Apply Edge Start your job search

Information Security Analyst

Xceedance · Gurugram, Haryana, India

Apply & track with Apply Edge
Experience Required: 5–8 YearsLocation: Gurgaon/ NoidaRole: GRC ConsultantSecurity Questionnaire Management· Serve as the single point of coordination for client-issued IT security/compliance questionnaires — cyclic and bi-annual in nature.· Log incoming requests from the shared distribution mailbox, loop in the account manager, and set/manage the standard ~60-day turnaround commitment to clients.· Route each questionnaire to the corporate Security Compliance team, who own roughly 90% of standard responses, and independently coordinate with business subject-matter experts to complete the remaining client- or business-specific questions.· Maintain the Received / Working / Sent folder structure and the historical SharePoint response repository; reuse and adapt previously validated answers to maintain consistency and speed of turnaround.· Cross-check current-cycle responses against prior submissions for the same client, flag inconsistencies or outdated answers, and escalate ambiguous or sensitive items for review before final submission.Access Recertification Management· Coordinate the semi-annual access recertification cycle (for H1 typically starting January/February and completing through June, aligned with SOX audit timing) covering in-scope applications and shared-data security objects.· Confirm application inventory and scope with application owners; submit and track data-pull requests to the Security Administration team via the internal ticketing system.· Consolidate and clean raw access-extract data (application ownership details, AD extracts, user profiles) into a standardized Excel workbook, using macros, formulas, and pivot tables to de-duplicate entries and merge rows where necessary (with multi-group access details).· Load the consolidated dataset into SharePoint, distribute recertification requests to business and IT reviewers, and track review decisions through to completion.· Compile audit-ready evidence packages (timestamps, reviewer decisions, access-removal confirmations) to support internal IT audit and SOX audit requirements.· Coordinate with Legal, HR, or other business stakeholders as needed for non-standard questionnaire items and escalate unique/new/non-standard client audit requests to senior team members.Additional Activities· Coordinate mandatory bi-annual security/privacy awareness training for employees and consultants with access to personal information — working with HR and the employee talent portal and managing SharePoint acknowledgment surveys or vendor points of contact for consultant populations.· Support the annual BCP/DR test cycle: confirm test dates with application owners, ensure business tester availability, track communications, and document test outcomes and remediation ownership.REQUIRED SKILLS & QUALIFICATIONS· Bachelor's degree in either Comp Science, Information Systems, Information Security, Privacy, Risk Management, IT/Information Systems Business Administration or a related field.· Overall 5+ years of experience with 3–5 years of experience in GRC coordination, compliance operations, IT audit/vendor-risk support, client assurance, and with project coordination roles; deep technical security background is not required.· Advanced Excel skills, including documentation, pivot tables, macros, formula-based reconciliation, and large-dataset consolidation/cleanup.· Strong working knowledge of MS Word, SharePoint, and shared-drive documentation management practices.· Excellent written and verbal English communication skills, with confidence handling client-facing as well as internal leadership correspondence.· Demonstrated ability to coordinate across cross-functional stakeholders — IT, Security, Legal, HR, Business, and third-party vendors etc. and drive follow-ups to closure.· High attention to detail and consistency when validating recurring or comparative data sets.· Ability to handle sensitive, PII-adjacent information responsibly and maintain confidentiality (the role does not require direct access to client applications or systems).· Availability to overlap with US Eastern Time hours (through at least 12:00 PM ET) for real-time collaboration with the client teams/stakeholders. PREFERRED ATTRIBUTES· Familiarity with vendor/third-party risk concepts (e.g., SIG questionnaires) is an advantage; formal GRC or security certifications are good to have but not mandatory for this role.· Prior experience supporting insurance, reinsurance, or financial services clients.· Experience with GRC tools, security questionnaire platforms, audit evidence repositories, or workflow tracking tools is an advantage.· Good understanding of information security, privacy, risk, access management, business continuity, and compliance concepts; familiarity with ISO 27001, ISO 27701, SOC/SOC 2, NIST, GDPR, HIPAA etc. or client audit requirements is preferred.· Certifications such as ISO 27001 Foundation/Internal Auditor, ISO 27701, ISO/IEC 27001:2022 LI or LA, CISA, CRISC, or equivalent are good to have.· Self-driven with strong ownership; comfortable ramping up through an apprenticeship/knowledge-transfer period alongside the client team before working semi-independently.· Comfortable in a coordination-heavy role with cyclical rather than constant workload peaks, and able to flex into ad hoc requests as they arise.ROLE FOCUSThis role is focused on client security assurance, questionnaire and access-recertification coordination, security awareness and training facilitation, BCP/DR facilitation and management, documentation management, and cross-functional stakeholder follow-up — however not on hands-on technical security work.