Sr. Information Security Analyst, GRC
300 US Lab
Job Description & Responsibilities
The Senior Information Security GRC Analyst reports to the Information Security GRC Manager and plays a critical role in supporting the Information Security program across key areas including information security risk management, third-party risk management, information security policy governance, operational risk reporting and analytics, and security and privacy awareness.
This role is a senior individual contributor responsible for executing and continuously improving information security risk management processes. The position partners closely with Information Security, Privacy, IT, and business stakeholders to identify, assess, document, and monitor information security risks across the enterprise.
Essential Duties
Information Security Risk Management
- Participate in enterprise and program-level initiatives aligned with Information Security goals and objectives.
- Support the maintenance and continuous improvement of the information security risk management framework, program guidelines, and standard operating procedures.
- Conduct information security risk and control assessments across technical environments, business processes, and third parties.
- Document identified control gaps and associated risks from both technical and business perspectives.
- Perform gap assessments against regulatory requirements, external standards, and internal security policies.
- Partner with Information Security, Privacy, IT, and business stakeholders to support risk prioritization and remediation planning.
- Support the security and privacy awareness and training program, including tracking participation and effectiveness metrics.
- Conduct third-party risk assessments and collaborate with internal stakeholders and vendors to identify, document, and track risk treatment plans.
- Support contract reviews by providing information security and third-party risk input.
________________________________________
Information Security Policy Governance
- Maintain enterprise information security policies, standards, and supporting documentation.
- Review and assess requested policy exceptions or violations and document associated risks.
- Provide guidance on policy interpretation and implementation to internal stakeholders.
________________________________________
Reporting and Metrics
- Develop and maintain information security risk and compliance metrics.
- Support the preparation of regular risk and compliance reports for senior leadership.
- Identify trends, emerging risks, and control weaknesses through analysis of metrics and assessment results.
Competencies
Knowledge
- Strong understanding of information security frameworks such as ISO 27001/27002, ISMS, SOC1&2 and NIST Cybersecurity Framework (CSF), with hands-on experience supporting implementation or audits.
- Working knowledge of information security risks related to enterprise information assets and intellectual property.
- Understanding of integrated IT and physical security risk concepts.
- Experience working in risk management environments involving information security, privacy, records management, or eDiscovery.
- Understanding and knowledge of IT General controls across multiple audit and compliance frameworks
- Foundational understanding of security technologies and architectures, including network security, identity and access management, encryption, application security, vulnerability management, and monitoring tools.
- Experience supporting security-related projects and initiatives in a cross-functional environment.
________________________________________
Behavioral Standards
- Strong interpersonal and collaboration skills with the ability to work effectively across technical and non-technical teams.
- Demonstrates professionalism, respect, and sound judgment in all interactions.
- Able to work independently with minimal supervision and escalate issues appropriately.
________________________________________
Communication
- Strong written and verbal communication skills with the ability to clearly articulate risks, findings, and recommendations.
- Detail-oriented with strong analytical and problem-solving abilities.
- Able to communicate complex security concepts in a manner appropriate to the audience.
________________________________________
Collaboration / Teamwork
- Builds positive working relationships with internal and external stakeholders.
- Demonstrates flexibility and adaptability in a dynamic environment with changing priorities.
- Willingness to collaborate for the benefit of the organization and its customers.
Qualifications
- Bachelor’s degree in information technology, cybersecurity, risk management, law
About 300 US Lab
Required Skills
Job Details
Posted by
N/A
Posted on:
8 Jul 2026
About 300 US Lab
More open roles
- Marketing Communications ManagerChtrbox · India
- SEM Analyst - Marketing Data Science - Hybrid (Marketing & Communications)FlexBoard · India
- VISUAL COMMUNICATION & SOCIAL MEDIA EXECUTIVESDS BY KUSHAL SHAH · Mumbai, Maharashtra, India
- Senior Java Full Stack Developer - Communication SurveillanceLuxoft · Gurugram, Haryana, India
- Senior Java Full Stack Developer - Communication SurveillanceLuxoft · Gurugram, Haryana, India
- Senior Java Full Stack Developer - Communication SurveillanceLuxoft · Gurugram, Haryana, India