Lead Information Security Analyst

Nomura

Mumbai

On-site

INR 1,800,000 - 2,400,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nomura is seeking a Lead Information Security Analyst in Mumbai to strengthen governance over third-party cyber risk management. The role blends security, automation, and AI to enhance risk controls and drive secure supplier engagements.

You will coordinate cross-functional assessments, ensure regulatory alignment, and work with legal and technology teams to embed security requirements into contracts and vendor due diligence processes.

Qualifications

  • Deep understanding of regulatory frameworks and compliance requirements.
  • Solid grasp of information security principles and practices.
  • Knowledge of current cyber threats and mitigation strategies.

Responsibilities

  • Maintain governance on TPCRM processes ensuring regional and global compliance.
  • Identify non-compliances in Third Party Cyber Security controls and discuss assessments with stakeholders.
  • Coordinate third party cyber security assessments with various business units and vendors.

Skills

Regulatory compliance
Information security
Cyber threat knowledge
Stakeholder communication
Security standards

Job description

Job Information
  • Job Title: Lead Information Security Analyst
  • Country: IN
  • City: Mumbai
  • Skill Category: ITTechnology
Description

We are seeking a skilled Automation Engineer to join our Information Security team within the Automation AI function. This role combines Python development expertise with modern AI application development to drive intelligent automation initiatives across our security operations. The ideal candidate will bring hands-on experience building web applications, APIs, and AI-powered solutions, and security orchestration playbooks while maintaining a solid understanding of cybersecurity principles. You will work at the intersection of security, automation, and AI to transform how our organization approaches information security challenges.

Responsibilities
  • Maintain strong governance on the third-party cyber risk assessment (TPCRM) process in terms of complying with regional and global requirements.
  • Identify non-compliances in Third Party Cyber Security control landscape and create and discuss the assessment reports with stakeholders.
  • Perform Third Party Cyber Security assessments by coordinating with various business departments and Third Parties.
  • Oversee third party governance across cyber assessment lifcycles including due diligence, reporting, issue remediation and reporting
  • Provide recommendations to the Third Party to remediate identified non-compliances and document remediation plans.
  • Periodically track non-compliances reported to the Third Parties for closure and validate the evidence shared by Third Parties.
  • Ensure periodic reporting on all the open items and completed assessments.
  • Liaise with stakeholders such as business owner, technology owner, legal team etc. to include the Information Security requirements in the contracts with third party vendor
  • Maintain and update inventory of assessments and define re-assessment calendars.
  • Carry out re-assessments based on defined re-assessment calendars.
  • Generate daily/weekly/monthly KRI KPI reports for internal and senior management consumption.
  • Work in a strategic and operational capacity to enhance the Third Party Cyber Security Risk Management process based on various international regulatory requirements and industry best practices.
  • Work with various stakeholders to automate the assessment and risk management process.
Knowledge, Skill, Experience Required
Essential
  • Knowledge of regulatory frameworks and experience with regulatory compliance
  • Familiarity with security standards (e.g., CRI, ISO 27001, NIST)
  • In-depth understanding of information security principles and practices
  • Knowledge of current cyber threats and mitigation strategies
  • Strong collaboration skills along with the ability to effectively communicate complex security-related information to a business audience, including risk identification, assessment, and remediation activity.
  • Excellent communication skills with the ability to articulate complex cyber threat information to technical and non-technical audiences.
  • Demonstrable ability to create and maintain collaborative relationships in a large, multinational organization.
  • Strong understanding of cyber security principles and technologies.
Beneficial
  • Specialist training or skills in one or more of the following:
  • Security certification (CISA/CISM/CISSP/CRISC/ISO-27001 etc.).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Tek Systems • Karnataka

Hybrid
INR 1,400,000 - 2,200,000
Cyber Security Senior Analyst - Third Party Risk Management
Cyber Security Senior Analyst - Third Party Risk Management

V2 Solutions • Bengaluru

On-site
INR 1,100,000 - 1,200,000
AVP Information Security
AVP Information Security

Jain International Trade Organisation - India • Mumbai

On-site
INR 3,000,000 - 4,500,000
AVP Information Security
AVP Information Security

JITO • Mumbai

On-site
INR 4,500,000 - 7,000,000
Lead Information Security Analyst
Lead Information Security Analyst

Nomura Holdings, Inc. • Mumbai

On-site
INR 3,000,000 - 4,500,000
Wellbeing benefits
Inclusive culture
Employee assistance
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
Information Security Analyst
Information Security Analyst

MRO • Pune District

On-site
INR 180,000 - 240,000
Information Security Analyst
Information Security Analyst

ASSA ABLOY Global Solutions • Chennai District

Hybrid
INR 900,000 - 1,500,000
Cyber Automation Engineer
Cyber Automation Engineer

ERM Placement Services • Navi Mumbai

On-site
INR 1,200,000 - 2,400,000
Director, Information Security
Director, Information Security

InvestCloud India • Bengaluru

On-site
INR 7,000,000 - 12,000,000