Home/Job List/Sr. Information Security Analyst, GRC

Sr. Information Security Analyst, GRC

300 US Lab

Maharashtra, India
Full-Time
Posted 1 month ago

Job Description & Responsibilities

The Senior Information Security GRC Analyst reports to the Information Security GRC Manager and plays a critical role in supporting the Information Security program across key areas including information security risk management, third-party risk management, information security policy governance, operational risk reporting and analytics, and security and privacy awareness.

This role is a senior individual contributor responsible for executing and continuously improving information security risk management processes. The position partners closely with Information Security, Privacy, IT, and business stakeholders to identify, assess, document, and monitor information security risks across the enterprise.

Essential Duties

Information Security Risk Management

  • Participate in enterprise and program-level initiatives aligned with Information Security goals and objectives.
  • Support the maintenance and continuous improvement of the information security risk management framework, program guidelines, and standard operating procedures.
  • Conduct information security risk and control assessments across technical environments, business processes, and third parties.
  • Document identified control gaps and associated risks from both technical and business perspectives.
  • Perform gap assessments against regulatory requirements, external standards, and internal security policies.
  • Partner with Information Security, Privacy, IT, and business stakeholders to support risk prioritization and remediation planning.
  • Support the security and privacy awareness and training program, including tracking participation and effectiveness metrics.
  • Conduct third-party risk assessments and collaborate with internal stakeholders and vendors to identify, document, and track risk treatment plans.
  • Support contract reviews by providing information security and third-party risk input.

________________________________________

Information Security Policy Governance

  • Maintain enterprise information security policies, standards, and supporting documentation.
  • Review and assess requested policy exceptions or violations and document associated risks.
  • Provide guidance on policy interpretation and implementation to internal stakeholders.

________________________________________

Reporting and Metrics

  • Develop and maintain information security risk and compliance metrics.
  • Support the preparation of regular risk and compliance reports for senior leadership.
  • Identify trends, emerging risks, and control weaknesses through analysis of metrics and assessment results.

Competencies

Knowledge

  • Strong understanding of information security frameworks such as ISO 27001/27002, ISMS, SOC1&2 and NIST Cybersecurity Framework (CSF), with hands-on experience supporting implementation or audits.
  • Working knowledge of information security risks related to enterprise information assets and intellectual property.
  • Understanding of integrated IT and physical security risk concepts.
  • Experience working in risk management environments involving information security, privacy, records management, or eDiscovery.
  • Understanding and knowledge of IT General controls across multiple audit and compliance frameworks
  • Foundational understanding of security technologies and architectures, including network security, identity and access management, encryption, application security, vulnerability management, and monitoring tools.
  • Experience supporting security-related projects and initiatives in a cross-functional environment.

________________________________________

Behavioral Standards

  • Strong interpersonal and collaboration skills with the ability to work effectively across technical and non-technical teams.
  • Demonstrates professionalism, respect, and sound judgment in all interactions.
  • Able to work independently with minimal supervision and escalate issues appropriately.

________________________________________

Communication

  • Strong written and verbal communication skills with the ability to clearly articulate risks, findings, and recommendations.
  • Detail-oriented with strong analytical and problem-solving abilities.
  • Able to communicate complex security concepts in a manner appropriate to the audience.

________________________________________

Collaboration / Teamwork

  • Builds positive working relationships with internal and external stakeholders.
  • Demonstrates flexibility and adaptability in a dynamic environment with changing priorities.
  • Willingness to collaborate for the benefit of the organization and its customers.

Qualifications

  • Bachelor’s degree in information technology, cybersecurity, risk management, law

Required Skills

CommunicationLeadership

Job Details

Employment TypeFull-Time
Work ModeOn-Site
Experience00 years
Positions1

Posted by

N/A

Posted on:

8 Jul 2026

About 300 US Lab

More open roles

Browse all jobs →