Security Integrated into Projects Analyst
Summary
Senior risk analyst on the Security Integrated into Projects (SIP) team, embedding cybersecurity and compliance into IT projects from the outset — performing risk assessments, shaping mitigation strategies, and collaborating with PMs, architects, and security stakeholders. Requires 5+ years in cybersecurity with NIST, GDPR, and ISO27001 knowledge.
Introduction & Summary
The Security Integrated into Projects (SIP) team is focused on embedding robust cybersecurity measures and compliance protocols into the earliest stages of IT project development. The aim is to proactively identify and mitigate risks, ensure regulatory compliance, and safeguard systems and data. This role will ensure that cybersecurity and compliance measures are integrated from the outset of IT solutions, enhancing the overall security posture of the organization.
Main Responsibilities
The Senior Risk Analyst will:
- Work with Project Managers and Service Providers to perform comprehensive risk assessments.
- Develop and implement risk management strategies that align with organizational values.
- Collaborate with architects, procurement, legal, engineers, and business stakeholders.
- Ensure validation from stakeholders including IT Security Architecture and PMO.
- Stay informed on the latest technologies and regulatory requirements.
- Provide expert guidance to the SIP Lead.
Key Requirements
- Bachelor's degree in Cybersecurity, Information Technology, or a related field.
- Minimum 5 years of experience in Cybersecurity, particularly in security integration.
- Proven background in conducting risk assessments and developing mitigation strategies.
- Knowledge of regulatory frameworks (NIST, GDPR, ISO27001) is essential.
- Relevant certifications (CISM, CISSP, ISO 27001 Lead Auditor) are advantageous.
- Excellent communication and interpersonal skills, effective in diverse team collaboration.
- Ability to work autonomously and in a collaborative environment.
- Strong project management experience with adaptability to evolving cyber threats.
- Fluent in English.
Other Details
This position is based in Koregaon Park, Pune with a hybrid work model (3 days per week in the office) and operates in the CET time zone. Candidates will have the opportunity to be part of a transformative journey within a young company focused on building robust cyber compliance capabilities.
