22 Sep
|
Eversana India
|
Pune
22 Sep
Eversana India
Pune
Job Description
THE POSITION:
The IT Security Risk Management Analyst is a key contributor to EVERSANA s IT Risk Compliance team, placed within EVERSANA s Information Security service line. This person will be responsible for performing security focused evaluations of governance, risk, and compliance of EVERSANA s Information Assets.
This rewarding position will also help with the continued development and operations of several IT governance and compliance activities. These are oriented towards objectively evaluating security control performance across the enterprise, and alignment of security controls with business objectives. Further, this role will assist other team members on the IT Risk Compliance team, and EVERSANA s Security Operations team to evaluate risks, threats, and opportunities for mitigation strategies in support of sound security practices.
Critical RESPONSIBILITIES:
Business Partner Support - 40%
- Support internal business partners with information and responses in requests from EVERSANA clients exploring security and general IT capabilities.
- Perform security focused assessments on EVERSANA s third party suppliers and vendors to assess potential risks and communicate impacts to IT and business leaders.
- Perform security focused assessments on EVERSANA s clients to assess potential risks and communicate impacts to IT and business leaders.
Policy Governance and Review- 10%
- Review, analyze, and maintain Information Security policies, standards, procedures, and guidelines to ensure alignment with business objectives, regulatory requirements, and industry best practices.
- Conduct periodic reviews of existing security policies and recommend updates based on changes in regulations, emerging threats, technology implementations, and organizational requirements.
- Coordinate policy review cycles with stakeholders, control owners, and business leaders to ensure timely approval and implementation of policy updates.
- Evaluate policy exceptions and deviations, assess associated risks, and provide recommendations for risk treatment and management approval.
Policy Development and Writing- 10%
- Draft, develop, and maintain Information Security policies, standards, procedures, and supporting documentation in accordance with frameworks such as ISO 27001, NIST, HIPAA, and applicable regulatory requirements.
- Collaborate with technical and business stakeholders to translate security, compliance, and operational requirements into transparent and actionable policy documentation.
- Ensure policy documentation is written in a consistent format, understandable to both technical and non-technical audiences, and supports organizational compliance objectives.
- Monitor changes in regulatory, legal, and industry requirements and update policy documentation to address evolving compliance obligations.
- Risk Management Operations - 10%
- Support and perform various risk assessment processes to develop threat models for various EVERSANA business lines, as well as improving awareness of financial and operational impacts identified risks posed to EVERSANA.
- Develop, review, and maintain Information Security policies, standards, and procedures to ensure alignment with organizational risk management objectives, regulatory requirements, and industry best practices, while facilitating stakeholder review, approval, and compliance monitoring.
Security Control Audit Support - 30%
- Monitor and facilitate audit activities for SOC 1, SOC 2, HIPAA risk assessments, and follow up activities of remediation for issues / findings identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place.
- Monitor and facilitate audit remediation activities identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place.
- Work with IT Risk Compliance team members to identify security controls applicable to various service lines.
- Support the draft and creation of reporting to senior leadership.
- Conduct periodic internal testing and auditing to support security control compliance.
- Support internal and external audits by providing policy documentation, evidence of policy reviews, approval records, and demonstrating compliance with applicable security frameworks and regulatory requirements.
- Four or more years of experience in an auditing role (Information Technology OR Compliance) OR two or more years of experience with risk management practices.
- Two or more years of experience with third party risk assessments.
- Experience in creating summary reports for a broad range of audiences, including senior leadership.
- Competent understanding of auditing practices (ex. SOC1 or SOC2, ISO27000)
- Understanding of Security Standards like ISO27001, PCI DSS, HIPAA, NIST 800-53
- Experience with risk management methodology s (quantitative assessments, FAIR, HIPAA security assessment) and their utilization.
- Excellent analytical, project management, and problem-solving skills
- Experience in drafting, reviewing, and maintaining Information Security policies, standards, procedures, and governance documentation.
- Strong understanding of policy lifecycle management, document governance, and regulatory compliance requirements.
- Excellent technical writing, documentation management, and stakeholder communication skills. Qualifications
Preferred qualifications:
- B.Tech/BE
- Experience required- 2-5
Industry Certification such as CISA, CIA, CRISC, TPCRA, ISO 27000 Internal Auditor, or Open FAIR
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 IT Security Risk Management Analyst (Policy Reviewer & Policy Writer) (Pune)
🏢 Eversana India
📍 Pune