Senior Information Security Analyst (Gurugram)

Senior Information Security Analyst (Gurugram)

03 Sep
|
Ameriprise India
|
Gurugram

03 Sep

Ameriprise India

Gurugram

About Our Company

Ameriprise India LLP has been providing client based financial solutions to help clients plan and achieve their financial objectives for 20 years. We are part of Ameriprise Financial Inc., a US financial planning company headquartered in Minneapolis with a global presence and diversified financial services leader with more than $1.5 trillion in assets under management, administration and advisement as of year-end 2024. The firm’s focus areas include Asset Management and Advice, Retirement Planning and Insurance Protection.

Be part of an inclusive, collaborative culture that rewards you for your contributions, and work with other talented individuals who share your passion for doing great work. You’ll also have plenty of opportunities to make your mark at the office and a difference in your community. So, if you're talented, driven and want to work for a solid, ethical company that cares, take the next step and create a career at Ameriprise India LLP.

Job Description

The Senior Information Security Analyst is an analyst-focused role within Identity & Access Governance (IAG). The role evaluates whether identities, access credentials and permissions are governed in accordance with policy, least-privilege principles and regulatory expectations. The analyst uses data, evidence and platform knowledge to identify access risk, investigate exceptions, challenge ineffective outcomes, coordinate remediation and communicate control health to stakeholders.
This is not a pure IAM implementation, platform engineering or operations ticket-processing role. Technical knowledge enables analysis, but success is measured by the quality of governance judgement, follow-through, evidence, reporting and risk reduction.

Responsibilities

- Analyze identity and access data to determine whether access remains appropriate, approved, timely and aligned to least privilege.

- Identify control gaps, policy violations, unusual patterns and incomplete outcomes; assess risk and recommend proportionate action.

- Coordinate governance activities across application owners, business reviewers, IAM delivery teams, infrastructure teams, audit, risk and other control partners.

- Drive issues through remediation and validate closure using reliable evidence rather than relying only on task or ticket completion.

- Prepare concise metrics, risk summaries, audit evidence and leadership reporting that explain control health, exceptions, ageing and remediation progress.

- Contribute to policies, standards, procedures, control design and continuous improvement in response to new risks, technologies and regulatory expectations.

- Explains the risk and control purpose behind an activity, not only the procedure or tool steps.

- Uses logical, evidence-based judgement when the documented procedure does not fully address the situation.

- Demonstrates strong governance judgement in at least one relevant identity domain, with the aptitude to learn adjacent areas.

- Identifies whether an issue originates from technology, data, process, a policy exception, or a failed control, and recommends action that addresses the underlying risk.



Owns assigned issues from identification through follow-up, escalation, documented remediation, and evidence-based closure.

- Communicates clearly with technical and business stakeholders, including when challenging an incomplete or inappropriate outcome.

- Identifies recurring themes and proposes proportionate improvements to controls, reporting or process design.

Core Capability Areas

1. Access Review and Certification

- Govern and facilitate periodic access reviews and certifications, including user, privileged, and application access.

- Govern identity lifecycle controls, including joiner, mover, and leaver controls; transfer reviews; and termination controls.

- Govern specialized reviews and remediation activities, including service-account reviews, orphan-account remediation, inactivity reviews, segregation-of-duties monitoring, and role-based access controls.

- Assess review scope, reviewer appropriateness, decision quality, conflicting decisions, overdue reviews and remediation status.

- Escalate material risks and recurring non-compliance; verify that access removals and ownership changes are completed.

- Maintain sufficient, accurate and retrievable evidence for internal and external audit.

2. Policy Enforcement

- Evaluate adherence to identity, authentication, privileged-access, credential-management and least-privilege requirements.

- Investigate policy exceptions and non-compliant configurations; coordinate risk assessment, approval, remediation or formal exception handling.

- Review identity and access implications for new services, cloud IAM entities, privileged accounts and changing technology patterns.

- Partner with technical teams to translate policy intent into clear, practical security requirements and guardrails.

3. User Activity Monitoring and Investigation

- Review privileged actions that cannot be linked to an approved business event or change record.

- Assess business justification, identify potentially inappropriate activity and escalate unresolved or high-risk cases.

- Monitor the health of event data, alert logic, evidence quality and governance workflows supporting privileged-action monitoring.

- Prepare investigative and compliance reporting for leadership, audit and risk stakeholders.

Required Qualifications:

- Bachelor's degree in a technical discipline or equivalent relevant work experience.

- Demonstrated experience in one or more governance areas: access reviews and attestations, JML controls, RBAC, SoD, policy enforcement, privileged-access governance, audit response or access-risk remediation.

- Hands-on familiarity with at least one Identity Governance and Administration or Privileged Access Management platform such as RSA Governance & Lifecycle (Aveksa), SailPoint, Saviynt,



Entra ID Governance, IBM Security Verify Governance, Idira Identity Security Platform (CyberArk), BeyondTrust, Delinea, Password Manager Pro or a comparable platform.

- 4–7 years of total professional experience, with at least 50% of that experience in identity and access governance.

- Experience analyzing access or control data and translating findings into risk, remediation, reporting or stakeholder action.

- Ability to create and modify SQL, PowerShell, Python, Power BI, spreadsheets or similar tools to investigate data, automate analysis or produce reporting.

- Effective written and verbal communication, attention to detail, follow-through and ability to manage competing priorities.

- Ability to work with stakeholders across onshore and offshore models and operate in a regulated or control-focused environment.

Preferred Qualifications:

- Experience in financial services or another highly regulated environment.

- Experience preparing identity and access control evidence or responding to regulatory, financial, technology-risk, or control audits, such as SOX, SOC, NYDFS, FINRA, SEC, GLBA, or comparable compliance assessments. General audit coordination experience without direct involvement in IAM controls, evidence, findings, or remediation will not by itself meet this requirement.

- Working knowledge of Active Directory / LDAP, authentication and authorization models, Windows or Linux, databases, cloud security governance, AI security governance, and privileged credentials.

- Experience with incident/problem/change/request management, business analysis, process flows, User Acceptance Testing, and project coordination.

- Relevant security certifications (CISSP, CISM, CISA, CRISC, GIAC, other).

In-Office Collaboration

We are a client-centric, relationship-based business. Working together, in-person, is foundational to how we achieve results. By fostering a culture of face-to-face collaboration, idea sharing, productivity and personal connection, we deliver for our stakeholders — clients, advisors, employees and shareholders. Our employees work in the office at least three (3) days per week, with flexibility to work from home two (2) days per week. Some roles may require additional in-office time or different in-office expectations, and specific requirements will be discussed during the hiring process.

Full-Time/Part-Time

Full time

Timings

(2:00p-10:30p)

India Business Unit

AWMPO AWMP&S; President's Office

Job Family Group

Technology

Ameriprise India LLP is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, genetic information, age, sexual orientation, gender identity, disability, military status, veteran status, marital status, pregnancy, family status or any other basis prohibited by law.

We are committed to fostering an inclusive and accessible recruitment process for individuals with disabilities. If you require a reasonable accommodation to participate in the application or interview process, speak to your recruiter to discuss how we can support you.

📌 Senior Information Security Analyst (Gurugram)
🏢 Ameriprise India
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior information security analyst (gurugram) / gurugram

Subscribe to this job alert:

Get the latest job offers by email for: senior information security analyst (gurugram) / gurugram