
Eurofins•2h ago
Naukri
Information Security Analyst
Bengaluru
Full Time
Mid Level
N/A
N/A
N/A
Full Job Description
Information Security Analyst - Bengaluru
Eurofins is seeking an experienced Information Security Analyst to join our team in Bengaluru. This role is crucial for supporting our robust security certifications, audit processes, and compliance programs. You will be instrumental in managing and maintaining key security standards such as ISO 27001, SOC 2, SWIFT, and LAB audits. Additionally, you will contribute to our third-party risk management initiatives and the review of critical vendor contracts.
Key Responsibilities
- Oversee and maintain compliance for ISO 27001, SOC 2, SWIFT, and other vital security audits.
- Facilitate internal and external audits, ensuring timely evidence collection and diligent tracking of identified findings.
- Develop and update essential security policies, procedures, and comprehensive audit documentation.
- Actively participate in Third-Party Risk Management (TPRM), including the thorough review of vendor security questionnaires.
- Examine security-related clauses within Master Service Agreements (MSAs), Statements of Work (SOW), Data Processing Agreements (DPAs), and other legal documents.
- Collaborate effectively with internal teams to ensure the consistent implementation and ongoing maintenance of security controls.
- Provide essential support for customer security assessments as required.
Requirements
- A minimum of 4 to 8 years of professional experience in information security, audit, or compliance roles.
- Solid understanding of recognized security frameworks including ISO 27001, SOC 2, and others.
- Demonstrated experience in managing audit processes and preparing audit evidence.
- Proficiency in risk management principles and conducting vendor security reviews.
- Exceptional communication, interpersonal, and documentation skills are essential.
Nice to Have
- Prior experience in TPRM and reviewing contract/security clauses.
- Familiarity with Governance, Risk, and Compliance (GRC) tools.
- Relevant industry certifications such as CISA, CISM, or ISO 27001:2022 Lead Auditor (or equivalent).
Company
Eurofins
Bengaluru
Posted on Naukri