Talent.com
Information Security Risk Analyst

Information Security Risk Analyst

ADMBengaluru, Republic Of India, IN
2 days ago
Job description

About ADM :

We are one of the world’s largest nutrition companies and a global leader in human and animal nutrition. We unlock the power of nature to provide nourishing quality of life by transforming crops into ingredients and solutions for foods, beverages, supplements, livestock, aquaculture, and pets.

About ADM India Hub :

At ADM, we have long recognized the strength and potential of India’s talent pool, which is why we have maintained a presence in the country for more than 25 years. Building on this foundation, we have now established ADM India Hub, our first GCC in India.

At ADM India Hub, we are hiring for IT and finance roles across diverse technology and business functions. We stand at the intersection of global expertise and local excellence, enabling us to drive innovation and support our larger purpose of unlocking the power of nature to enrich quality of life.

Security Governance Analyst

Position Summary :

This role will report to the Director Security Governance & Awareness within Global Information & Cyber Security as a member of the security governance team to help with governance of the Information Security program and security risks. Together with the Director Security Governance & Awareness, this role will reduce risk by continuously reviewing, refining, and recommending improvements to the Information Security operating model, policies, standards, and processes and provide reporting and recommendations to the CTO, CISO, and senior leadership.

Job Responsibilities :

  • Develop, maintain, evaluate and implement policies and procedures aligned with both business requirements and legislative changes, (i.E. ISO 27001 / 27002, COBIT 5, NIST CSF, NIS2, GDPR).
  • Collaborate with subject matter experts to write policies and standards in line with the ADM Control Framework, based on NIST CSF, ISO 27001 / 27002, SCF (Secure Controls Framework).
  • Lead control assessment activities addressing security and regulatory requirements, engaging appropriate business units and personnel to plan and execute the ADM Control Governance program, documenting gaps / vulnerabilities and driving risk identification and intake.
  • Manage and maintain GICS SharePoint sites for security awareness, policies, standards, training, newsletters and reporting of threats.
  • Implement security policies and standards aligned with enterprise objectives.
  • Collaborate with subject matter experts to align security and compliance requirements with emerging business needs.
  • Participate in the development and implementation of security awareness program training, materials, and events. Develop and deliver content to educate the business about the ADM Control Framework and other organizational programs.
  • Manage Global Information & Cyber Security SharePoint Site, Yammer and Social Chorus, including all security awareness newsletters, videos, promotions, team updates, policies and standards.
  • Develop and communicate guidelines for enterprise security practices.
  • Assist with control design and implementation for the ADM Control Framework, including tracking and reporting progress, security control gaps, and metrics.
  • Proactively identify and collect appropriate and meaningful metrics to be reported in order for the business leaders to make appropriate risk-based decisions.
  • Monitor compliance with security policies and standards across the organization utilizing reporting and metrics, driving process improvement.
  • Compile, review, and analyze security information to provide recommendations, metrics, and reports for management review and decision making.
  • Facilitation and management of security policies, policy exceptions, standards, procedures and guidelines.
  • Document and track requests for variance from standards. Monitor risk mitigation processes and progress until variances are closed.
  • Actively stay aware of processes and methods for identifying and addressing non-compliance to information security standards and communicate the findings clearly to business areas.
  • Collaborate with key business units and capability stakeholders, including, but not limited to, Privacy, IT, Internal Audit, InfoSec, Corporate Security, and HR to develop and improve Information Governance across the enterprise.
  • Establish security metric baselines and generate reports reflecting current performance against those baselines using Power BI.
  • Document narrative summary and analysis of the metrics.
  • Review, track and update company standards for compliance to legal and regulatory requirements. Work with subject matter experts to maintain documentation;

modifies or creates newsecurity standards as needed.

  • Monitor compliance with security policies and standards across the organization utilizing reporting and metrics. Drive compliance improvement to processes.
  • Document and track requests for variance from standards. Monitor risk mitigation processes and progress with the clients until variances are closed.
  • Perform functions in a timely manner and with extreme level of attention to detail, urgency and thoroughness.
  • Job Requirements :

  • BA / BS degree or higher or equivalent experience.
  • Minimum of 4-8 years of experience in security and IT / OT related fields.
  • Experience managing SharePoint sites (web development), posting updates and configuring sites and forms. Basic knowledge and understanding of how information security affects an organization and ability to link it to business processes.
  • Experience with Security Awareness program management and implementation.
  • Basic knowledge and understanding of risk assessment and control methods.
  • Basic knowledge and understanding of end-user computing tools, hardware, application software, network, communications and mobile technologies.
  • Basic knowledge and understanding of information security policies, standards and processes.
  • Basic knowledge of electronic record retention policies and standards.
  • 5 years of regulatory requirements and frameworks such as ISO 27001 / 27002, PCI, CIS CSC, SOX, HIPPA, COBIT, GDPR or NIST Cyber Security Framework (CSF).
  • SANS 401 (can be obtained after employment).
  • 5 years of experience in a GRC discipline. One year of work in a Governance, Risk, Compliance (GRC) function in a highly regulated environment, may substitute for up to 18 months' experience.
  • Proven success implementing security policies, standards, and / or controls.
  • Ability to translate strategy into actionable plans impact organizational change.
  • Familiarity with complex multi-national companies and distributed business models.
  • Ability to work across the organization, building relationships and influencing peers and management through establishing trust and credibility.
  • Applies sound judgment and creativity to solve complex problems.
  • Ability to excel in a rapidly changing environment.
  • Experience in one or more of the following areas preferred : network administration, systems administration, SDLC / secure soft, encryption, asset management, identity and access management, Audit, Governance Risk & Compliance, IT Operations, Security Risk Management.
  • Strong verbal and written communication skills;
  • ability to drive discussions and influence decision making;
  • strong presentation andreporting skills. Proficient in technical writing and leveraging various creative mechanisms to communicate to diverse audiences.

  • Ability to communicate with and create documentation for technical and non-technical audiences.
  • Strong leadership and communications skills.
  • Limited travel required.
  • Desired Skills :

  • Practical experience implementing NIST, ISO, or other industry standards Certifications, such as CISM, CISSP, CISA, or CRISC.
  • Create a job alert for this search

    Information Security Analyst • Bengaluru, Republic Of India, IN

    Related jobs
    • Promoted
    Information Security Specialist

    Information Security Specialist

    ACL DigitalBengaluru, Karnataka, India
    Archer Information Security GRC Data Management.Type of resource : Consulting Based Services (CBS).Support the Corporate Information Security GRC team in managing and enhancing the qual-ity, integra...Show moreLast updated: 2 days ago
    • Promoted
    Senior Manager - Information Security (Governance, Risk and Compliance)

    Senior Manager - Information Security (Governance, Risk and Compliance)

    NaviBengaluru, Karnataka, India
    At Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regu...Show moreLast updated: 17 days ago
    • Promoted
    Mobisy - Information Security Analyst

    Mobisy - Information Security Analyst

    MobisyTechnologiesBangalore, India
    We are looking for a detail-oriented Information Security Analyst / Specialist to join our InfoSec team.The ideal candidate will ensure compliance with industry standards, strengthen security operati...Show moreLast updated: 30+ days ago
    • Promoted
    Mashreq - Senior Manager - Information Security - Risk Management - GRC

    Mashreq - Senior Manager - Information Security - Risk Management - GRC

    Mashreq Global Services Private LimitedBangalore, India
    Security Risk Management : - Develop, implement, and maintain the Information Security Risk Management Framework, ensuring alignment with the banks enterprise risk management (E...Show moreLast updated: 29 days ago
    • Promoted
    Sr. Security Engineer - Information Security

    Sr. Security Engineer - Information Security

    PINKVILLAhosur, tamil nadu, in
    Pinkvilla is seeking a dynamic Information Security professional, who will contribute to strengthening our security posture by working closely with cross-functional teams, monitoring threats, secur...Show moreLast updated: 1 day ago
    • Promoted
    Information Security Analyst, AVP

    Information Security Analyst, AVP

    Deutsche BankBangalore, India
    Job Title : Information Security Analyst, AVP.The Risk Lead Function covering Chief Security Office (CSO) CTO, IS Threat Operations and Office of the CSO is looking for an Information Security Speci...Show moreLast updated: 30+ days ago
    • Promoted
    INFOLOB Global - Security Compliance Analyst II

    INFOLOB Global - Security Compliance Analyst II

    INFOLOB SOLUTIONS INDIA PRIVATE LIMITEDBangalore
    Job Description : At Infoblox, every breakthrough begins with a bold what if.What if your ideas could ignite global innovation?. What if your curiosity could redefine...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Administrator (ISA) - Senior Manager

    Information Security Administrator (ISA) - Senior Manager

    State Street CorporationBangalore, India
    The Information Security Administrator (ISA) will support business units in their efforts to comply with GCS security policy and required controls. Working with direction from the Senior Information...Show moreLast updated: 3 days ago
    • Promoted
    Saks Fifth Avenue - Senior Analyst - Information Security Strategy & Resilience

    Saks Fifth Avenue - Senior Analyst - Information Security Strategy & Resilience

    HUDSON'S BAY SERVICES PRIVATE LIMITEDBangalore
    You Will Be : - A key contributor to the Information Security Strategy serving as Subject Matter Expert (SME), working closely with cross-functional teams to strengt...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Threat Analyst - Information Security

    Senior Threat Analyst - Information Security

    OptivBangalore
    Description : This position will be on-site reporting to our Bangalore office M-F.This team provides 24 / 7 support.This role requires shift flexibil...Show moreLast updated: 2 days ago
    • Promoted
    Tech-Functional Business Analyst – Signal & Risk Management (Pharmacovigilance)

    Tech-Functional Business Analyst – Signal & Risk Management (Pharmacovigilance)

    vueverse.hosur, tamil nadu, in
    We are looking for a highly experienced IT / Tech-Functional Business Analyst (12+ years) with deep expertise in Pharmacovigilance (PV) systems, specifically Signal Management and Risk Management mod...Show moreLast updated: 1 day ago
    • Promoted
    Senior Cloud Security Specialist

    Senior Cloud Security Specialist

    ACL Digitalhosur, tamil nadu, in
    We are a leading organization in the field of information security, dedicated to protecting our clients' data and ensuring their digital safety. Our mission is to provide innovative security solutio...Show moreLast updated: 16 days ago
    • Promoted
    Cyber Security Specialist

    Cyber Security Specialist

    Innefu Labshosur, tamil nadu, in
    We are seeking experienced and detail-oriented professionals for the role.The selected candidates will be responsible for assisting cybercrime investigations by collecting and analysing digital evi...Show moreLast updated: 16 days ago
    • Promoted
    Mashreq - Senior Manager - Information Security Cyber Culture & Awareness

    Mashreq - Senior Manager - Information Security Cyber Culture & Awareness

    Mashreq Global Services Private LimitedBangalore, India
    Responsibilities : - Cybersecurity Training Program Development - Design, develop, and deliver engaging cybersecurity training programs tailored f...Show moreLast updated: 29 days ago
    • Promoted
    Mashreq - Manager - Information Security

    Mashreq - Manager - Information Security

    Mashreq Global Services Private LimitedBangalore, India
    Management : - To Strategize, develop and implement Data Protection Controls in coordination with stakeholders across the Organization globally. To ensure compliance of the Organ...Show moreLast updated: 30+ days ago
    • Promoted
    Quantiphi - Information Security Analyst

    Quantiphi - Information Security Analyst

    Quantiphi AnalyticsBangalore
    Description technology is the heart of our business, a global and diverse culture is the heart of our success.We love our people and we take pride in catering them to a culture built on transparen...Show moreLast updated: 23 days ago
    • Promoted
    Nextiva - Information Security Auditor

    Nextiva - Information Security Auditor

    NextivaBangalore
    Description : The Information Security Auditor will work across the organization to ensure Nextivas complian...Show moreLast updated: 30+ days ago
    • Promoted
    Amadeus Labs - Senior Specialist - Information Security

    Amadeus Labs - Senior Specialist - Information Security

    Amadeus LabsBangalore
    Description : Job Title : SENIOR SPECIALIST INFORMATION SECURITY.Summary Of The Role : Youll play a key role in en...Show moreLast updated: 30+ days ago