SOC 2, NIST, and applicable regulatory requirements.
- Conduct risk assessments and security due diligence for third‑party vendors, suppliers, and business partners to identify and mitigate cyber, operational, and compliance risks.
- Analyze security, privacy, and regulatory requirements to evaluate risk exposure and recommend appropriate remediation strategies.
- Prepare comprehensive risk assessment reports, dashboards, and executive‑level summaries to support informed business decision‑making.
- Perform control design and effectiveness reviews across business processes, applications, and infrastructure environments.
- Assess new technologies, cloud services, and business initiatives to ensure security and compliance requirements are embedded throughout the lifecycle.
- Partner with application owners, engineering teams, and business stakeholders to identify vulnerabilities, assess risk impact, and drive timely remediation efforts.
- Monitor, analyze, and report on emerging cybersecurity threats, industry trends, regulatory changes, and best practices to enhance organizational resilience.
- Develop and maintain risk metrics, key risk indicators (KRIs), and governance reporting to measure and communicate risk posture.
- Contribute to continuous improvement initiatives by enhancing risk management methodologies, audit processes, and security governance practices.
- Provide subject matter expertise and support for security awareness, compliance initiatives, and cross‑functional risk management activities.
- Perform additional responsibilities and special projects assigned in support of the organization’s security and compliance objectives.
Qualifications
The individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Minimum 3+ years of experience in information security, governance risk and compliance.
Preferred Qualifications
- Minimum 3-5 years of experience in information security risk and compliance.
- Familiarity with ISO 27001, NIST CSF, SOC 2, PCI DSS, CSA STAR and related risk assessment methodologies.
- Knowledge of enterprise network and systems architecture concepts and technologies, including enterprise directory, enterprise integration architecture, and Identity & Access Management.
- Thorough knowledge and understanding of security risk assessment on all information systems such as people, process, technology, and information processing facilities.
- Knowledge of cloud security.
- Prepare risk assessment report and risk treatment plan.
- Conduct information security awareness sessions to end users/middle management.
- Certifications such as ISO 27001, CISA, CISM, CRISC, AWS Security Cloud Certifications are an added advantage.
- Self‑starter and lead the risk analysis in assigned areas with minimum supervision.
- Strong technical background in technical systems/environments.
- Strong written and verbal communication skills.
- Ability to develop good working relationships and excellent interpersonal skills.
- Capable of working independently and as part of a team.
Education and Qualification
- An undergraduate degree in Information Technology, Computer Science, Engineering, or a related field is required, with a preferred graduate degree.
- Demonstrated ability to communicate effectively and professionally in English, both verbally and in writing, across technical and non‑technical audiences.
- Strong analytical and documentation skills, with the ability to interpret and apply technical standards, regulatory requirements, security frameworks, audit reports, and industry publications.
- Ability to translate complex technical concepts into clear, actionable recommendations for business stakeholders and leadership.
- Proficiency in reviewing and understanding security policies, technical specifications, risk assessments, compliance requirements, and industry best practices.
Why apply?
- Empowerment: Work as part of a global team in a flexible work environment, learning and enhancing your expertise. We welcome an opportunity to meet you and learn about your unique talents, skills, and experiences. You don’t need to check all the boxes. If you have most of the skills and experience, we want you to apply.
- Innovation: Embrace challenges and drive change. We are open to ideas, including flexible work arrangements, job sharing or part‑time opportunities.
- Integrity: Results‑oriented, reliable, and straightforward and value being treated accordingly. We want all employees to be themselves, to feel appreciated and accepted.
- Opportunity for flexible working arrangements.
HID is an Equal Opportunity/Affirmative Action Employer – Minority/Female/Disability/Veteran/Gender Identity/Sexual Orientation.