IT Security Business Analyst

NTT DATA Europe & Latam

Emilia-Romagna

In loco

EUR 60.000 - 90.000

Tempo pieno

38 ore fa
Candidati tra i primi
Generatore di candidature

Trasforma questa candidatura in un colloquio — un curriculum e una lettera di presentazione creati in base a ciò questo datore di lavoro sta cercando.

Supera i filtri ATS

Descrizione del lavoro

NTT DATA Romania’s Agile Transformation Office is seeking an IT Security Business Analyst to join a strategic insurance project. You will analyze secrets management, security requirements and governance across enterprise systems.

You will document findings, define functional and non-functional needs, and support risk assessments, controls, and remediation planning; strong English communication is essential.

Competenze

  • Bachelor's degree in Informatics or similar field required.
  • Experience in IT security analysis, security requirements engineering or governance in complex environments.
  • Knowledge of secrets types (passwords, SSH keys, API keys, tokens, certificates).
  • Experience translating findings into implementable security requirements.
  • Strong English communication and documentation skills.

Mansioni

  • Conduct end-to-end analysis of secret and credential management across applications, infra, platforms, and processes.
  • Identify, classify and document secrets management details including ownership, storage, and access.
  • Assess control weaknesses and propose remediation to tighten security and auditability.
  • Define functional and non-functional requirements for centralized secrets management.
  • Support lifecycle processes for secret creation, storage, access, rotation, and decommissioning.
  • Prepare security analysis deliverables and risk assessments for governance.

Conoscenze

IT security analysis
Security requirements engineering
Control assessment
Security governance
IAM/PAM/least privilege
Stakeholder facilitation

Formazione

Bachelor's degree in Informatics or related field

Strumenti

CyberArk
HashiCorp Vault
Azure Key Vault
AWS Secrets Manager
GCP Secret Manager

Descrizione del lavoro

Who We Are

We believe that clarity turns complexity into meaningful outcomes. We are a department within NTT DATA Romania, known as the Agile Transformation Office, your gateway to creating real impact in software projects by keeping the focus on value and alignment.

Who We Are

We believe that clarity turns complexity into meaningful outcomes. We are a department within NTT DATA Romania, known as the Agile Transformation Office, your gateway to creating real impact in software projects by keeping the focus on value and alignment. If you can bridge business and technology, translating needs into solutions and ensuring team alignment, we look forward to your application for the IT Security Business Analyst role. We are looking for candidates to join a strategic project within the insurance sector, focused on developing and enhancing enterprise software solutions and integrations.

What You’ll Be Doing
  • Conduct end-to-end analysis of existing secret and credential management practices across applications, infrastructure, platforms and operational processes.
  • Identify, classify and document technical and workforce secrets, including ownership, usage, storage location, criticality, lifecycle stage, access model and associated risks.
  • Assess current-state control weaknesses such as unmanaged SSH keys, hardcoded credentials, shared accounts, undocumented secret usage, insufficient rotation and weak auditability.
  • Define and document detailed functional and non-functional requirements for centralized secrets management capabilities.
  • Support the design of compliant lifecycle processes for creation, storage, access, usage, rotation, revocation, emergency access and decommissioning of secrets.
  • Analyze dependencies across systems, applications, service accounts, technical users and operational teams to support onboarding and migration planning.
  • Prepare clear and defensible security analysis deliverables, including gap assessments, process documentation, risk assessments, control requirements and remediation recommendations.
  • Facilitate and document workshops with technical, operational and business stakeholders to gather requirements, validate findings and resolve ambiguities.
  • Contribute to tool evaluation activities by translating operational and security needs into concrete assessment criteria and use cases.
  • Validate whether proposed solution approaches meet defined security, compliance and operational expectations.
  • Support reporting and governance activities by maintaining traceability of findings, risks, requirements, remediation items and implementation dependencies.
  • Ensure analysis outputs are audit-ready, internally consistent and suitable for decision-making at project and stakeholder governance level.
What You'll Bring Along
  • Bachelor's degree in Informatics or similar field of study or equivalent working experience is required
  • Strong experience in IT security analysis, security requirements engineering, control assessment or security governance in complex enterprise environments.
  • Proven knowledge of secrets and credential types, including passwords, SSH keys, API keys, tokens, certificates, service accounts and privileged credentials.
  • Experience in analyzing IT processes, identifying control gaps and translating findings into implementable security requirements.
  • Strong understanding of IAM, PAM, least privilege, segregation of duties, auditability and secure access governance.
  • Ability to work across technical and non-technical stakeholder groups and drive structured analysis in ambiguous environments.
  • Experience in regulated, global or highly controlled environments.
  • Experience with CyberArk, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager or similar platforms.
  • Knowledge of ISO 27001, NIST, CIS Controls or enterprise security governance frameworks.
  • Experience in transformation or migration projects involving credential centralization and legacy cleanup.
  • Strong documentation, workshop facilitation and communication skills in English.
  • Excellent command of both spoken and written English.
Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

IT Security Business Analyst: Secrets & Access Governance
IT Security Business Analyst: Secrets & Access Governance

NTT DATA Europe & Latam • Emilia-Romagna

In loco
EUR 60.000 - 90.000
Security by Design Engineer
Security by Design Engineer

TeamSystem • Roma

In loco
EUR 49.000 - 63.000
Hybrid work model
Learning paths and growth
Senior .NET Developer Lead (IAM / IGA)
Senior .NET Developer Lead (IAM / IGA)

NTT DATA Europe & Latam • Emilia-Romagna

In loco
EUR 70.000 - 110.000
Cyber Security Specialist
Cyber Security Specialist

Volkswagen Group Italia S.p.A. • Verona

Ibrido
EUR 48.000 - 56.000
Remote work up to 8 days/mo
Bonuses based on performance
Cafeteria and meal options
+1
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

Integrity360 • Italia

In loco
EUR 65.000 - 90.000
Cybersecurity Compliance Specialist
Cybersecurity Compliance Specialist

MEERAB GROUP • Agrate Brianza

In loco
EUR 40.000 - 65.000
Security by Design Engineer
Security by Design Engineer

TeamSystem • Milano

Ibrido
EUR 49.000 - 63.000
Total compensation
Wellbeing budget
Hybrid model
+3
Cyber Security Specialist
Cyber Security Specialist

Avvale • Turbigo

Ibrido
EUR 40.000 - 70.000
Flexibility in remote working
Training & development budget
Commitment to gender equality & inclusion
Cyber Security Functional Analyst
Cyber Security Functional Analyst

Aizoon • Bologna

In loco
EUR 50.000 - 65.000
Competitive salary
Bonuses based on performance
Welfare incentives
+1
Junior Consultant, Technology Risk
Junior Consultant, Technology Risk

Jobtailor • Catania

In loco
EUR 40.000 - 60.000