Analyst - Business Risk Controls Management
On-sitePune, Maharashtra, India
Job Summary
Conduct application risk assessments using defined frameworks to identify, rate severity, and document security risks in enterprise applications. Validate security controls across various application control programs and track remediation actions by following up with application owners. Maintain accurate records in GRC tools and contribute to playbooks, templates, and process improvements. Communicate risks in simple, business-friendly language while ensuring assessments are delivered on time with clear documentation. Demonstrate ownership of assigned tasks and continuously improve technical and risk knowledge within the first 90 days.
Required Qualifications
- 3+ Years Required
- 1+ years of experience in cybersecurity, risk, or application support
- Basic understanding of web applications and APIs
- Knowledge of common vulnerabilities such as those in OWASP Top 10
- Familiarity with authentication and access control concepts
- Ability to read and understand technical documentation
- Strong analytical and problem-solving ability
- Good written and verbal communication
- Working knowledge of Excel and documentation tools
- Strong integrity and ethical judgment
- Adherence to defined assessment methodology
- Clear and timely communication of risks
- Willingness to learn core security concepts within the first 90 days
Desired Qualifications
- Vocational and/or Technical Education Preferred
- 5+ Years Preferred
- Exposure to secure SDLC practices
- Understanding of cloud basics in AWS, Azure, or GCP
- Familiarity with risk frameworks like NIST CSF 2.0 or ISO 27001
- Experience with any GRC tool
- Internship or project experience in cybersecurity
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.