Support Engineer - Risk & Compliance Analyst
Bengaluru, India · On-site · Full-time
- Posted 5d ago
- From Securonix’s careers page
- Location
- Bengaluru, India
- Work mode
- On-site
- Type
- Full-time
- Level
- Senior
- Experience
- 2+ years
- Department
- Information Technology
Opens the listing on securonix.bamboohr.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Essential Functions of the Job:
-
Conduct controls assessments to identify and assess Information Security risks within the Securonix IT environment. Ensure that control self-assessments are conducted in a timely manner ensuring completeness and accuracy.
-
Co-ordinate with auditors and internal stakeholders for audit evidence gathering.
-
Conduct risk assessments and vendor risk reviews and maintain documentation of risks in the GRC tool.
-
Ensure that appropriate documentation in the form of policies, standards and procedures is created and managed to support the various security, compliance, and audit requirements.
-
Work with other teams in the IT org to establish standards and process for maintaining and improving the organization’s security posture.
-
Assist in continuous improvement and maturing the Information Security GRC program
Additional Job Functions:
-
Maintain the risk register with up-to-date risk details, and track risk response plans(remediation/exceptions) to closure
-
Perform audits and assessments of third parties such as vendors, service providers, and consulting organizations as required.
-
Work closely with Technology and Security teams to develop appropriate remediation action plans for identified risks.
Knowledge and Skill Requirements:
-
Demonstrated experience in performing risk assessments and control reviews against compliance frameworks such as COSO, COBIT, NIST, ISO 27001, etc.
-
Understanding of IT General Controls in relation to SOC 2, ISO 27001, ISO 42001 and other compliance frameworks.
-
Familiarity with IT and Information Security processes such as identity and access management, vulnerability management, encryption and key management, logging and monitoring and application security is desirable.
-
Familiarity with cloud and SaaS-based environments and technologies with associated auditing methodologies is desirable.
-
Bachelor’s / Master’s degree in a computer or information management field or similar work experience.
-
Relevant certifications like CISSP, CISA, CRISC, ISO 27001 – Lead Auditor/Lead Implementer desirable, but not mandatory.
-
Strong attention to detail, influencing, and problem resolution skills.
-
2+ years’ experience in Information Security - IT audit and/or IT Risk & Compliance roles.
Skills they ask for
Pick one to see other roles that ask for it.
- Risk assessment
- Controls review
- Compliance framework
- IT general controls
- Soc2
- Iso 27001
- Iso 42001
- IT and information security processes
- Cloud and saa s based environments
- Audit methodologies
- Identity and access management iam
- Vulnerability management
- Encryption and key management
- Monitoring and logging tools
- Web application security
About Securonix
Threat detection and response security softwareSecuronix provides security analytics and threat detection and response tools, including SIEM, UEBA, and SOAR capabilities.
See all 17 roles at SecuronixMore roles at Securonix
See all 17- Lead, Sales Development RepresentativePlano · Lead · HybridSales · Lead · HybridPlano, United States3d
- Support Engineer - Risk & Compliance AnalystPune · Senior · On-siteInformation Technology · Senior · On-sitePune, India5d
- Staff SDET (Big Data & Agentic AI)Pune · Senior · On-siteEngineering · Senior · On-sitePune, India1w
- Senior SIEM EngineerBengaluru · Senior · On-siteInformation Technology · Senior · On-siteBengaluru, India1w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.