Sr Security GRC Analyst

Bengaluru | Security | Full-time

Apply

MoEngage is an insights-led customer engagement platform trusted by 1,350+ global consumer brands, including McAfee, Flipkart, Domino’s, Nestle, Deutsche Telekom, and OYO. MoEngage combines data from multiple sources to help brands gain a 360-degree view of their customers.  

MoEngage Analytics arms marketers and product owners with insights into customer behavior. Brands can leverage MoEngage Personalize to orchestrate journeys and build 1:1 conversations across the website, mobile, email, social, and messaging channels. MoEngage Inform, the transactional messaging infrastructure, helps unify promotional and transactional communication to a single platform for better insights and lower costs. MoEngage’s AI Suite helps marketers develop winning copies and creatives, optimize campaigns and channels that boost engagement, and help with faster execution.

For over a decade, consumer brands in 60+ countries have been using MoEngage to power digital experiences for over a billion monthly customers. With offices in 15 countries, MoEngage is backed by Goldman Sachs Asset Management, B Capital, Steadview Capital, Multiples Private Equity, Eight Roads, F-Prime Capital, Matrix Partners, Ventureast, and Helion Ventures.

MoEngage was named a Contender in The Forrester Wave™: Real-Time Interaction Management, Q1 2024 report, and Strong Performer in The Forrester Wave™ 2023 report. MoEngage was also featured as a Leader in the IDC MarketScape: Worldwide Omni-Channel Marketing Platforms for B2C Enterprises 2023.

Key Skills: Knowledge of Information Security Standards along with Regulatory Compliance Understanding [Information Security Governance, Risk and Compliance (GRC), ISO 27001, SOC2, GDPR, DPDA], Risk Management Expertise, Auditing Skills, Communication Skills, Analytical Thinking, Familiarity with GRC Tools, BCP & DR Concepts, Years of Experience: 3-5 years

Does this sound like you?

You enjoy tackling complex cybersecurity and infosec compliance issues and have a knack for handling customer inquiries: 

  • Dealing with customer inquiries about the company's security policies and practices, requires excellent customer service skills and an in-depth understanding of the company's cybersecurity measures.

  • Conduct information security risk assessments effectively and serve as an internal auditor for any security-related issues that may arise within the organization.

  • Develop and continuously update company-wide security policies, standards, guidelines, and procedures based on the evolving cybersecurity landscape.

  • Understanding and catering to the security needs of various organizational stakeholders, especially when translating them into tangible security policies (AI-centric for example).

  • Cultivating a culture of collective responsibility and continuous improvement within the team in relation to security effectiveness.

  • Utilizing multiple security tools and methodologies to consistently assess the effectiveness of existing security controls.

  • Helping to implement and maintain IT governance, risk management, and compliance frameworks amidst rapidly changing industry standards and regulations.

  • Keeping up-to-date with changes in information security trends, regulatory requirements and best practices to continually improve the company's GRC program.

  • Adapting to and managing any other related tasks that may arise during the department's day-to-day operations. This includes novel problem-solving and agility in response.

As a Security Lead, you will:

  • Analyse client requests in the RFP lifecycle, mainly to understand information security requirements and articulate our current control framework

  • Assist multiple customer-initiated security audits.

  • Provide regular updates to stakeholders and management regarding the status of RFP activities and project milestones

  • Collaborate with stakeholders, including IT and security teams and sales leaders, to understand project requirements and objectives

  • Monitor remediation activities following audits to ensure any identified gaps are addressed promptly.

  • Document lessons learned and best practices to continuously improve the RFP process

  • Ensuring the security and compliance of our platform by effectively responding to security questionnaires and assessments

  • Strong understanding of key compliance frameworks (e.g., SOC 2, ISO 27001,  GDPR, HIPAA).

  • Proven experience in managing and executing risk assessments, compliance audits, and control testing.

  • In-depth knowledge of risk management principles, security controls, and industry regulations.

  • Maintain documentation of compliance processes, procedures, and controls.

  • Support internal and external audits, including coordination with auditors, preparing audit materials, and tracking findings and resolutions.