Job Information
- Job Title: Lead Information Security Analyst
- Country: IN
- City: Mumbai
- Skill Category: ITTechnology
Description
We are seeking a skilled Automation Engineer to join our Information Security team within the Automation AI function. This role combines Python development expertise with modern AI application development to drive intelligent automation initiatives across our security operations. The ideal candidate will bring hands-on experience building web applications, APIs, and AI-powered solutions, and security orchestration playbooks while maintaining a solid understanding of cybersecurity principles. You will work at the intersection of security, automation, and AI to transform how our organization approaches information security challenges.
Responsibilities
- Maintain strong governance on the third-party cyber risk assessment (TPCRM) process in terms of complying with regional and global requirements.
- Identify non-compliances in Third Party Cyber Security control landscape and create and discuss the assessment reports with stakeholders.
- Perform Third Party Cyber Security assessments by coordinating with various business departments and Third Parties.
- Oversee third party governance across cyber assessment lifcycles including due diligence, reporting, issue remediation and reporting
- Provide recommendations to the Third Party to remediate identified non-compliances and document remediation plans.
- Periodically track non-compliances reported to the Third Parties for closure and validate the evidence shared by Third Parties.
- Ensure periodic reporting on all the open items and completed assessments.
- Liaise with stakeholders such as business owner, technology owner, legal team etc. to include the Information Security requirements in the contracts with third party vendor
- Maintain and update inventory of assessments and define re-assessment calendars.
- Carry out re-assessments based on defined re-assessment calendars.
- Generate daily/weekly/monthly KRI KPI reports for internal and senior management consumption.
- Work in a strategic and operational capacity to enhance the Third Party Cyber Security Risk Management process based on various international regulatory requirements and industry best practices.
- Work with various stakeholders to automate the assessment and risk management process.
Knowledge, Skill, Experience Required
Essential
- Knowledge of regulatory frameworks and experience with regulatory compliance
- Familiarity with security standards (e.g., CRI, ISO 27001, NIST)
- In-depth understanding of information security principles and practices
- Knowledge of current cyber threats and mitigation strategies
- Strong collaboration skills along with the ability to effectively communicate complex security-related information to a business audience, including risk identification, assessment, and remediation activity.
- Excellent communication skills with the ability to articulate complex cyber threat information to technical and non-technical audiences.
- Demonstrable ability to create and maintain collaborative relationships in a large, multinational organization.
- Strong understanding of cyber security principles and technologies.
Beneficial
- Specialist training or skills in one or more of the following:
- Security certification (CISA/CISM/CISSP/CRISC/ISO-27001 etc.).