Position Title : Lead Risk Analyst
Experience : 10 to 15 Years
Location : Bangalore
Mode of Work : On-Site / Hybrid (As per project requirement)
Contract Duration : 18+ Months (Long-Term Contract)
Industry Domain : Cybersecurity / IT Risk Summary :
We are seeking an experienced and strategic Lead Risk Analyst to drive and strengthen our cybersecurity risk management capabilities. This is a high-visibility role for a seasoned professional with extensive experience in cybersecurity risk assessment, policy governance, and team leadership. You will play a pivotal role in leading risk initiatives, working across business units and digital platforms to ensure enterprise-wide cybersecurity standards are maintained and risks are mitigated effectively.
This opportunity offers a unique chance to contribute to a mature cybersecurity program in a global Fortune 500 organization over a long-term contract, influencing policies, controls, and the risk landscape across critical Responsibilities Risk Leadership :
- Develop, execute, and continuously improve cybersecurity risk strategies aligned with organizational goals and industry best practices.
- Establish and oversee enterprise-wide cybersecurity risk management frameworks, methodologies, and processes.
- Lead efforts to identify, assess, prioritize, and manage cybersecurity risks impacting business units and digital platforms.
- Act as a strategic advisor to senior management on emerging cyber threats, risks, and recommended & Stakeholder Management :
- Lead and mentor a team of cybersecurity risk analysts, ensuring performance alignment, skill development, and consistent execution of cybersecurity risk functions.
- Facilitate cross-functional collaboration with IT, OT, Legal, Compliance, and Business Unit leadership to promote risk awareness and adherence to cybersecurity policies.
- Build and maintain strong working relationships with Risk Management Operations (RMO) and other governance bodies to ensure that cybersecurity risks are accurately reported, tracked, and addressed.
- Communicate risk issues to both technical and non-technical stakeholders in a clear and actionable Compliance, and Governance :
- Define and maintain cybersecurity policies, standards, and guidelines to meet internal requirements and regulatory obligations.
- Ensure that security controls are aligned with frameworks such as NIST, ISO 27001, CIS, or other industry standards.
- Collaborate with audit and compliance teams during internal and external assessments, ensuring audit-readiness and issue Improvement & Reporting :
- Identify trends, risk patterns, control gaps, or inefficiencies in current risk management practices and propose data-driven solutions.
- Provide regular reporting and metrics on risk posture, remediation efforts, and compliance status to leadership.
- Leverage threat intelligence and risk analysis tools to stay ahead of cybersecurity challenges and improve response Qualifications and Skills :
Bachelors or Masters degree in Computer Science, Information Security, Risk Management, or a related :
10 to 15 years of experience in Information Security, Risk Analysis, Governance, Risk, and Compliance (GRC).Proven experience in a leadership role, managing teams in a large-scale, enterprise cybersecurity Expertise :Strong understanding of cybersecurity frameworks such as NIST, ISO 27001, CIS Controls, COBIT, and FAIR.Deep knowledge of risk management principles, threat modeling, control frameworks, and incident response protocols.Experience conducting security assessments, gap analyses, and managing risk treatment plans.Familiarity with cloud environments, third-party risk management, and securing digital transformation & Technologies :Proficiency in tools like Archer GRC, RSA, ServiceNow GRC, or similar platforms for risk tracking and reporting.Familiarity with SIEM, vulnerability scanners, audit tools, and compliance automation Skills :Excellent communication, presentation, and stakeholder engagement skills.Strong analytical thinking and decision-making abilities.Ability to work under pressure, manage ambiguity, and lead change across complex environments.ref : hirist.tech)