EY
EY•14h ago
Naukri

Security Analyst

Bengaluru
Full Time
Mid Level

Auto Apply to 50+ AI Matched Security Analyst Jobs

Use Auto Apply Agents to Bulk Apply jobs with ATS Optimised Resumes, find verified Insider Connections for jobs at EY

Full Job Description

At EY, you will have the chance to build a career as unique as you are, with global scale, inclusive culture, and technology to become the best version of you. Join as an Information Security Analyst - Sr. Associate to protect data and information systems, which are central to EY's business operations.

You will collaborate with a global team of over 950 Information Security professionals to support EY's business by protecting EY and client information assets. The Technology Assurance, Risk, and Policy (TARP) function within Information Security will create and promote a holistic Governance, Risk, and Compliance (GRC) program, integrating initiatives with global firm objectives and emerging cybersecurity threats.

The role involves developing security assurance processes, conducting technical audit plans, maintaining the Information Security Management System (ISMS), and ensuring compliance with frameworks like ISO 27001, SOC 1, SOC 2, HITRUST, and UK Cyber Essentials Plus Certification.

Key responsibilities include:

  • Creating and maintaining process documents and internal procedures.
  • Developing comprehensive Information Security technical audit plans and schedules based on client demands, regulatory requirements, industry best practices, and organizational objectives.
  • Maintaining the firm's ISMS and participating in ISO 27001 activities, including risk assessments, monitoring frameworks, and remediation tracking.
  • Collaborating with internal stakeholders (IT, compliance, ET, CT) to align audit activities with organizational goals.
  • Maintaining accurate documentation of vulnerabilities, remediation plans, and risk mitigation strategies.
  • Staying informed about emerging threats, attack vectors, and security vulnerabilities.

To qualify, you must have Min 3 years of experience in an information security or technology audit field. You should also have the ability to:

  • Work collaboratively with various teams to understand processes and documentation requirements.
  • Deliver high-quality documentation with meticulous attention to detail.
  • Quickly grasp complex technical concepts and communicate them clearly.
  • Be a strong multi-tasker and prioritize duties effectively.

Ideally, you will have a Bachelors or above in Information Technology or Cyber Security related Degrees and a keen interest in pursuing relevant Information Security Certifications like CISSP, CISM, ISO 27001 Lead Auditor, ISO 42001 Lead Auditor/Implementer, CISA, etc.

Company

EY

EY

EY is a global professional services firm that leverages data and technology to help clients create long-term value, build trust in capital markets, and address complex challenges facing the world. Wi...

Bengaluru
Posted on Naukri