Security Analyst
Angel One · Bangalore Urban, Karnataka, India
Angel One · Bangalore Urban, Karnataka, India
**About Angel One:** Angel One is one of India’s fastest growing fin-techs, on a bold mission to make investing simple, smart, and inclusive for every Indian. With over 3+ crore clients, we’re building at scale – and building for impact. Our Super App helps clients manage their investments, trade seamlessly, and access financial tools tailored to their goals. We are working to build personalized financial journeys for our clients, powered by new-age tech, AI, Machine Learning and Data Science. We're a builder's company at heart. You’ll have the space to experiment, the freedom to move with velocity, and the mandate to make bold, user-first decisions – every single day. The vibe? Think less hierarchy, more momentum. Everyone has a seat at the table and a shot to build something that lasts. Be part of a team that’s scaling sustainably, thinking big, and building for the next billion. **Why You'll Love Working at Angel One!** **Tech Systems that run at Scale:** From AI to real-time data infra, you’ll work on tech that’s ahead of the curve and solve problems that truly matter. **Build one of India’s Leading Fintech Platform:** We’re not just disrupting finance – we’re shaping how billion Indians access wealth. Own It. Drive It. Scale It: You’ll have the freedom to lead, the resources to build, and the opportunity to leave your mark. Empowered Growth: We invest in your growth and empower you to explore your full potential. Exceptional Benefits: Our comprehensive benefits package includes health insurance, wellness programs, learning & development opportunities, and more. A Security GRC (Governance, Risk, and Compliance) Analyst bridges technical security teams and business leadership by managing risk, ensuring compliance with standards (CSCRF, ISO 27001, NIST) and help in strengthening security policies. They perform full GRC for Angelone with respect to technology, interfacing with auditors for regulatory audits, interface for risk assessments, manage internal, external, third-party audits, and use tools like ZenGRC or Archer to track control effectiveness and remediation. **Job Title: Security Analyst** **Job Function: Information Security / Compliance** **Location: Bangalore** What You Will Do Framework Management: Map organizational practices to frameworks (CSCRF, ISO 27001, NIST) and maintain compliance maturity. Risk Management: Conduct internal and vendor risk assessments, identifying vulnerabilities and assigning risk scores. Audit Management: Lead internal and external audits, compile evidence, and manage audit findings. Adoption of cloud security framework: Well versed with the cloudAWS/GCP) native security services and implementation. Policy Development: Create, update, and implement information security policies, standards, and procedures. Tools, Applications, Third-Party Risk: Perform vendor risk assessments and ensure third-party contracts comply with security requirements. Reporting & Monitoring: Develop GRC dashboards and report control failures or risks to stakeholders and management. Security Training: Conduct security awareness training and foster a culture of compliance. **Who You Are** **Experience:** 8-10+ years in IT audit, risk management, information security, security operations. **Framework Knowledge:** Deep knowledge of CSCRF, ISO 27001, SOC 2, NIST, PCI DSS, GDPR Good knowledge of cloud adoption framework Having good knowledge on any of the cloud environment. **AWS/GCP is preferable GRC Tools:** Practical experience with platforms like ZenGRC, OneTrust, Archer. **Certifications:** ISO 27K LA/LI, CISA (Certified Information Systems Auditor), or CGRC. Soft Skills: Strong communication skills to translate technical risks into business impact, analytical thinking, and attention to detail. **Performance Indicators (KPIs)** **Audit Readiness:** Successfully passing audits with minimal findings. Risk Reduction: Timely remediation of identified risks and control gaps. **Policy Compliance:** Full adoption of security controls across the organization. Tools & Technologies GRC Platforms: Archer, ServiceNow GRC, One Trust. Productivity Tools: Microsoft Office (Excel, Word), Jira, Confluence. Assessment Tools: Risk Assessment trackers, Vendor questionnaire tools.