Lead Information Security Analyst, ITC
Nike · Karnataka
- Experience7–8 yrs
- SalaryNot disclosed
- Work modeunknown
- Levelexecutive
- Posted16 Sept 2026
About Nike
Nike is hiring in Karnataka in consumer goods. This role looks for around 7+ years of experience.
Skills
- SOX ITGC
- NIST CSF
- ISO 27001
- risk lifecycle management
- third-party cyber risk
- DR/BCP practices
- ServiceNow GRC
- Governance
- Risk
- Compliance
- Technical Recovery
- cybersecurity risk assessments
The role
A GRC analyst at a global consumer goods company governs cybersecurity risk across governance, risk, compliance, and technical recovery workstreams, applying SOX ITGC, NIST CSF, and ISO 27001. The role manages ServiceNow GRC, third-party cyber risk, and disaster recovery and business continuity practices.
Full job description
Who You’ll Work With
The Lead GRC Information Security Analyst 4 is an advanced individual contributor and workstream owner on the GRC team at Nike's India Technology Center (ITC), reporting to the ITC GRC Director. This role partners with the Global GRC team in Beaverton, Oregon and cross-functional leaders across Global Technology, Internal Audit, and Finance.
Who We Are Looking For
The candidate needs to have advanced GRC delivery experience and the versatility to operate as a Lead GRC Athlete—running workstreams end-to-end across Governance, Risk, Compliance, and Technical Recovery, and rotating between them without re-hiring. This is a workstream ownership role that requires in-depth knowledge, conceptual thinking, and the credibility to work with Principals globally. The candidate provides direction and mentorship to Seniors and Analysts, advises the team on complex matters, and foresees most future implications of the solutions they implement. Solid working knowledge of SOX ITGC, NIST CSF and ISO 27001, risk lifecycle management, third-party cyber risk, DR/BCP practices, and ServiceNow GRC is essential. The candidate closes loops with artifacts and evidence and knows when to execute, when to govern, and when to escalate.
7+ years of professional experience in technology risk, cybersecurity risk, IT audit, compliance, or GRC in matrixed, multinational technology organizationsBachelor’s degree or equivalent combination of education, experience, or trainingProfessional certifications strongly preferred (e.g., CISA, CRISC, CISM, CISSP, GRCP, ISO 27001 LA/LI)Hands-on experience with ServiceNow GRC (or comparable platform)Demonstrated hands-on delivery across at least two of four GRC streams (Governance, Risk, Compliance, Technical Recovery)
What You’ll Work On
You run GRC workstreams as a Lead GRC Athlete across Governance, Risk, Compliance, and Technical Recovery. You coach Seniors and Analysts, serve as the trusted delivery lead for the ITC Principal and Director, and partner across the global GRC organization to deliver outcomes at ITC.
You own one or more workstreams end-to-end in the stream where demand is highest (Governance, Risk, Compliance, or Technical Recovery), rotating based on the stream with the longest queueYou drive risk lifecycle discipline and risk register hygiene in ServiceNow GRC, and support policies, standards, exceptions, attestations, and governance forum cadenceYou drive SOX ITGC testing readiness and evidence quality, TPRM remediation, cybersecurity risk assessments, and DR/BCP exercise supportYou provide direction and mentorship to Senior and Analyst GRC Athletes on the workstream—unblocking issues, reviewing artifacts, and enforcing a quality barYou produce and interpret workstream metrics (control effectiveness, risk closure, TPRM cycle time, DR test outcomes) for Directors and Principals and recommend improvementsYou build strong working relationships with control owners, engineers, vendors, and cross-functional partners; you navigate ambiguity and competing prioritiesYou identify recurring pain points, propose changes, and implement improvements with an eye to future implications for the global program