Apply Edge Start your job search

Senior Technical Risk Analyst

HGS · Bengaluru, Karnataka, India

Apply & track with Apply Edge

Senior Technical Risk AnalystGlobal Enterprise SecurityRole OverviewThe Senior Technical Risk Analyst will support the operation and continued evolution of the organization's Cyber and IT Risk Management capabilities within Global Enterprise Security (GES), including alignment with broader business and Enterprise Risk Management processes.This is a hands-on technical risk role requiring strong analytical judgment, technical curiosity, and the ability to independently investigate and challenge risk assertions. The analyst will work directly with security, technology, engineering, architecture, and business teams to understand technical conditions, determine their actual risk significance, and translate validated exposure into actionable risk information.The role goes beyond traditional GRC administration. Analysts are expected to examine the technology, controls, threat context, and supporting data behind identified concerns - not simply document the presence of a finding or deviation.What You'll DoTechnical Risk AnalysisConduct technical risk assessments across applications, infrastructure, cloud environments, platforms, and technology services.Evaluate technical risk using evidence and context to determine exposure and business impact. Apply technical judgment to distinguish findings, issues, exceptions, and material risks, challenging unsupported risk assertions.Develop risk scenarios and recommendations that connect technical conditions, credible threats, controls, and business impact.Risk Intelligence & Decision SupportIdentify and analyze security, technology, operational, and business data needed to support objective risk decisions.Correlate technical signals to identify trends, concentrations, systemic conditions, and emerging risks.Develop data-driven risk indicators and identify opportunities to automate risk monitoring and reporting.Translate technical exposure into actionable insights for technology and business leaders.Program EvolutionSupport the evolution of Cyber Risk Management into broader IT Risk Management and alignment with Enterprise Risk Management. Strengthen relationships across technical findings, issues, exceptions, controls, systems, business services, and risks. Support consistent approaches to risk prioritization, ownership, treatment, aggregation, and escalation. Advance risk methodologies and technologies toward more dynamic, data-driven risk management.What You'll BringAt least 10+ years of general IT and Technology experience, with at least 6+ year of experience in cybersecurity, technology risk, or a related technical discipline, with a strong understanding of enterprise technology environments and cybersecurity controls.Demonstrated ability to investigate technical security concerns, interpret technical evidence, and determine their actual risk significance.Ability to challenge unsupported assumptions regarding severity, likelihood, impact, or risk.Experience translating complex technical conditions into clear business-relevant risk scenarios.Working knowledge of cybersecurity and risk frameworks, including NIST and ISO.Strong analytical, communication, and stakeholder-management skills, with the ability to work effectively with engineers, architects, security practitioners, and business leaders.An undergraduate degree in Business, Information Technology, or related disciplines (or additional years of equivalent experience).Preferred:Experience with data-driven risk analysis, cloud and hybrid technology environments, scenario-based or quantitative risk methodologies, continuous risk monitoring, or the modernization of Cyber or IT Risk Management programs.Applicable industry recognized certifications: CISSP, CISM, CRISC, CISA, etc.What Success Looks Like:Success in this role means bringing technical depth, evidence, and sound judgment to risk management.The Senior Technical Risk Analyst will help ensure that identified risks accurately represent meaningful technology exposure - not simply the presence of a finding or deviation. They will investigate what is behind a risk assertion, identify the data needed to validate it, understand the effectiveness of existing controls, and appropriately scope and prioritize the resulting exposure.Ultimately, this role will help strengthen the connection between technical evidence, issues, controls, system-level risk, business impact, and enterprise risk, enabling more objective and data-driven risk decisions across the organization.