Security Analyst - Int'l India
Role details
Job location
Tech stack
Job description
We are seeking a Security Analyst to support one of our clients' enterprise information security program by translating technical security risks into business impacts and advising stakeholders on risk treatments.
Responsibilities:
-
Support our enterprise information security program
-
Translate technical security risks into clear business impacts
-
Advise stakeholders on pragmatic risk treatments
-
Help implement and validate security controls across networks, endpoints, and cloud environments
-
Partner with IT, product, and business teams to assess threats
-
Identify control gaps
Requirements
-
2+ years of professional experience in cybersecurity with emphasis in network security and/or security engineering (e.g., cloud, firewalls, IDS/IPS, endpoint protection, vulnerability management, logging/monitoring).
-
Demonstrated experience conducting or supporting risk assessments (e.g., asset/context discovery, threat & likelihood analysis, control gap identification, residual risk estimation) and documenting outcomes in clear, actionable language.
-
Familiarity with common security frameworks/controls (e.g., NIST CSF/800-53/800-30, ISO 27001/27002, CIS Critical Security Controls) and ability to map findings to these references.
-
Working knowledge of network fundamentals (TCP/IP, routing, segmentation, DNS, TLS), identity and access management, and secure configuration baselines.
-
Ability to write clear advisory reports and present risk/controls to stakeholders; strong documentation habits (runbooks, diagrams, tickets).
-
Experience collaborating with IT or engineering teams to implement and validate controls (e.g., compensating controls, segmentation changes, logging enrichment). * Experience facilitating or contributing to risk registers, exception/acceptance processes, and risk treatment plans with measurable milestones.
-
Familiarity with privacy & data protection concepts (e.g., data classification, retention, DLP controls) and regulatory drivers (e.g., SOX/PCI/HIPAA/GLBA as applicable).
-
Knowledge of DevSecOps practices (e.g., secrets management, SAST/DAST, SBOMs, CI/CD guardrails).
-
Contribution to security awareness or secure-by-design initiatives.
-
Relevant certifications (e.g., Security+, Network+, Cloud Fundamentals) or equivalent practical experience.