← Browse all jobs

S

Information Security Analyst

Soch Street · India

FULL TIME

Job Description

What You’ll Do

● Support the operation and continuous improvement of the Information Security Management System — ISO 27001, SOC 2-style controls, and customer/internal compliance requirements.

● Maintain security policies, standards, control documentation, and compliance trackers; translate customer contracts and security addendums into internal controls.

● Coordinate audit evidence collection for internal, external, surveillance, and customer-led audits; track findings and remediation through closure.

● Support periodic risk assessments and help maintain the enterprise risk register.

● Track key security metrics (vulnerability remediation, training completion, vendor risk, compliance maturity) and prepare updates for leadership and Security Council reviews.

● Support responses to customer security questionnaires, RFP/RFI security sections, and due-diligence requests; coordinate customer audits and walkthroughs.

● Execute third-party risk management — vendor due-diligence reviews, risk ratings, remediation tracking, and periodic reassessments of critical vendors.

● Coordinate security awareness initiatives, including onboarding and refresher training, phishing simulations, and role-based awareness content.

● Maintain audit-ready documentation and identify opportunities to automate evidence collection, compliance tracking, and reporting workflows.

What We’re Looking For

● 3-4 years of experience in Information Security, GRC, IT Risk, Compliance, Audit, or related roles.

● Hands-on experience with ISO 27001, SOC 2-style controls, internal/external audits, and customer security assessments.

Experience performing or supporting security audits, IT risk assessments, or control testing — Big 4 or similar audit/advisory background is a strong fit.

● Experience in vendor risk management, third-party due diligence, and contract security reviews.

● Ability to respond to customer security questionnaires, RFP/RFI security sections, and due-diligence requests.

● Good understanding of access control, vulnerability management, secure SDLC, incident management, data protection, and cloud security.

● Strong documentation, coordination, and follow-up skills; comfortable working across Engineering, Product, DevOps, IT, HR, Procurement, Legal, and Customer Success.

● Strong ownership mindset — able to drive tasks to closure without frequent follow-up.

Preferred Qualifications

● Certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISA, CISM, CRISC, Security+, or CISSP.

● Experience working in SaaS, fintech, AI/technology, financial services, or customer-audited environments.

● Familiarity with frameworks such as NIST CSF, NIST 800-53, CIS Controls, ISO 27001 Annex A, OWASP, and cloud security benchmarks.

● Experience using GRC platforms, ticketing tools, document repositories, vendor risk tools, and dashboard/reporting tools.

Details

CompanySoch Street
LocationIndia
TypeFULL TIME
Nichegeneral

Similar Jobs

S

Customer success manager

Supy

G

Assistant professor of computer science

GL Bajaj Institute Of Technology And Management

M

Subject matter expert

MHC GLOBAL Pvt Ltd

J

Customer support specialist

JMD Technologies Inc.

C

Customer service representative

Career Comfort