IS Risk Analyst - Assurance
Bajaj Finserv · Bengaluru
- Experience2–5 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelmid
- Posted3 Sept 2026
About Bajaj Finserv
Bajaj Finserv is hiring in Bengaluru in financial services. This role looks for around 2+ years of experience.
Skills
- GRC
- security governance
The role
An information security risk analyst at a financial services company assesses technology controls, evaluates cyber risk, and supports assurance activities. The role applies GRC practices and security governance to strengthen organizational resilience.
Full job description
Responsibilities:
Oversee and execute end-to-end control assurance activities for all subfunctions within information security. Formalize, pilot, and execute the first line of defense (1LOD) assessments for information security to proactively identify risks to the business.
Lead the client assessments program by liaising with internal client partners to ensure the company is meeting client expectations for information security assessments and audits.
Collaborate with sourcing and legal teams to review third-party supplier contracts, ensuring contractual terms align with the defined scope of services and comply with applicable regulatory requirements and governance frameworks.
Support execution of FedLine and other assessments by working with internal SMEs and second and third lines of defense teams.
Support renewal of cyber insurance for the organization by working with insurance brokers and key internal stakeholders.
Develop Financial Security Assurance-specific security standards and procedures.
Perform other duties and/or special projects as assigned.
Requirements:
Bachelor's degree in computer engineering or a related field, with a minimum of 10+ years of experience in information security OR, in lieu of the bachelor's degree, a minimum of 12+ years of experience in information security.
8+ years of progressive experience in information security, technology risk, security controls assurance, or audit, including 5+ years leading teams.
Good understanding of IS risk management concepts.
Strong working knowledge of IT-related US banking regulations and industry best practices (NIST, PCI DSS, HIPAA, CRI, etc. ).
Demonstrated experience designing and executing control testing/assurance programs across multiple security domains.
Exposure to working with external attack surface monitoring tools to partner with internal stakeholders to remediate external risk exposure to the organization.
Proven ability to influence and partner across information security, technology, risk, compliance, and audit functions.
Excellent executive communication skills, able to synthesize complex findings into clear, actionable insights.
Excellent interpersonal skills with the ability to influence team members, management, and external groups.
Self-motivated and able to work independently or in a team environment and work with virtual teams.
Desired Skills:
In-depth understanding and working experience in information security and risk management in US-based financial institutions.
Good understanding of security controls pertaining to emerging technologies like cloud, AI, and data protection.
Exposure to SIG and other Shared Assessments offerings.
Familiarity with privacy regulations across the US, India, and the Philippines.
Certifications (preferred): CISM, CISA, CCSP, CGRC, CISSP, etc.