Job Description
o Lead and support risk assessments of new and existing technology initiatives, products, and services.
o Conduct deep-dive risk reviews of IT and Cyber domains such as Identity & Access Management, Network Security, Incident Management, Data Protection etc.
o Advise business and IT stakeholders on risk mitigation strategies and control enhancements.
- Technology Risk Oversight
o Provide independent oversight and challenge to first line technology risk activities, controls, and remediation plans.
o Review and assess technology risk and control self-assessments (RCSAs), risk registers, and key risk indicators (KRIs).
o Monitor emerging technology risks (e.g., AI, quantum, etc.) and escalate as appropriate.
Policy & Framework Review & Developmento Contribute to the development, maintenance, and enhancement of technology risk management frameworks, policies, and standards.
o Ensure alignment with regulatory expectations (e.g., FFIEC, NIST, ISO 27001) and industry best practices.
Cyber Maturity Review & Challengeo Review quarterly cyber maturity reviews performed by first-line and challenge the outcomes with clear reasoning.
Reporting & Communicationo Prepare and present technology risk reports, dashboards, and insights for senior management and governance committees.
o Communicate complex technology risk concepts in clear, business-focused language
Requirements
Qualifications :
Must Have Skills / Project Experience / Certifications :
Bachelor’s degree in information technology or related field1-3 years information security experience with 3+ years of experience in technology risk managementExcellent verbal and written communicationUnderstanding and knowledge of industry standards and industry frameworks (e.g., COBIT, COSO, ISO 27001, PCI, NIST)Experience of implementing and operationalizing technology risk management programs.Understanding of security requirements, contributions to security design and hands-on implementation of multiple security technologies and capabilitiesHands on experience working with stakeholders in identifying, prioritizing and developing plans and roadmaps for cyber security programsBroad domain knowledge and strong understanding of three or more cyber security domains including (but not limited to) :Cyber risk strategyCyber risk program management and deliveryCyber security operationsSecurity architectureData protectionApplication security / SDLCThird party risk managementCloud securityCyber Threat IntelligenceSecurity Operations CenterIncident ResponseCyber ResilienceGood to Have Skills / Project Experience / Certifications :
CISSP / CRISC (or equivalent)Education :
B.E. / B.Tech + MBA (Preferred)Requirements
Cyber Threat Intelligence Analyst will be catering a pivotal role in CTI team supporting multiple global clients for recent threat advisories, impact analysis and recommendations via sharing threat advisories coming up from Embark GCC threat portals, External Threat Feeds. Demonstrates proven expertise in awareness of threats model around the globe, geographical threats impact aligning with current client’s business infrastructure.
CTI analyst will process incoming malware analysis reports, APT threat actors research, zero-day vulnerabilities advisory disclosure and provide recommendations to wide array of customer base.CTI analyst should be well versed with External Attack Surface Monitoring and OSINT techniques which can be used by threat actors to map business infra recon.Member should have working knowledge of CTI toolsets for example OpenCTI, MISP, Threat Feeds, Malware Sandboxes.CTI member expected to share research findings through internal blogs, presentations and will be a pivotal participant in developing threat intelligence cycle.Knowledge of IOC lifecycle management, PIR (Priority Intelligence Requirements) and Threat Modelling.Ability to automate manual and repetitive tasks such as IOC revalidation, IOC extraction, integration with existing tools and technologies and designing of threat intel playbooks / workflows through scripting knowledge of Python / Bash etc.Familiarity with SIGMA, YARA and other open Standard CTI formats (Provide intelligence briefings to wide array of client base on threats or threat actors and risk they bring to the active geographical environment.CTI analyst will participate in incident response process on an as needed basis to prepare recommendations, analytical and remediation instructions to assist customers.Provide dashboard and monthly threat intel reports related to Incidents detected for governance model.Maintain through documentation of cyber threats, threat vectors and attack trends consumptions aligning to threat actors TTPs.Provide OSINT analysis as in when required via available dark web portals, brand monitoring solutions, External Attack Surface Monitoring control sets. Preferred KnowledgeRequired Professional ExperienceOverall experience of 1-3 years in intelligence studies, threat actor profiling, cyber threat intelligence.Strong understanding of corporate solutions, attack patterns and cyber kill chainExperienced with threat intelligence platforms will be value addition like Recorded Future, Threat Connect, Maltego or similar. EducationEducation B.E / B.Tech (Tier 1 / 2) in Computer Science, Information Technology or related fields