The Application Risk Assessment team serves as the first line of risk defense for the organization’s application landscape. The team works closely with engineering and product teams to identify, assess, and reduce security risks early in the application lifecycle. By applying structured methodologies aligned with frameworks such as NIST CSF and ISO 27001, the team ensures applications are designed and operated with robust security controls. This role places you at the intersection of technology and risk, where your assessments directly influence design decisions, strengthen security posture, and enable protected and reliable product delivery.
Key Responsibilities and Duties
Perform application risk assessments using defined frameworks.
Validate security controls across various application control programs.
Identify risks in enterprise applications, rate severity, and document findings based on the assessments.
Track remediation actions and follow up with application owners.
Support risk evaluations.
Maintain accurate records in GRC tools.
Contribute to playbooks, templates,
Work Experience
3+ Years Required; 5+ Years Preferred
Physical Requirements
Physical Requirements: Sedentary Work
Career Level
4IC
Expectations
Deliver assessment results on time with clear documentation.
Communicate risks in simple, business friendly language.
Show ownership of assigned application related tasks.
Ask the right questions when requirements are unclear.
Continuously improve technical and risk knowledge.
Maintain confidentiality and data handling discipline.
Non-Negotiables
Strong integrity and ethical judgment.
Adherence to defined assessment methodology.
Transparent and timely communication of risks.
Willingness to learn core security concepts within the first 90 days.
Required Skills
1+ years of experience in cybersecurity, risk, or application
📌 Analyst Business Risk Controls Management Pune
🏢 TIAA
📍 Pune
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.