Job Title: Security Analyst / Architect Location: Mumbai--- [, Hybrid] Department:Enterprise security architect
Role Overview
Responsible for end-to-end security oversight of the enterprise applications, including access governance, architecture validation, IAM support, vulnerability assessment, and coordination with stakeholders across applications, security, cloud, and operations teams.
Key Responsibilities
- Review reports, analyse access gaps, identify excessive privileges, SoD conflicts, and track closure with stakeholders.
- Coordinate with application owners, HR, IT, and auditors; ensure timely review cycles, evidence collection, and reporting.
- Review security architecture, validate data flows, and ensure security controls are properly designed across cloud and on-prem environments.
- Translate business and technical requirements into well-architected security solutions and provide guidance on control implementation.
- Lead or support planning, design, deployment, and documentation of cybersecurity projects aligned with standards and policies.
- Act as SME for IAM/IDAM (SSO, MFA, PAM, identity lifecycle); ensure alignment of application onboarding with identity standards.
- Strengthen cloud and infrastructure security across AWS/Azure/GCP, including perimeter controls (firewalls, WAF) and secure configurations.
- Collaborate with DevOps teams to integrate security practices into CI/CD pipelines and SDLC.
- Conduct vulnerability assessments, threat modelling, and risk analysis; recommend mitigation measures.
- Support incident response investigations and ensure proper containment, root-cause assessment, and recovery.
Required Skills & Qualifications
- 58 years of experience in information security, including access governance, architecture review, and project execution.
- Strong understanding of IAM/IDAM concepts and tools, authentication/authorization models, and privileged access practices.
- Technical proficiency across cloud platforms (AWS/Azure/GCP), network security, SIEM, vulnerability scanners, IDS/IPS, and automation scripting (Python/PowerShell/Bash).
- Familiarity with NIST, ISO 27001, GDPR, HIPAA, and related security frameworks.
- Strong analytical, coordination, communication, and documentation skills, including ability to present technical issues to non-technical stakeholders.
- Bachelor’s degree in IT/Security and preferred certifications (Security+, CISM, AWS/Azure Security).