Senior Information Security Analyst

Threadneedle group

Hinoba-an

Hybrid

PHP 792,000 - 1,187,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Ameriprise India LLP seeks a Senior Information Security Analyst focused on Identity & Access Governance. You will analyze identity data, assess access against least privilege, identify policy violations, and coordinate remediation with cross-functional teams.

Strong governance judgement and reporting are essential. Responsibilities include coordinating across application owners, IAM delivery, audit, risk, and control partners; producing leadership-ready metrics and evidence-based closure.

Qualifications

  • Bachelor's degree in a technical discipline or equivalent work experience.
  • Experience in governance areas: access reviews, attestations, RBAC, SoD, policy enforcement, privileged-access governance.
  • Hands-on familiarity with at least one IAM/Governance platform such as Aveksa, SailPoint, Saviynt, or CyberArk-based tools.
  • 4–7 years total professional experience, with significant IAM governance exposure.
  • Ability to create/modify SQL, PowerShell, Python, Power BI for data investigation and reporting.
  • Strong written/verbal communication and ability to manage competing priorities.

Responsibilities

  • Analyze identity and access data to assess alignment with least privilege.
  • Identify policy violations and risk, coordinate remediation.
  • Coordinate governance activities across owners, IAM teams, and audit partners.
  • Drive remediation with evidence-based closure and testing.
  • Prepare concise risk summaries and leadership reporting.

Skills

SQL
PowerShell
Python
Power BI
Governance
Stakeholder management

Education

Bachelor's degree in technical field

Tools

RSA Governance & Lifecycle (Aveksa)
SailPoint
Saviynt
Entra ID Governance
IBM Security Verify Governance

Job description

About Our Company Ameriprise India LLP has been providing client based financial solutions to help clients plan and achieve their financial objectives for 20 years. We are part of Ameriprise Financial Inc., a US financial planning company headquartered in Minneapolis with a global presence and diversified financial services leader with more than $1.5 trillion in assets under management, administration and advisement as of year-end 2024. The firm’s focus areas include Asset Management and Advice, Retirement Planning and Insurance Protection. Be part of an inclusive, collaborative culture that rewards you for your contributions, and work with other talented individuals who share your passion for doing great work. You’ll also have plenty of opportunities to make your mark at the office and a difference in your community. So, if you're talented, driven and want to work for a strong, ethical company that cares, take the next step and create a career at Ameriprise India LLP.

Job Description

The Senior Information Security Analyst is an analyst-focused role within Identity & Access Governance (IAG). The role evaluates whether identities, access credentials and permissions are governed in accordance with policy, least-privilege principles and regulatory expectations. The analyst uses data, evidence and platform knowledge to identify access risk, investigate exceptions, challenge ineffective outcomes, coordinate remediation and communicate control health to stakeholders. This is not a pure IAM implementation, platform engineering or operations ticket-processing role. Technical knowledge enables analysis, but success is measured by the quality of governance judgement, follow-through, evidence, reporting and risk reduction.

Responsibilities
  • Analyze identity and access data to determine whether access remains appropriate, approved, timely and aligned to least privilege.
  • Identify control gaps, policy violations, unusual patterns and incomplete outcomes; assess risk and recommend proportionate action.
  • Coordinate governance activities across application owners, business reviewers, IAM delivery teams, infrastructure teams, audit, risk and other control partners.
  • Drive issues through remediation and validate closure using reliable evidence rather than relying only on task or ticket completion.
  • Prepare concise metrics, risk summaries, audit evidence and leadership reporting that explain control health, exceptions, ageing and remediation progress.
  • Contribute to policies, standards, procedures, control design and continuous improvement in response to new risks, technologies and regulatory expectations.
  • Explains the risk and control purpose behind an activity, not only the procedure or tool steps.
  • Uses logical, evidence-based judgement when the documented procedure does not fully address the situation.
  • Demonstrates strong governance judgement in at least one relevant identity domain, with the aptitude to learn adjacent areas.
  • Identifies whether an issue originates from technology, data, process, a policy exception, or a failed control, and recommends action that addresses the underlying risk.
  • Owns assigned issues from identification through follow-up, escalation, documented remediation, and evidence-based closure.
  • Communicates clearly with technical and business stakeholders, including when challenging an incomplete or inappropriate outcome.
  • Identifies recurring themes and proposes proportionate improvements to controls, reporting or process design.
Core Capability Areas
  1. Access Review and Certification

    Govern and facilitate periodic access reviews and certifications, including user, privileged, and application access. Govern identity lifecycle controls, including joiner, mover, and leaver controls; transfer reviews; and termination controls. Govern specialized reviews and remediation activities, including service-account reviews, orphan-account remediation, inactivity reviews, segregation-of-duties monitoring, and role-based access controls. Assess review scope, reviewer appropriateness, decision quality, conflicting decisions, overdue reviews and remediation status. Escalate material risks and recurring non-compliance; verify that access removals and ownership changes are completed. Maintain sufficient, accurate and retrievable evidence for internal and external audit.

  2. Policy Enforcement

    Evaluate adherence to identity, authentication, privileged-access, credential-management and least-privilege requirements. Investigate policy exceptions and non-compliant configurations; coordinate risk assessment, approval, remediation or formal exception handling. Review identity and access implications for new services, cloud IAM entities, privileged accounts and changing technology patterns. Partner with technical teams to translate policy intent into clear, practical security requirements and guardrails.

  3. User Activity Monitoring and Investigation

    Review privileged actions that cannot be linked to an approved business event or change record. Assess business justification, identify potentially inappropriate activity and elevate unresolved or high-risk cases. Monitor the health of event data, alert logic, evidence quality and governance workflows supporting privileged-action monitoring. Prepare investigative and compliance reporting for leadership, audit and risk stakeholders.

Required Qualifications
  • Bachelor's degree in a technical discipline or equivalent relevant work experience.
  • Demonstrated experience in one or more governance areas: access reviews and attestations, JML controls, RBAC, SoD, policy enforcement, privileged-access governance, audit response or access-risk remediation.
  • Hands‑on familiarity with at least one Identity Governance and Administration or Privileged Access Management platform such as RSA Governance & Lifecycle (Aveksa), SailPoint, Saviynt, Entra ID Governance, IBM Security Verify Governance, Idira Identity Security Platform (CyberArk), BeyondTrust, Delinea, Password Manager Pro or a comparable platform.
  • 4–7 years of total professional experience, with at least 50% of that experience in identity and access governance.
  • Experience analyzing access or control data and translating findings into risk, remediation, reporting or stakeholder action.
  • Ability to create and modify SQL, PowerShell, Python, Power BI, spreadsheets or similar tools to investigate data, automate analysis or produce reporting.
  • Effective written and verbal communication, attention to detail, follow‑through and ability to manage competing priorities.
  • Ability to work with stakeholders across onshore and offshore models and operate in a regulated or control‑focused environment.
Preferred Qualifications
  • Experience in financial services or another highly regulated environment.
  • Experience preparing identity and access control evidence or responding to regulatory, financial, technology‑risk, or control audits, such as SOX, SOC, NYDFS, FINRA, SEC, GLBA, or comparable compliance assessments.
  • General audit coordination experience without direct involvement in IAM controls, evidence, findings, or remediation will not by itself meet this requirement.
  • Working knowledge of Active Directory / LDAP, authentication and authorization models, Windows or Linux, databases, cloud security governance, AI security governance, and privileged credentials.
  • Experience with incident/problem/change/request management, business analysis, process flows, User Acceptance Testing, and project coordination.
  • Relevant security certifications (CISSP, CISM, CISA, CRISC, GIAC, other).
In‑Office Collaboration

We are a client‑centric, relationship‑based business. Working together, in‑person, is foundational to how we achieve results. By fostering a culture of face‑to‑face collaboration, idea sharing, productivity and personal connection, we deliver for our stakeholders — clients, advisors, employees and shareholders. Our employees work in the office at least three (3) days per week, with flexibility to work from home two (2) days per week. Some roles may require additional in‑office time or different in‑office expectations, and specific requirements will be discussed during the hiring process.

Work Schedule / Business Unit

Full‑Time/Part‑Time Full time Timings (2:00p-10:30p) India Business Unit AWMPO AWMP&S President's Office Job Family Group Technology

Equal Opportunity Employer

Ameriprise India LLP is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, genetic information, age, sexual orientation, gender identity, disability, military status, veteran status, marital status, pregnancy, family status or any other basis prohibited by law. We are committed to fostering an inclusive and accessible recruitment process for individuals with disabilities. If you require a reasonable accommodation to participate in the application or interview process, speak to your recruiter to discuss how we can support you.

About Our Legacy

Since 1894, Ameriprise Financial has helped people feel more confident about their financial future. Guided by strong values and a deep commitment to clients, we've remained a trusted leader in financial planning and advice for more than 130 years. Through our businesses, Ameriprise Financial, Columbia Threadneedle Investments and RiverSource Insurance & Annuities, we deliver advice, investment and protection solutions designed for long‑term success. While each business brings distinct capabilities and expertise, all are united by our unwavering focus on clients and a strong financial foundation. For you, that means the opportunity to build a meaningful career in a high‑performing, collaborative culture where your expertise can grow, your contributions are valued and your work can make a real impact. As a global financial services company with three complementary businesses, the breadth of our capabilities sets us apart. It also creates unique opportunities for employees to learn, collaborate and grow their careers: Ameriprise Financial: Financial planning, advice and wealth management. Columbia Threadneedle Investments: Global asset management serving individual, institutional and corporate clients. RiverSource Insurance & Annuities: Products and solutions designed to help clients protect and grow their wealth.

Explore Opportunities

Ameriprise US | Careers

Ameriprise India | Careers

Columbia Threadneedle Investments US | Careers

Columbia Threadneedle Investments EMEA APAC | Careers

RiverSource | Careers

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Risk Analyst
Lead Risk Analyst

Threadneedle group • Hinoba-an

Hybrid
PHP 1,187,000 - 1,847,000
Business Systems Analyst-Tech
Business Systems Analyst-Tech

Threadneedle group • Hinoba-an

On-site
PHP 792,000 - 1,187,000
Principal Lead DevOps
Principal Lead DevOps

Threadneedle group • Hinoba-an

On-site
PHP 2,639,000 - 4,618,000
Group Lead - Data and Change Management
Group Lead - Data and Change Management

Threadneedle group • Hinoba-an

Hybrid
PHP 1,187,000 - 1,583,000
Analyst Financial Advisory Support
Analyst Financial Advisory Support

Threadneedle group • Hinoba-an

Hybrid
PHP 396,000 - 792,000
Sr. Manager - Alternative Investments
Sr. Manager - Alternative Investments

Threadneedle group • Hinoba-an

Hybrid
PHP 3,299,000 - 5,937,000
Operational Risk Management Associate
Operational Risk Management Associate

Threadneedle group • Hinoba-an

Hybrid
PHP 594,000 - 858,000
Senior Operational Risk Management Associate
Senior Operational Risk Management Associate

Threadneedle group • Hinoba-an

Hybrid
PHP 792,000 - 990,000
Senior Lead - HR Systems Admin
Senior Lead - HR Systems Admin

Threadneedle group • Hinoba-an

Hybrid
PHP 594,000 - 858,000
Hybrid work model
Senior Salesforce Business Analyst
Senior Salesforce Business Analyst

Threadneedle group • Hinoba-an

On-site
PHP 726,000 - 1,715,000