As an InfoSec Analyst at SentiLink, you will serve as the primary point of contact for the due diligence process, internally and externally, ensuring we meet our SLAs. This role is highly visible, offering a unique opportunity to learn from and collaborate with subject matter experts, department heads, and other key stakeholders at SentiLink.
The role is based in India and will be remote full-time.
Responsibilities:
- Draft responses to the security questionnaires, customer risk assessments, and security reviews in alignment with the standards and service level agreements that the division decides.
- Maintain reports, registers, and dashboards that the division will utilize.
- Manage and maintain the various repositories that the division is currently maintaining.
- Assist and manage the SentiLink Security Program in close collaboration with the Director of Security.
- Deliver assignments within the specified SLA.
- Identify, build, manage, and distribute a range of performance metrics for the division.
- Maintain a consistent and intense focus on compliance and risk management.
- Delivery of scheduled security compliance activities and filing of evidence.
- Assist in compliance audits, internal and external audits.
- Lead and own compliance activities.
Requirements:
- Minimum of 5 years of working experience or 2 to 3 years of experience in a similar role.
- Exceptional quantitative aptitude and skill set with a mastery of Microsoft Office applications.
- Rigorous analytical mindset with a high level of intellectual curiosity and excellent problem-solving skills.
- A sharp focus on attention to detail, accuracy, and data validation.
- Effective communication skills (listening, verbal, and written).
- Excellent interpersonal and teamwork skills.
- Sound judgment and discretion.
- Strong initiative, energy, and confidence in completing assignments with limited supervision.
- Ability to manage multiple priorities in a fast-paced, fluid startup environment.
- Good knowledge and understanding of financial statements, corporate policies, insurance, corporate structures, legal entities, and subsidiaries.
- Knowledge of information security risk management and controls (broadly under GRC - governance, risk, and compliance).
- Technical knowledge of network infrastructure and cloud platforms.
- Knowledge of SOC2 or PCI-DSS or NIST or ISO 27001 standards is a plus.
- This job is located in India