NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Risk Analyst in India
2 days ago
Apply with autofill
Apply with autofill
Eversana1·2 days ago
2 days ago

IT Security Risk Management Analyst (Policy Reviewer & Policy Writer)- SOC or ISO or NIST + Audit

Pune, IndiaFull-timeMid · 2-5 yearsRisk Analyst

Sign up free to see how well your resume matches this role.

Boost your chances at eversana1

How you compare FREE

?
Your scoreYour score: not yet known
→
63
Top 10%Top 10%: 63 out of 100

Top 10% of NextRaise users matched against Risk Analyst roles in India.

Must-have skills for this role

  • iso 27001
  • nist
  • policy writing
  • risk assessment

PDF or DOCX · no account needed

Apply faster with autofill FREEeversana1 uses SmartRecruiters - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Support internal business partners with information and responses in requests from EVERSANA clients exploring security and general IT capabilities.
  • Perform security focused assessments on EVERSANA’s third party suppliers and vendors to assess potential risks and communicate impacts to IT and business leaders.
  • Perform security focused assessments on EVERSANA’s clients to assess potential risks and communicate impacts to IT and business leaders.
  • Review, analyze, and maintain Information Security policies, standards, procedures, and guidelines to ensure alignment with business objectives, regulatory requirements, and industry best practices.
  • Conduct periodic reviews of existing security policies and recommend updates based on changes in regulations, emerging threats, technology implementations, and organizational requirements.
  • Coordinate policy review cycles with stakeholders, control owners, and business leaders to ensure timely approval and implementation of policy updates.
  • Evaluate policy exceptions and deviations, assess associated risks, and provide recommendations for risk treatment and management approval.
  • Draft, develop, and maintain Information Security policies, standards, procedures, and supporting documentation in accordance with frameworks such as ISO 27001, NIST, HIPAA, and applicable regulatory requirements.
  • Collaborate with technical and business stakeholders to translate security, compliance, and operational requirements into clear and actionable policy documentation.
  • Ensure policy documentation is written in a consistent format, understandable to both technical and non-technical audiences, and supports organizational compliance objectives.
  • Monitor changes in regulatory, legal, and industry requirements and update policy documentation to address evolving compliance obligations.
  • Support and perform various risk assessment processes to develop threat models for various EVERSANA business lines, as well as improving awareness of financial and operational impacts identified risks posed to EVERSANA.

What they're looking for

  • Four or more years of experience in an auditing role (Information Technology OR Compliance) OR two or more years of experience with risk management practices.
  • Two or more years of experience with third party risk assessments.
  • Experience in creating summary reports for a broad range of audiences, including senior leadership.
  • Competent understanding of auditing practices (ex. SOC1 or SOC2, ISO27000)
  • Understanding of Security Standards like ISO27001, PCI DSS, HIPAA, NIST 800-53
  • Experience with risk management methodology’s (quantitative assessments, FAIR, HIPAA security assessment) and their utilization.
  • Excellent analytical, project management, and problem-solving skills
  • Experience in drafting, reviewing, and maintaining Information Security policies, standards, procedures, and governance documentation.
  • Strong understanding of policy lifecycle management, document governance, and regulatory compliance requirements.
  • Excellent technical writing, documentation management, and stakeholder communication skills.

Nice to have

  • B.Tech/BE
  • Experience required- 2-5
  • Industry Certification such as CISA, CIA, CRISC, TPCRA, ISO 27000 Internal Auditor, or Open FAIR

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Company Description

Company Description

At EVERSANA, we are proud to be certified as a Great Place to Work across the globe. We’re fueled by our vision to create a healthier world. How? Our global team of more than 7,000 employees is committed to creating and delivering next-generation commercialization services to the life sciences industry. We are grounded in our cultural beliefs and serve more than 650 clients ranging from innovative biotech start-ups to established pharmaceutical companies. Our products, services and solutions help bring innovative therapies to market and support the patients who depend on them. Our jobs, skills and talents are unique, but together we make an impact every day. Join us! 

Across our growing organization, we embrace diversity in backgrounds and experiences. Improving patient lives around the world is a priority, and we need people from all backgrounds and swaths of life to help build the future of the healthcare and the life sciences industry. We believe our people make all the difference in cultivating an inclusive culture that embraces our cultural beliefs.  We are deliberate and self-reflective about the kind of team and culture we are building. We look for team members that are not only strong in their own aptitudes but also who care deeply about EVERSANA, our people, clients and most importantly, the patients we serve.   We are EVERSANA.  

Job Description

THE POSITION:

The IT Security Risk Management Analyst is a key contributor to EVERSANA’s IT Risk & Compliance team, placed within EVERSANA’s Information Security service line.  This person will be responsible for performing security focused evaluations of governance, risk, and compliance of EVERSANA’s Information Assets. 

This rewarding position will also help with the continued development and operations of several IT governance and compliance activities. These are oriented towards objectively evaluating security control performance across the enterprise, and alignment of security controls with business objectives.  Further, this role will assist other team members on the IT Risk & Compliance team, and EVERSANA’s Security Operations team to evaluate risks, threats, and opportunities for mitigation strategies in support of sound security practices.

Critical RESPONSIBILITIES:

Business Partner Support –   40%

  • Support internal business partners with information and responses in requests from EVERSANA clients exploring security and general IT capabilities.
  • Perform security focused assessments on EVERSANA’s third party suppliers and vendors to assess potential risks and communicate impacts to IT and business leaders.
  • Perform security focused assessments on EVERSANA’s clients to assess potential risks and communicate impacts to IT and business leaders.

 

Policy Governance and Review- 10%

  • Review, analyze, and maintain Information Security policies, standards, procedures, and guidelines to ensure alignment with business objectives, regulatory requirements, and industry best practices.
  • Conduct periodic reviews of existing security policies and recommend updates based on changes in regulations, emerging threats, technology implementations, and organizational requirements.
  • Coordinate policy review cycles with stakeholders, control owners, and business leaders to ensure timely approval and implementation of policy updates.
  • Evaluate policy exceptions and deviations, assess associated risks, and provide recommendations for risk treatment and management approval.

Policy Development and Writing- 10%

  • Draft, develop, and maintain Information Security policies, standards, procedures, and supporting documentation in accordance with frameworks such as ISO 27001, NIST, HIPAA, and applicable regulatory requirements.
  • Collaborate with technical and business stakeholders to translate security, compliance, and operational requirements into clear and actionable policy documentation.
  • Ensure policy documentation is written in a consistent format, understandable to both technical and non-technical audiences, and supports organizational compliance objectives.
  • Monitor changes in regulatory, legal, and industry requirements and update policy documentation to address evolving compliance obligations.                                                                               
  • Risk Management Operations – 10%    
  • Support and perform various risk assessment processes to develop threat models for various EVERSANA business lines, as well as improving awareness of financial and operational impacts identified risks posed to EVERSANA.
  • Develop, review, and maintain Information Security policies, standards, and procedures to ensure alignment with organizational risk management objectives, regulatory requirements, and industry best practices, while facilitating stakeholder review, approval, and compliance monitoring.

Security Control Audit Support – 30%

  • Monitor and facilitate audit activities for SOC 1, SOC 2, HIPAA risk assessments, and follow up activities of remediation for issues / findings identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place.
  • Monitor and facilitate audit remediation activities identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place.
  • Work with IT Risk & Compliance team members to identify security controls applicable to various service lines.
    • Support the draft and creation of reporting to senior leadership.
  • Conduct periodic internal testing and auditing to support security control compliance.
  • Support internal and external audits by providing policy documentation, evidence of policy reviews, approval records, and demonstrating compliance with applicable security frameworks and regulatory requirements.
  • Four or more years of experience in an auditing role (Information Technology OR Compliance) OR two or more years of experience with risk management practices.
  • Two or more years of experience with third party risk assessments.
  • Experience in creating summary reports for a broad range of audiences, including senior leadership.
  • Competent understanding of auditing practices (ex. SOC1 or SOC2, ISO27000)
  • Understanding of Security Standards like ISO27001, PCI DSS, HIPAA, NIST 800-53
  • Experience with risk management methodology’s (quantitative assessments, FAIR, HIPAA security assessment) and their utilization.
  • Excellent analytical, project management, and problem-solving skills
  • Experience in drafting, reviewing, and maintaining Information Security policies, standards, procedures, and governance documentation.
  • Strong understanding of policy lifecycle management, document governance, and regulatory compliance requirements.
  • Excellent technical writing, documentation management, and stakeholder communication skills.

Qualifications

Preferred qualifications:

  • B.Tech/BE 
  • Experience required- 2-5

Industry Certification such as CISA, CIA, CRISC, TPCRA, ISO 27000 Internal Auditor, or Open FAIR

 

Additional Information

All your information will be kept confidential according to EEO guidelines.

Our team is aware of recent fraudulent job offers in the market, misrepresenting EVERSANA. Recruitment fraud is a sophisticated scam commonly perpetrated through online services using fake websites, unsolicited e-mails, or even text messages claiming to be a legitimate company. Some of these scams request personal information and even payment for training or job application fees. Please know EVERSANA would never require personal information nor payment of any kind during the employment process. We respect the personal rights of all candidates looking to explore careers at EVERSANA.

From EVERSANA’s inception, Diversity, Equity & Inclusion have always been key to our success. We are an Equal Opportunity Employer, and our employees are people with different strengths, experiences, and backgrounds who share a passion for improving the lives of patients and leading innovation within the healthcare industry. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion, and many other parts of one’s identity. All of our employees’ points of view are key to our success, and inclusion is everyone's responsibility.

Follow us on LinkedIn | Twitter

Company

Eversana1
Pune, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Eversana1's careers site·first seen 18 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Manager - Data Privacy Risk at terrapayBengaluru, India–match not yet calculated
  • Third-Party Risk Management - Assistant Manager at State StreetBengaluru, India–match not yet calculated
  • Specialist - R&C - Risk Management 4A at GenpactDelhi NCR, India–match not yet calculated
  • CRE Environmental Risk Review Analyst at JPMorgan ChaseBengaluru, India–match not yet calculated
  • Risk Analyst at invescoHyderabad, India–match not yet calculated

Browse more jobs

  • Risk Analyst jobs in India
  • Compliance Officer jobs in India
  • Insurance Agent jobs in India
  • Insurance Claims Adjuster jobs in India
  • Risk Analyst jobs in United States
  • Risk Analyst jobs in United Kingdom