⚡ New

Sr Info Security Analyst IND

FM India

BengaluruFull-timeMid LevelOn-site

Job Description

About us:

We are a highly successful 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Businesses worldwide trust our expertise to protect their assets, relying on our comprehensive risk assessments and robust, engineering-based insurance solutions to safeguard against fire, natural disasters, and other perils. Serving over a quarter of the Fortune 500 and major corporations globally, we deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive.

FM India is a strategic location for driving our global operational efficiency. Our presence in India allows us to leverage the countrys talented workforce and advance our capabilities to serve our clients better. We have diverse corporate functions that emphasize research, advanced technologies like AI and analytics, risk engineering, research, finance, marketing, HR, etc. working together to provide innovative solutions and nurture lasting relationships from co-workers to clients.

Role Title: Sr Info Security Analyst IND

Position Summary:

FM is seeking a Senior Information Security Analyst with expertise in Security Controls Testing and Controls Assurance. In this role, you will play a critical part in protecting FM by assessing risks across external vendors, SaaS platforms, cloud solutions, and internal control environments. Your work will evaluate both the design and operating effectiveness of security controls and, where applicable, how third-party solutions interact with FM systems and data.

This includes supporting periodic control attestation and certification activities for regulatory and internally established controls, including controls associated with Rhode Islands Model Audit Rule (MAR) and First Line control-monitoring programs. You will review control-owner attestations and supporting evidence, assess whether controls are operating as intended, document conclusions, and escalate potential exceptions or deficiencies. You will partner closely with business, technology, and risk stakeholders to identify risks, assess control effectiveness, and recommend practical, business-aligned mitigation strategies.

Job Responsibilities:

  • Lead end-to-end security control testing and assurance activities, including planning, walkthroughs, sampling, evidence review, documentation, and reporting.
  • Perform independent assessments of control design and operating effectiveness across internal systems in alignment with established security frameworks, standards, and regulatory requirements.
  • Coordinate and administer periodic control attestation and certification cycles, including controls associated with Rhode Islands Model Audit Rule (MAR) and internally established First Line controls.
  • Review control-owner attestations and supporting evidence, certify First Line controls, and follow up on responses requiring clarification, investigation, or escalation.
  • Maintain controls within the organizations Governance, Risk, and Compliance platform, including control descriptions, ownership, frequency, evidence requirements, testing procedures, status, and conclusions.
  • Assess internal processes, technical environments, solution architectures, cloud platforms, APIs, data flows, and system integrations to identify control weaknesses and cyber risks.
  • Review and interpret control evidence, audit reports, architecture diagrams, data flow diagrams, and other security documentation to support clear and defensible conclusions.
  • Document and communicate control gaps, deficiencies, and improvement opportunities, and support remediation, exception management, risk acceptance, and regulatory audit readiness.
  • Recommend practical mitigation strategies, including compensating controls, control enhancements, and secure design improvements.
  • Partner with business, technology, risk, legal, and other stakeholders to strengthen control effectiveness and support governance activities.

Skill and Experience:

Technical

Soft Skills

  • 2-4 years of experiencerequired in cybersecurity, information security, or cyber risk, with experience in third-party risk management (TPRM), security controls testing, IT risk, or audit.
  • General knowledge of operating systems, networks, databases, and application development, including how these components interact within secure enterprise environments.
  • Understanding of IT General Controls (ITGCs), including controls related to: Logical access management, Change management, Computer operations, System and database security controls
  • Understanding of controls-assurance and compliance-monitoring activities, including control attestations, certifications, evidence sufficiency reviews, exception identification, and regulatory audit support.
  • Exposure to security frameworks such as NIST CSF, ISO 27001, CIS Controls, or SOC-aligned controls.
  • Strong verbal and written communication skills, with the ability to clearly document and communicate findings.
  • Strong interpersonal skills and ability to work across business, technology, and risk stakeholders.
  • Ability to manage multiple priorities and coordinate activities effectively.
  • Demonstrated attention to detail and professional skepticism.

Must Have Skills:

Controls Testing

  • Security Control Testing and Controls Validation Experience testing and validating security controls, reviewing control-owner attestations and supporting evidence, and documenting conclusions regarding control design and operating effectiveness.
  • Familiarity with regulatory control environments, including Rhode Islands Model Audit Rule (MAR), or comparable internal control frameworks such as SOX.
  • Familiarity with Security and Control Frameworks Working knowledge of common frameworks such as NIST CSF, ISO 27001, CIS Controls, or SOC-aligned controls.
  • Documentation and Evidence Collection Ability to gather, review, and clearly document evidence supporting control design and operating effectiveness.
  • Attention to Detail and Consistency Strong focus on accuracy, repeatability, and completeness when executing testing procedures and documenting results.
  • Collaboration and Coachability Ability to work effectively with senior risk, compliance, and technology team members, take direction well, and continuously improve testing quality.

Education and Certifications:

4 Year/ bachelors degree required.

Preferred certifications: CISA, CISM, CISSP

Work location: Bengaluru

Posted Today

Related Jobs

Accountant

Zetheta Algorithms Private Limited

Malappuram Today
Full-time

Related Searches

Apply Now