04 Sep
|
PEOPLE FORCE CONSULTING
|
Bengaluru
04 Sep
PEOPLE FORCE CONSULTING
Bengaluru
Remote: Remote
People Force is looking for a Senior IT Risk Analyst for a 6-12 month contract role with one of our client. This is a remote position for candidates based in India, working in EST hours only.Job Description Role SummaryThe Senior IT Risk Analyst partners with IT and business teams to identify, assess, and reduce technology and cyber risk across the enterprise. This role leads and supports governance, control testing, audit readiness, and compliance initiatives while driving automation and enable efficiencies in recurring risk and compliance processes. The ideal candidate brings a strong blend of hands-on technical security knowledge and risk expertise.Key ResponsibilitiesIT Risk, Governance & Program ExecutionPartner effectively with IT operational teams to create awareness of and communicate IT risk, governance, and control requirements.Implement, enhance, and manage an Enterprise IT Risk Management Framework, including associated methodologies, templates, and workflows.Develop and maintain enterprise IT risk register templates, risk acceptance/exemption forms, KRIs, and reporting dashboards.Conduct and document risk assessments (inherent/residual risk), threat modeling discussions, and control gap analyses.Prepare IT risk-related presentations and reporting for senior management, including trends, emerging risks, and remediation status.Follow up on action items from IT risk, audit, and compliance meetings; track remediation plans, owners, and due dates.Create simple documentation/runbooks for automated processes while ensuring controls remain auditable.Audit, Compliance & Control TestingGather, validate, and store artifacts to prepare for audits and support IT audit functions (internal and external).Champion collection of audit/compliance program responses and documentation; ensure completeness, quality, and traceability.Assist in the coordination and documentation of IT risk and compliance program libraries (policies, standards, procedures, evidence).Perform IT control testing (design and operating effectiveness) across key domains (access, change management, logging/monitoring, vulnerability management, backup/DR, etc.).Support and/or lead compliance initiatives including:SOC 2SOX / Bill 198Other frameworks/standards as adopted (e.g., NIST, ISO 27001, CIS Controls)Technical Security Domain CoverageThe Senior IT Risk Analyst is expected to have working knowledge and be able to assess risks/controls across:Network Security: segmentation, firewall rules, secure network design, IDS/IPS concepts, secure remote access, cloud network controls.Identity & Access Management (IAM):
access provisioning/deprovisioning, RBAC/ABACconcepts, MFA, privileged access management (PAM), service accounts, identity governance and good knowledge of Active Directory.Application Security (AppSec): secure SDLC, OWASP Top 10, code scanning concepts(SAST/DAST/SCA), API security basics, threat modeling, secure change practices.Vulnerability Management: scanning lifecycle, risk-based prioritization, patch management, remediation verification, exception management, and reporting.Logging/Monitoring & Detection: security logging requirements, SIEM concepts, alert tuning basics, use cases, evidence requirements.Cryptography & Data Protection: encryption in transit/at rest, key management basics,certificate lifecycle, hashing/signing fundamentals, tokenization concepts etc.Endpoint/Server Security: hardening baselines, EDR concepts, configuration management, and secure build standards.Cloud & SaaS Security: shared responsibility model, cloud control mapping, IAM in cloud, security posture management concepts.IT Audit & Controls: control objectives, evidence standards, sampling approaches, risk/control mapping, and audit readiness.Vendor & Third-Party RiskImplement and run an enterprise-wide vendor risk assessment program, including onboarding, periodic reviews, and issue tracking.Work with Legal, Procurement, and business owners to assess security requirements in contracts and vendor due diligence.Track and report third-party findings and remediation commitments. Business Continuity / Disaster RecoverySupport or manage Disaster Recovery and Business Continuity (DR/BCP) governance, including testing schedules, evidence capture, lessons learned, and control improvements.Collaboration•Collaborate with Internal Audit, Infrastructure, Development, Legal, HR, Finance, and other stakeholders on cross-functional IT risk, governance, and compliance requirements.Provide advisory support to IT teams on control design improvements and practical remediation options.Act as a key contributor and emerging subject matter expert across assigned IT risk domains.What You Bring to the RoleExperience & Background8+ years of experience in IT risk, security, compliance, audit, or related fields,
with demonstrated exposure to technical security domains.Experience supporting SOC 2 and/or SOX/Bill 198 compliance programs.Experience performing or coordinating IT control testing and audit preparation.DR/BCP governance and testing experience.Technical & Analytical SkillsStrong understanding across security domains (network, IAM, AppSec, vulnerability management, cryptography/data protection, logging/monitoring, endpoint/server security).Ability to translate technical findings into risk language that business stakeholders understand.Strong documentation skills: control narratives, process flows, risk assessments, evidence indexing.Automation & Tooling (Preferred/Valued)• Experience with GRC platforms and workflows, and/or automation using scripts/tools (e.g., Excel/PowerQuery, SQL, Python, Power BI/Tableau, ticketing integrations).• Familiarity with security tools and outputs (e.g., vulnerability scanners, SIEM, IAM/PAM solutions) to support control testing and evidence-based assurance.• Familiarity with automation approaches, including the use of artificial intelligence (AI) to accomplish tasks and workflows.• Create simple documentation/runbooks for automated processes and ensure controls remain auditable.Certifications & Education• Bachelor’s or master’s degree in information security, Computer Science, or Business (or equivalent experience).Preferred technical designations:• CISA or CRISC (strongly preferred)• Other relevant certifications are a plus (e.g., CISSP, CCSP, Security+, GIAC, or cloud security certs)Keys to Your Success• Solid mix of business and technical capabilities with the confidence to engage technical SMEs.• Strong attention to detail, organization skills, and time management—able to manage multiple deadlines and stakeholders.• Proactive mindset: identifies control weaknesses early and drives remediation to closure.• Solid communicator: clear, articulate, and confident written/verbal skills for reports and senior leadership presentations.• Collaborative and able to become a subject matter expert in specific IT risk, governance, and control areas.Diversity, Inclusion, and Equal Prospect Employment:At People Force Consulting Inc, we are committed to fostering diversity, equity, and inclusion. We welcome applicants from all backgrounds, including Indigenous peoples, women, visible minorities, persons with disabilities, and members of 2SLGBTQIA+ communities. If you require any accommodations during the recruitment or interview process, please let us know, we will work with you to ensure an accessible and positive experience.
📌 Senior IT Risk Analyst (Bengaluru)
🏢 PEOPLE FORCE CONSULTING
📍 Bengaluru