Live opening · Posted 2 days ago

Sr. Info Security Analyst IND

Delta Air Lines · Bangalore
Instahyre 2-5 yrs
You are 2 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 2 days ago
CompanyDelta Air Lines
LocationBangalore
Experience2-5 yrs
SourceInstahyre
Listed2 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
3 min from Instahyre publishing this role to us finding it
2 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,370 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Seeking a Senior Information Security Analyst with expertise in Third-Party Risk Management (TPRM) and/or Security Controls Testing. In this role, you will play a critical part in protecting FM by assessing risks across external vendors, SaaS platforms, cloud solutions, and internal control environments. Your work will evaluate both the design and operating effectiveness of security controls and, where applicable, how third-party solutions interact with FM systems and data.
This includes reviewing security control environments, internal controls, and solution implementations with a focus on data handling, storage, processing, and system integrations. You will partner closely with business, technology, procurement, and risk stakeholders to identify risks, assess control effectiveness, and recommend practical, business-aligned mitigation strategies.
Responsibilities:
Lead end-to-end third-party risk assessments and/or security control testing activities, including planning, execution, documentation, and reporting.
Perform independent validation of control design and operating effectiveness across internal systems and/or external vendors in alignment with established frameworks and standards.
Evaluate vendor security programs, governance, and control environments, as well as internal controls, processes, and supporting evidence to determine effectiveness and maturity.
Assess solution architecture, cloud environments (SaaS/PaaS), APIs, data flows, and integration points, or validate controls governing these areas, depending on assignment.
Identify and communicate inherent and residual cyber risks, including issues related to data protection, identity & access management, system connectivity, and external exposure.
Review and interpret security documentation, including SOC 1/SOC 2 reports, control testing evidence, audit reports, architecture diagrams, and data flow diagrams.
Execute control testing procedures, including walkthroughs, sampling, evidence review, and documentation of results in a consistent and repeatable manner.
Document findings clearly, including control gaps, deficiencies, and improvement opportunities, and support remediation tracking and resolution.
Recommend practical risk mitigation strategies, including compensating controls, control enhancements, secure design improvements, and contractual safeguards.
Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and governance activities.
Requirements:
2-4 years of experience required in cybersecurity, information security, or cyber risk, with experience in third-party risk management (TPRM), security controls testing, IT risk, or audit.
General knowledge of operating systems, networks, databases, and application development, including how these components interact within secure enterprise environments.
Understanding of IT General Controls (ITGCs), including controls related to: Logical access management, Change management, Computer operations, System and database security controls.
Exposure to security frameworks such as NIST CSF, ISO 27001 CIS Controls, or SOC-aligned controls.
4-year/ bachelor's degree required.
Preferred certifications: CISA, CISM, CISSP.
Soft Skills:
Strong verbal and written communication skills, with the ability to clearly document and communicate findings.
Strong interpersonal skills and ability to work across business, technology, and risk stakeholders.
Ability to manage multiple priorities and coordinate activities effectively.
Demonstrated attention to detail and professional scepticism.
Must Have Skills:
Controls Testing:
Security Control Testing and Validation: Experience performing control testing, reviews, or self-assessments against defined standards, procedures, or frameworks.
Familiarity with Security and Control Frameworks: Working knowledge of common frameworks such as NIST CSF, ISO 27001 CIS Controls, or SOC-aligned controls.
Documentation and Evidence Collection: Ability to gather, review, and clearly document evidence supporting control design and operating effectiveness
Attention to Detail and Consistency: Strong focus on accuracy, repeatability, and completeness when executing testing procedures and documenting results.
Collaboration and Coachability: Ability to work effectively with senior risk, compliance, and technology team members, take direction well, and continuously improve testing quality.

Experience
2-5 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App