Information Security Analyst

ASSA ABLOY Global Solutions

Chennai District

On-site

INR 900,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ASSA ABLOY Global Solutions in Chennai is seeking an Information Security Analyst to drive risk assessments, third‑party reviews, and internal audit. You will design and review security controls, partner with engineering and business teams to remediate findings, and monitor evolving threats and compliance requirements.

The role emphasizes collaboration, strong communication, and ongoing security governance.

Qualifications

  • Minimum 3+ years of experience in information security, governance, risk and compliance.
  • Experience conducting ISMS audits and risk assessments.
  • Knowledge of security standards and regulatory requirements.

Responsibilities

  • Support audit programs with evidence collection, control validation, issue tracking, and remediation verification.
  • Conduct ISMS audits aligned with ISO 27001, SOC 2, NIST, and regulatory requirements.
  • Perform risk assessments and third‑party due diligence to identify cyber, operational, and compliance risks.
  • Analyze security, privacy, and regulatory requirements to evaluate risk exposure and remediation needs.
  • Prepare risk reports, dashboards, and executive summaries for decision making.
  • Design and assess control effectiveness across processes, apps, and infrastructure.
  • Evaluate new technologies and cloud services for security and compliance.
  • Collaborate with owners, engineering teams, and stakeholders to remediate vulnerabilities.
  • Monitor threats and regulatory changes to enhance resilience.
  • Develop risk metrics and governance reporting to communicate risk posture.
  • Contribute to continuous improvement of risk management and audit processes.
  • Provide security awareness and compliance support across the organization.
  • Handle additional responsibilities and special projects as needed.

Skills

Information security
Risk management
Audit readiness
Vendor risk management

Education

Undergraduate degree in IT/CS/Engineering
Graduate degree preferred

Tools

ISO 27001
CISA
CISM
CRISC
AWS Security Certifications

Job description

Information Security Analyst

Location: Chennai, India (Hybrid)

Job ID: 48705

Profile Summary

This role is primarily responsible for performing risk assessments, third‑party reviews, internal audit, information security control and system review and design. The successful candidate should have broad information security and risk experience, a high degree of professionalism, a friendly and collaborative demeanor, and strong verbal, written, and organizational skills. This position typically reports to the Manager of Information Security.

Responsibilities
  • Support internal and external audit programs, including evidence collection, control validation, issue tracking, and remediation verification.
  • Conduct Information Security Management System (ISMS) audits in alignment with standards and frameworks such as ISO 27001, SOC 2, NIST, and applicable regulatory requirements.
  • Conduct risk assessments and security due diligence for third‑party vendors, suppliers, and business partners to identify and mitigate cyber, operational, and compliance risks.
  • Analyze security, privacy, and regulatory requirements to evaluate risk exposure and recommend appropriate remediation strategies.
  • Prepare comprehensive risk assessment reports, dashboards, and executive‑level summaries to support informed business decision‑making.
  • Perform control design and effectiveness reviews across business processes, applications, and infrastructure environments.
  • Assess new technologies, cloud services, and business initiatives to ensure security and compliance requirements are embedded throughout the lifecycle.
  • Partner with application owners, engineering teams, and business stakeholders to identify vulnerabilities, assess risk impact, and drive timely remediation efforts.
  • Monitor, analyze, and report on emerging cybersecurity threats, industry trends, regulatory changes, and best practices to enhance organizational resilience.
  • Develop and maintain risk metrics, key risk indicators (KRIs), and governance reporting to measure and communicate risk posture.
  • Contribute to continuous improvement initiatives by enhancing risk management methodologies, audit processes, and security governance practices.
  • Provide subject matter expertise and support for security awareness, compliance initiatives, and cross‑functional risk management activities.
  • Perform additional responsibilities and special projects assigned in support of the organization’s security and compliance objectives.
Qualifications

The individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Minimum 3+ years of experience in information security, governance risk and compliance.

Preferred Qualifications
  • Minimum 3-5 years of experience in information security risk and compliance.
  • Familiarity with ISO 27001, NIST CSF, SOC 2, PCI DSS, CSA STAR and related risk assessment methodologies.
  • Knowledge of enterprise network and systems architecture concepts and technologies, including enterprise directory, enterprise integration architecture, and Identity & Access Management.
  • Thorough knowledge and understanding of security risk assessment on all information systems such as people, process, technology, and information processing facilities.
  • Knowledge of cloud security.
  • Prepare risk assessment report and risk treatment plan.
  • Conduct information security awareness sessions to end users/middle management.
  • Certifications such as ISO 27001, CISA, CISM, CRISC, AWS Security Cloud Certifications are an added advantage.
  • Self‑starter and lead the risk analysis in assigned areas with minimum supervision.
  • Strong technical background in technical systems/environments.
  • Strong written and verbal communication skills.
  • Ability to develop good working relationships and excellent interpersonal skills.
  • Capable of working independently and as part of a team.
Education and Qualification
  • An undergraduate degree in Information Technology, Computer Science, Engineering, or a related field is required, with a preferred graduate degree.
  • Demonstrated ability to communicate effectively and professionally in English, both verbally and in writing, across technical and non‑technical audiences.
  • Strong analytical and documentation skills, with the ability to interpret and apply technical standards, regulatory requirements, security frameworks, audit reports, and industry publications.
  • Ability to translate complex technical concepts into clear, actionable recommendations for business stakeholders and leadership.
  • Proficiency in reviewing and understanding security policies, technical specifications, risk assessments, compliance requirements, and industry best practices.
Why apply?
  • Empowerment: Work as part of a global team in a flexible work environment, learning and enhancing your expertise. We welcome an opportunity to meet you and learn about your unique talents, skills, and experiences. You don’t need to check all the boxes. If you have most of the skills and experience, we want you to apply.
  • Innovation: Embrace challenges and drive change. We are open to ideas, including flexible work arrangements, job sharing or part‑time opportunities.
  • Integrity: Results‑oriented, reliable, and straightforward and value being treated accordingly. We want all employees to be themselves, to feel appreciated and accepted.
  • Opportunity for flexible working arrangements.

HID is an Equal Opportunity/Affirmative Action Employer – Minority/Female/Disability/Veteran/Gender Identity/Sexual Orientation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Record UK Ltd • Chennai District

Hybrid
INR 800,000 - 1,200,000
Senior Associate - IT
Senior Associate - IT

Eurofins • Bengaluru

Hybrid
INR 800,000 - 1,200,000
Information Security and Compliance Analyst
Information Security and Compliance Analyst

Rightpoint • Jaipur Municipal Corporation

Remote
INR 600,000 - 900,000
30 Paid leaves
Public Holidays
Casual and open office environment
+6
Information Security Analyst
Information Security Analyst

HID • Chennai District

On-site
INR 800,000 - 1,200,000
Flexible work arrangements
Training and development opportunities
Diverse and inclusive teams
Manager – Security Infrastructure & Applications
Manager – Security Infrastructure & Applications

inlogic Technologies Pvt. Ltd. • Chennai District

On-site
INR 1,800,000 - 2,400,000
Competitive compensation and benefits package
Flexible work arrangements
Professional development opportunities
Security Analyst (Cyber Defense Analyst)
Security Analyst (Cyber Defense Analyst)

Jobgether • India

On-site
INR 1,700,000 - 2,400,000
Health insurance
Paid time off
Flexible work
+6
Information Security and Compliance Analyst
Information Security and Compliance Analyst

Genpact • Jaipur

Hybrid
INR 800,000 - 1,200,000
30 Paid leaves
Family medical insurance
Flexible Work Schedule
+2
Senior Information Security Analyst
Senior Information Security Analyst

Threadneedle group • Gurugram District

On-site
INR 2,500,000 - 3,800,000
IT Compliance Lead
IT Compliance Lead

Mobileum • Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
India: Governance, Risk & Compliance Analyst
India: Governance, Risk & Compliance Analyst

H&P • Dadri

On-site
INR 600,000 - 800,000