
Cybersecurity & GRC Analyst
- Bangalore, Karnataka
- Permanent
- Full-time
- Position is based in Bangalore Office, INDIA.
- Strong hands-on experience in security tools like Crowdstrike EDR,ITP, SAOR Fusion, API integrations etc. and continuously fine tune policies to improve overall proception capabilities and posture.
- Experienced in SIEM platforms, Cisco IronPort, Cisco Umbrella, Cisco Secure Endpoint, Crowdstrike, Forcepoint DLP.
- Good experience in working/communicating with cross-functional IT infrastructure teams like network, system, database, application, security to build and manage effective security operations.
- Exposure to using frameworks and compliances like MITRE ATT&CK. CIS Critical Controls, OWASP, SOC2, ISO 27001 etc.
- Ability to work with internal / external Audit teams and represent organizational responses
- Exposure to related areas of cybersecurity including Host Security, Network Security, IAM, Vulnerability Management, DLP, Penetration Testing, Compliance etc.
- Deep dive analysis of triggered alerts using various security solutions.
- Good understanding of various SOC processes like monitoring, analysis, playbooks, escalation, incident documentation, SLAs, client meetings, BCP, report creation and ability to explain.
- Perform root case analysis of incidents/breaches and maintain compliance to global data privacy laws like GDPR etc.
- Maintain up-to-date documentation of designs/configurations
- Key IT- GRC Responsibilities:
- Risk Assessment and Management: Identify, assess, and prioritize IT-related risks, developing mitigation strategies.
- Compliance Management: Ensure adherence to relevant regulations, industry standards, and internal policies. E.g. GDPR, CCPA, ISO 270001, SOC2.
- Policy Development and Implementation: Create and maintain IT governance policies and procedures.
- Audit Management, tracking and Reporting: Conduct internal audits, document findings, and prepare reports for management and stakeholders.
- Collaboration: Work with IT, security, and other business teams to implement and maintain GRC programs.
- Staying Current: Keep abreast of evolving regulations, industry best practices, and emerging technologies, continuous controls evaluation, mapping to standards and improvement, evaluating existing IT general and entity level controls and improving them.
- Skills and Qualifications:
- Technical Skills: Understanding of IT systems, networks, and security technologies.
- Analytical Skills: Ability to analyze data, identify trends, and make recommendations.
- Communication Skills: Ability to explain complex technical concepts to non-technical audiences.
- Problem-Solving Skills: Ability to identify and resolve issues related to compliance and risk.
- Certifications:
- Ability to fluently communicate in English with local and international users
- Ability to communicate effectively with peers and management
- Having the Ability to critically think and problem solve a given situation /challenge
- Ability to collaborate with peers and team members within and outside security function and the large organizational teams.
- Ability to logically reason out and question and improve posture and control positions
- Being proactive and self-driven
- 5Years (Min) - 8 Years experience required,
- Bachelor's degree in computer science, information science or related field
- certification include (at least 1 min preferred): CISSP , CISM, CISA , CRISC , Security+, GIAC, GSEC, GCIA, GCFA, GCTI r similar equivalent certifications.