logo
Required Skills
Locked
It Compliance
Locked
It Risk Management
Locked
It Security Management
Locked
Information Security Consulting
Locked
It Audit
Locked
It Risk
Locked
Information Security
Locked
It Risk Assessment

Job Description

Job Summary

We are seeking a motivated and detail-oriented Information Security Analyst with 24 years of experience in information security, risk management, compliance, vulnerability management, and security operations. The ideal candidate will support the organization's information security program by identifying security risks, ensuring compliance with security policies and standards, monitoring security controls, and assisting in the protection of critical business assets and data.

Key Responsibilities

  • Monitor and maintain the organization's information security controls, policies, and procedures.
  • Conduct security risk assessments and identify potential threats, vulnerabilities, and control gaps.
  • Perform vulnerability assessments and coordinate remediation efforts with IT and business teams.
  • Support security audits, compliance reviews, and certification activities.
  • Review and analyze security incidents, investigate findings, and recommend corrective actions.
  • Assist in implementing and monitoring security frameworks, standards, and best practices.
  • Participate in third-party/vendor security assessments and due diligence reviews.
  • Conduct periodic access reviews and support identity and access management (IAM) processes.
  • Monitor security tools and analyze logs to identify suspicious activities and security events.
  • Collaborate with infrastructure, application, cloud, and business teams to strengthen security posture.
  • Assist in developing security awareness programs and conducting employee security training.
  • Maintain security documentation, reports, risk registers, and compliance evidence.
  • Stay updated on emerging cybersecurity threats, vulnerabilities, and regulatory requirements.

Required Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
  • 2–4 years of experience in Information Security, Cybersecurity, IT Security, Risk & Compliance, or Security Operations.
  • Strong understanding of information security principles, controls, and governance practices.
  • Experience with:
    • Risk Assessments
    • Security Audits
    • Vulnerability Management
    • Security Compliance
    • Access Management
    • Security Incident Analysis
  • Knowledge of security frameworks and standards such as:
    • ISO 27001
    • NIST Cybersecurity Framework
    • CIS Controls
    • SOC 2
    • PCI-DSS
    • GDPR (preferred)
  • Familiarity with security technologies including:
    • SIEM Solutions
    • Endpoint Protection Tools
    • Vulnerability Scanners (Nessus, Qualys, Rapid7)
    • Identity and Access Management Solutions
  • Understanding of network, application, cloud, and endpoint security concepts.
  • Strong analytical, documentation, and problem-solving skills.
  • Excellent communication and stakeholder management abilities.

Preferred Skills

  • Experience supporting ISO 27001 implementation, audits, or certification activities.
  • Knowledge of cloud security concepts in AWS, Azure, or GCP environments.
  • Exposure to third-party risk management and vendor security assessments.
  • Basic understanding of security automation and scripting (PowerShell, Python, Bash).
  • Experience with GRC (Governance, Risk, and Compliance) tools.

Preferred Certifications

One or more of the following certifications is desirable:

  • CompTIA Security+
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
  • Certified Information Systems Security Professional (CISSP) – Associate level acceptable
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • Microsoft SC-900 / SC-200
  • Certified Ethical Hacker (CEH)

Key Competencies

  • Information Security Governance
  • Risk Assessment and Management
  • Security Compliance and Audits
  • Vulnerability Management
  • Security Awareness and Training
  • Incident Analysis and Reporting
  • Third-Party Risk Management
  • Policy and Procedure Development
  • Documentation and Reporting
  • Cross-Functional Collaboration

Preferred Candidate Profile

The ideal candidate should possess a strong understanding of information security governance, risk, and compliance requirements while being capable of supporting operational security activities. The role requires the ability to work closely with technical and business stakeholders to ensure the confidentiality, integrity, and availability of organizational information assets.



Salary

3.75-6.5 Lacs PA

Location

Chennai

Job Overview
Job Posted:
1 month ago
Job Type
Full Time, Permanent
Job Role
Security Engineer / Analyst,
Education
UG: Any Graduate
Experience
2-7 Yrs
Total Vacancies
1
Location

Chennai