Cyber Security Risk Analyst · Gurugram, India in City of London
Cyber Security Risk Analyst · Gurugram, India

Cyber Security Risk Analyst · Gurugram, India in City of London

City of London Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
Sage Publishing

At a Glance

  • Tasks: Lead cyber risk assessments and conduct detailed security audits across cloud and on-prem environments.
  • Company: Join a forward-thinking tech company committed to diversity and inclusion.
  • Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
  • Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
  • Qualifications: Experience in cyber security, risk assessment, and relevant certifications like CISA or CISSP.
  • Other info: Dynamic team environment with a focus on innovation and collaboration.

The predicted salary is between 36000 - 60000 £ per year.

The purpose of the Cyber Security Risk Analyst is to own the risk assessment lifecycle and lead detailed technical security audits across cloud and on-prem environments. This position will also be responsible for design and execution of IT controls testing, the evaluation of technical controls effectiveness, and for driving remediation with engineering and product teams.

Key Accountabilities:

  • Lead technology and cyber risk assessments, maintaining a risk register with clear impact/likelihood rationales and treatment plans.
  • Map controls to frameworks (ISO/IEC 27001:2022/27002, NIST CSF 2.0, NIST 800‑53, CIS Controls, PCI DSS 4.0) and regulatory obligations (GovRAMP, EU AI Act, GDPR, CCPA).
  • Support policy/standard updates and control design reviews; advise on risk appetite, KRIs, and control maturity targets.
  • Conduct security risk assessments, identifying threats, vulnerabilities, and control gaps.
  • Maintain the security risk register, define treatment plans, and monitor remediation progress.
  • Support quantitative or qualitative risk analysis (e.g., FAIR-lite) for critical assets and processes.
  • Conduct deep dive security reviews, identifying threats, vulnerabilities and control gaps.
  • Plan and execute end-to-end technical audits including scope, testing plans, evidence requests, fieldwork, sampling, walkthroughs, and issue rating.
  • Develop control frameworks for secure software development and execute audits having a good understanding of agile software development practices and security by design principles (DevSecOps).
  • Produce clear, actionable audit reports and present findings to engineering leadership and risk committees.
  • Test design and operating effectiveness of Access Control, Application and Data Security, IT Service Operations, Technology Architecture, Logical and Physical Security.
  • Validate evidence, perform re-performance/inspection, and document results according to audit best practices.
  • Track remediation to closure; verify fixes and update control matrices.
  • Perform third-party risk assessments, reviewing security posture, contractual controls, and data flows.
  • Contribute to AI governance and data protection audits where relevant.
  • Partner with security engineering, IT, data, and product teams to translate requirements into technical controls and pragmatic remediation.
  • Create playbooks, control testing procedures, and knowledge articles; run enablement sessions to raise control maturity.

Skills, Qualifications & Experience:

  • Proven experience in cyber security with demonstrable experience in risk assessment and security auditing.
  • Audit and security certifications such as CISA, CISSP, CISM, ISO 27001 Lead Auditor/Implementer or equivalent experience.
  • Strong knowledge of ISO 27001/27002 and NIST CSF, with familiarity across NIST 800‑53, CIS Controls, and SOC 2 or PCI DSS.
  • Hands‑on experience assessing Microsoft and Azure security including Entra ID, Defender suite, Sentinel, Intune, Azure Policy, and Purview.
  • Experience with Identity and Access, Cloud Security (Azure, AWS), Data Protection, SecOps, Agile Software Development (DevSecOps), Security by Design.
  • Solid grasp of ITGCs and evidence‑based testing methods; excellent audit documentation and reporting skills.
  • Technical literacy across networks, identity, cloud, endpoints, logging/monitoring, and secure configuration.
  • Competence in using GenAI to enhance work practices and have experience in using Agentic AI to automate GRC processes.
  • Ability to develop relationships with key technical position holders across locations and functions.
  • Excellent communication skills with the ability to express ideas and messages clearly, both written and verbally.

Diversity, Equity, and Inclusion:

At Sage we are committed to building a diverse and inclusive team that is representative of all sections of society and to sustaining a culture that celebrates difference, encourages authenticity, and creates a deep sense of belonging. We welcome applications from all members of society irrespective of age, disability, sex or gender identity, sexual orientation, color, race, nationality, ethnic or national origin, religion or belief as creating value through diversity is what makes us strong.

Cyber Security Risk Analyst · Gurugram, India in City of London employer: Sage Publishing

At Sage, we pride ourselves on being an exceptional employer, particularly for the Cyber Security Risk Analyst role in Gurugram. Our vibrant work culture fosters collaboration and innovation, while our commitment to employee growth is evident through continuous learning opportunities and support for professional certifications. With a focus on diversity, equity, and inclusion, we create an environment where every team member can thrive and contribute meaningfully to our mission of enhancing security across cloud and on-prem environments.
Sage Publishing

Contact Detail:

Sage Publishing Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Security Risk Analyst · Gurugram, India in City of London

Tip Number 1

Network like a pro! Reach out to folks in the cyber security field on LinkedIn or at local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by brushing up on your technical skills and understanding the latest trends in cyber security. Practice common interview questions and be ready to discuss your experience with risk assessments and audits.

Tip Number 3

Showcase your expertise! Create a portfolio that highlights your past projects, especially those involving risk assessments and security audits. This will give potential employers a clear view of what you bring to the table.

Tip Number 4

Don’t forget to apply through our website! We’ve got loads of opportunities waiting for talented individuals like you. Plus, it’s a great way to ensure your application gets seen by the right people.

We think you need these skills to ace Cyber Security Risk Analyst · Gurugram, India in City of London

Risk Assessment
Technical Security Audits
IT Controls Testing
ISO/IEC 27001:2022/27002
NIST CSF 2.0
NIST 800-53
CIS Controls
PCI DSS 4.0
Security Risk Assessments
Control Frameworks Development
Agile Software Development (DevSecOps)
Audit Documentation and Reporting
Microsoft and Azure Security Assessment
Identity and Access Management
Cloud Security (Azure, AWS)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Cyber Security Risk Analyst role. Highlight your experience with risk assessments, security audits, and any relevant certifications like CISA or CISSP. We want to see how your skills match what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for our team. Don't forget to mention specific frameworks or tools you've worked with that relate to the job.

Showcase Your Technical Skills: In your application, be sure to showcase your technical skills, especially in areas like cloud security and IT controls testing. We love seeing hands-on experience with Microsoft and Azure security, so make that front and centre!

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you'll be able to keep track of your application status. Plus, we love seeing candidates who take that extra step!

How to prepare for a job interview at Sage Publishing

Know Your Frameworks

Familiarise yourself with the key frameworks mentioned in the job description, like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these in past roles or projects, as this will show your technical depth and understanding of compliance.

Showcase Your Audit Experience

Prepare specific examples of audits you've conducted, including the scope, testing plans, and outcomes. Highlight any challenges you faced and how you overcame them, as this demonstrates your problem-solving skills and hands-on experience.

Communicate Clearly

Practice articulating complex security concepts in simple terms. Since you'll be presenting findings to engineering leadership, being able to convey your ideas clearly is crucial. Consider doing mock interviews with a friend to refine your communication style.

Build Relationships

Think about how you can demonstrate your ability to collaborate with cross-functional teams. Prepare examples of how you've worked with engineering, IT, or product teams in the past to implement security controls or remediate risks, as this shows your teamwork skills.

Cyber Security Risk Analyst · Gurugram, India in City of London
Sage Publishing
Location: City of London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>