- Information Security Analyst , Third party risk assessment, vendor risk assessment ,Cyber Security
- ISO 27001, GDPR , HIPAA, NIST, COBIT SOC II
- Stakeholder management, Documentation , Monitoring
About the Role
We are seeking a Senior Analyst (Individual Contributor) in the area of Cyber Security for the Third Party Cyber Security Evaluations team. The role activities include assessing, testing, monitoring, and reporting on the adequacy, efficiency, and effectiveness of information security related controls for third party.
Location : Hyderabad/ Bangalore
Work Mode: Hybrid
Shift timing: 1:30 PM to 10:30 PM
Key Responsibilities
- Work and collaborate with third party service providers to assess information security risk in IT infrastructures, applications, and information security programs of varying sizes and complexities.
- Execute remote security assessments via questionnaires, as needed, and complete associated reports, and security plans.
- Review/analyze third party attestation and certification artifacts (SOC2, SIG, PCI DSS, Etc.) shared by third parties to identify the information security risks
- Document assessment results and write assessment report(s) for key stakeholders in conjunction with the Information Security Risk Assessment Program.
- Provide subject matter expertise in the Third Party information security program and provide timely solutions to identified problems
- Work independently as the Third Party Assessment lead. Collaborate with the senior leader - Third Party Assessment management; US and internal stakeholders
- Analyze the data related to information security findings and present meaningful views to relevant stakeholders on the trends and patterns of control gaps.
- Manage different intake request scenarios to close the assessments within the stipulated timeframe.
Required Qualifications
- 6+ years of experience working in Information Security Governance Risk and Compliance
- 3+ years of experience working in Third Party Information Security Assessment or Cyber Security Assessments
- Bachelor’s and/or Master’s degree in Computer Science or Information Systems
- Knowledge of security frameworks and regulations such as ISO 27001/27002, PCI DSS, COBIT, NIST, GLBA, GDPR
- Superior attention to detail with excellent written and verbal communication skills.
- Expertise in writing technical reports.
- Demonstrated critical thinking and analytical skills.
- Strong understanding of information security domains and possesses a well-rounded technical background. Knowledge of operational risk, IT processes and systems
- Comfortable with making and presenting recommendations to a wide audience of stakeholders
Desired Qualifications
- Demonstrated experience in stakeholder management
- Demonstrated experience of conflict resolution, negotiation and problem identification and solving skills.
- Demonstrated experience in managing complex projects related to information security
- Knowledge of operational risk, IT processes and systems
- Advanced MS SharePoint and Microsoft office skills