{"id":"4d2410a2-a64c-41df-a445-6263c1eae909","company":{"id":"6e9b4866-fa55-42ed-addf-8448051a14fa","company_stack":[],"company_gallery":[],"company_stats":[],"company_about_section":{"name":"FM India","video_link":null,"description":"<p>FM is a 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Serving over a quarter of the Fortune 500 and major corporations globally, they deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive. FM India located in Bengaluru is a strategic location for driving FM&#39;s global operational efficiency that allows them to leverage the country&rsquo;s talented workforce and advance their capabilities to serve their clients better.</p>","primary_color":null,"secondary_color":null},"company_benefit_section":[],"company_testimonial_section":[],"company_culture_section":[],"onboarding_process":null,"ticker_logos":[],"gtn_companies":[],"role_category":[{"name":"BE Technology Workforce Development"},{"name":"Business Enablement"},{"name":"Business Operations"},{"name":"Human Resources"},{"name":"Marketing"},{"name":"Natural Hazard & Aggregation"},{"name":"Technology"}],"cta_color":"#333333","name":"FM India","short_name":"FM India","slug":"fmindia","description":"<p>FM is a 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Serving over a quarter of the Fortune 500 and major corporations globally, they deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive. FM India located in Bengaluru is a strategic location for driving FM&#39;s global operational efficiency that allows them to leverage the country&rsquo;s talented workforce and advance their capabilities to serve their clients better.</p>","short_description":"<p>We are a highly successful 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Businesses worldwide trust our expertise to protect their assets, relying on our comprehensive risk assessments and robust, engineering-based insurance solutions to safeguard against fire, natural disasters, and other perils. Serving over a quarter of the Fortune 500 and major corporations globally, we deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive.</p>","about_us":"We are a highly successful 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Businesses worldwide trust our expertise to protect their assets, relying on our comprehensive risk assessments and robust, engineering-based insurance solutions to safeguard against fire, natural disasters, and other perils. Serving over a quarter of the Fortune 500 and major corporations globally, we deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive.","video_link":null,"logo_url":"https://talent500-public-prod-cb.s3.ap-south-1.amazonaws.com/company_logos/FM_India_logo_29977edb691e4bf3884483d917bfd431.png","job_logo":"uploads/company_images/thefmgroup_logo.jpeg","job_logo_url":"https://talent500-public-prod-cb.s3.ap-south-1.amazonaws.com/company_job_logos/thefmgroup_logo_64b8b7d77d714fd78f9aefd4fb7e2038.jpeg","show_powered_by_talent500_logo":false,"website":null,"redirect_logo_url":"https://talent500.com/fmglobal/home/","linkedIn":null,"facebook":null,"twitter":null,"instagram":null,"hero_type":"1","nav_bar_color":null,"nav_items_color":"#FFFFFF","gallery_heading":"Gallery","company_image_url":"","meta_title":null,"meta_description":"For nearly two centuries, businesses worldwide have trusted us, a global leader in commercial property insurance, to protect their assets. We provide comprehensive risk assessments, robust insurance plans, and innovative, engineering-based solutions protecting against fire, natural disasters, and other perils. Serving over 25% of the Fortune 500 companies and large corporations worldwide, we deliver data-driven risk management solutions that enhance business resilience and continuity and empower businesses to thrive.\r\n\r\nFM India, located in Bengaluru, is our second HQ and a key hub for driving our global operational efficiency. Our presence in India allows us to leverage the country’s talented workforce and advance our capabilities to serve our clients better. We have diverse corporate functions that emphasize research, advanced technologies like AI and analytics, risk engineering, research, finance, marketing, HR, etc.","hero_h1":null,"hero_h2":null,"primary_color":"#0D102B","secondary_color":"#333333","cta_text":null,"jobs_subtitle":null,"mission":null,"stack_section_title":null,"stack_section_description":"","powered_by_logo_url":"https://d36dj8u11ystvj.cloudfront.net/Talent500_PoweredBy+(1).png","cta_bg_color":"#FFFFFF","cta_text_color":"#FFA000","cta_border_color":"#FFFFFF","h1_font_size":null,"h2_font_size":null,"h3_font_size":null,"h4_font_size":null,"body_size_1":null,"body_size_2":null,"h1_font_w":null,"h2_font_w":null,"h3_font_w":null,"h4_font_w":null,"body_w_1":null,"body_w_2":null,"public_name":null,"use_public_name":false,"unique_id":"cf0459b0-1760-4f5b-96d6-20436cb13179","head_favicon_url":"","head_title":null,"privacy_policy_name":"Privacy Policy","privacy_policy_url":null,"mandate_privacy_policy":null,"ticker_title":null,"publish":true,"company_font_family":"5","use_company_font_on_jobs_page":true,"gallery_section_name":null,"about_section_name":"FM India","testimonial_section_name":null,"benefits_section_name":null,"culture_section_name":null,"jobs_section_name":null,"is_job_displayable":true,"is_onboarding_skip":false,"company_specific_workflow":0,"third_party_company":false,"is_vendor_third_party_company":false,"priority_order":0,"order_of_about_role":1,"order_of_about_company":2,"whatsapp_company_logo":"uploads/company_images/FMIndia.png","whatsapp_company_logo_url":"https://talent500-public-prod-cb.s3.ap-south-1.amazonaws.com/talent500-companies/whatsapp/logos/FMIndia_e539ac4b146a463397d66aa151cf27ee.png","whatsapp_job_bg_color":"#040812","whatsapp_job_text_color":"#FFFFFF","engagement_type":null,"font_family":5},"location":"Bengaluru","primary_skills":["Regulatory Comliance","GRC or Governance Risk Compliance","Risk Assesment","Information Security"],"secondary_skills":["CISM or CISA"],"experience_range":"5 - 8 years","job_qualifications":[""],"screening_questions":[{"id":"11101272-8617-446d-8955-c9cf6c988536","question_number":1,"description":"How many years of experience do you have in Regulatory Compliance?","question_type":"MCSA","question_options":[{"option":"Less than 1 year","option_id":1},{"option":"More than 1 year","option_id":2},{"option":"More than 2 years","option_id":3},{"option":"More than 3 years","option_id":4},{"option":"No experience, but have strong understanding & knowledge","option_id":5},{"option":"No experience, but, I'm a quick learner","option_id":6}]},{"id":"c8cecdf5-6e84-4474-86d2-5c0e4fa7b960","question_number":2,"description":"How many years of experience do you have in Risk Assessment?","question_type":"MCSA","question_options":[{"option":"Less than 1 year","option_id":1},{"option":"More than 1 year","option_id":2},{"option":"More than 2 years","option_id":3},{"option":"More than 3 years","option_id":4},{"option":"No experience, but have strong understanding & knowledge","option_id":5},{"option":"No experience, but, I'm a quick learner","option_id":6}]},{"id":"726c4108-cc1e-4178-b325-9cfb89557e96","question_number":3,"description":"How many years of experience do you have in Governance Risk Compliance?","question_type":"MCSA","question_options":[{"option":"Less than 2 years","option_id":1},{"option":"More than 2 years","option_id":2},{"option":"More than 3 years","option_id":3},{"option":"More than 4 years","option_id":4},{"option":"No experience, but have strong understanding & knowledge","option_id":5},{"option":"No experience, but, I'm a quick learner","option_id":6}]},{"id":"8608c908-b53d-4c0f-9fb5-b6a027ff551c","question_number":4,"description":"How many years of experience do you have in Information Security?","question_type":"MCSA","question_options":[{"option":"Less than 2 years","option_id":1},{"option":"More than 2 years","option_id":2},{"option":"More than 3 years","option_id":3},{"option":"More than 4 years","option_id":4},{"option":"No experience, but have strong understanding & knowledge","option_id":5},{"option":"No experience, but, I'm a quick learner","option_id":6}]},{"id":"1fa1a3b8-a885-4b41-a24c-d4720ca8f4c9","question_number":5,"description":"If selected, how soon can you join us?","question_type":"MCSA","question_options":[{"option":"Within 15 days","option_id":1},{"option":"Within 15-30 days","option_id":2},{"option":"Within 30-45 days","option_id":3},{"option":"Within 45-60 days","option_id":4},{"option":"60+ days","option_id":5}]},{"id":"877e598f-da9f-4c80-bff5-37707bd96d7c","question_number":6,"description":"If selected, would you be willing to relocate to Bangalore?","question_type":"MCSA","question_options":[{"option":"Yes, willing to relocate","option_id":1},{"option":"No, not willing to relocate","option_id":2},{"option":"I am based in Bangalore","option_id":3}]},{"id":"7fa889a4-af22-44ad-922c-50e3693ef9c7","question_number":7,"description":"What is your overall years of experience?","question_type":"MCSA","question_options":[{"option":"0-5 years","option_id":1},{"option":"5-8 years","option_id":2},{"option":"8-10 years","option_id":3},{"option":"10+ years","option_id":4}]}],"title":"Lead Info Security Analyst IND","description":"<p><strong>About us:&nbsp;</strong></p><p>We are a highly successful 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Businesses worldwide trust our expertise to protect their assets, relying on our comprehensive risk assessments and robust, engineering-based insurance solutions to safeguard against fire, natural disasters, and other perils. Serving over a quarter of the Fortune 500 and major corporations globally, we deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive.&nbsp;</p><p>FM India is a strategic location for driving our global operational efficiency. Our presence in India allows us to leverage the country’s talented workforce and advance our capabilities to serve our clients better. We have diverse corporate functions that emphasize research, advanced technologies like AI and analytics, risk engineering, research, finance, marketing, HR, etc. working together to provide innovative solutions and nurture lasting relationships – from co-workers to clients.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p><strong>Role Title: Lead Info Security Analyst IND</strong></p><p><strong>Job Responsibilities:</strong></p><ul><li>Coordinate and support responses to global regulatory exams, client cybersecurity questionnaires, and external compliance inquiries by partnering with Information Security &amp; Risk Management, IT, and business stakeholders to gather, validate, and document supporting evidence. Track and manage incoming requests, ensuring responses are complete, accurate, and delivered within required timelines.</li><li>Translate technical control information into clear, concise, and externally appropriate responses tailored to regulators and clients, ensuring consistency with supporting evidence and control documentation. Support responses to follow-up questions, clarifications, and additional evidence requests.</li><li>Map internal security controls to global regulatory requirements and industry frameworks (e.g., NIST CSF, CIS 8.1, and regional regulations such as APRA, IRDAI, GDPR, DORA, NYDFS).</li><li>Identify and document gaps between existing controls and regulatory expectations and recommend improvements. Support tracking and reporting of remediation activities related to identified gaps.</li><li>Support preparation of regulatory reports, internal summaries, and compliance status updates.</li><li>Monitor changes in global cybersecurity and privacy regulations and assess potential impacts to the organization.</li><li>Serve as a central coordination point for regulatory and client assurance activities. Collaborate with Information Security, IT, Risk Management, Legal, and business stakeholders to collect information and drive alignment. Performs research and analysis regarding security threats, vulnerabilities, mitigating strategies, and industry trends. From this analysis, recommends specific actions and implementation strategy to address high-risk program gaps, control deficiencies or Policy / Standard improvements.</li><li>Performs security assessment of third party providers to ensure that they have the contractual, operational and technical programs in place to adequately protect Restricted and Highly Restricted information. Provides results of assessment and security consultation to third party and management regarding security risks and recommended&nbsp;improvement expectations.</li><li>Leads, maintains and positively influences enhancements to security program, standards, supporting documents, solutions and&nbsp;frameworks. Ensures that improvements include stakeholder support, are communicated well and implemented effectively.</li><li>Ensures that security services and activities are delivered according to expectations related to quality, customer focused, timeliness and metrics reporting</li><li>Successfully develops relationships with business associates and with peers in Information Services to create trust and a positive, collaborative work environment. Proven success in influencing positive outcomes in difficult&nbsp;situations.</li></ul><p><strong>Skill and Experience:</strong></p><ul><li>5-8 years of experience&nbsp;required to perform essential job functions.</li><li>Additional Experience Qualifier (optional): Minimum of five (5) years of experience in information technology or business analysissecurity, risk, audit, or regulatory compliance, with at least three (3) years in an information security specific field, such as user access management, computer forensics, network perimeter security, incident response, system security, risk, audit, or other related discipline..</li></ul><p><strong>TECHNICAL SKILLS:</strong></p><ul><li>Working knowledge of MS Office suite, especially MS Word and Excel</li><li>Expertise in at least one security, technical or risk discipline, demonstrated by relevant industry certifications</li><li>Ability to leverage various trusted sources of information articles, webinars, Internet, etc to gain accurate knowledge of current security threats, vulnerabilities, mitigating strategies to address them and then recommend and implement appropriate solutions for the organization</li></ul><p><strong>Must Have Skills:</strong></p><ul><li>Cybersecurity Regulatory and Client Compliance<br>Hands-on experience responding to regulatory exams, audits, and client security assessments, including coordinating evidence collection and developing clear, defensible written responses.&nbsp;</li></ul><p><strong>IT Security Control:</strong></p><ul><li>Global Regulatory Familiarity<br>Practical experience supporting or interpreting regional cybersecurity&nbsp;regulations, with emphasis on APAC frameworks&nbsp;frameworks&nbsp;such as APRA, and&nbsp;&nbsp;MAS, and&nbsp;&nbsp;/&nbsp;IRDAI, or similar international regulatory regimes.</li><li>Control Framework Mapping and Evidence Management<br>Strong ability to map security controls across&nbsp;to industry&nbsp;frameworks (for example NIST CSF, ISO 27001CIS 8.1, SOC?aligned controls), assess effectiveness, and manage supporting documentation.</li><li>Independent Execution and Judgment<br>Proven ability to manage work independently, prioritize competing demands, and deliver accurate, timely outputs with minimal supervision.</li><li>Clear Written and Verbal Communication<br>Ability to translate security and control information into clear, concise responses suitable for regulators, auditors, clients, and internal stakeholders.</li></ul><p><strong>SOFT SKILLS:</strong></p><ul><li>Strong verbal and written communication skills, with the ability to translate technical security concepts into clear, concise responses for regulators, clients, and business stakeholders.</li><li>Strong organizational and time management skills, with the ability to manage multiple concurrent requests and deadlines.</li><li>High attention to detail, particularly in documentation quality and accuracy of responses.</li><li>Strong stakeholder management and collaboration skills, with the ability to work effectively across Information Security &amp; Risk Management, IT, Risk, Legal, and business teams.</li><li>Ability to work independently, prioritize competing demands, and deliver high-quality outputs with minimal supervision.</li><li>Strong problem-solving and analytical skills, with the ability to interpret regulatory requirements and apply them in a practical, risk-based manner.</li><li>Strong interpersonal skills</li><li>Coordinate and lead program activities with team members and other stakeholders</li><li>Excellent customer service skills</li><li>Works collaboratively or independently to deliver appropriate, quality initiatives within budget and on time</li><li>Must have a strong work ethic, great time management skills and a positive attitude</li></ul><p><strong>TECHNICAL KNOWLEDGE:</strong></p><ul><li>Hands-on experience responding to regulatory exams, audits, or client security assessments, including evidence collection, control mapping, and response coordination. Strong knowledge of operating systems, networks, application development</li><li>Experience supporting or participating in IT general controls (ITGC) or cybersecurity control audits, with an understanding of audit expectations, testing approaches, and evidence requirements.</li><li>Strong understanding of cybersecurity control frameworks such as NIST CSF 2.0 and CIS v 8.1, including experience mapping controls to regulatory requirements.</li><li>Familiarity with global regulatory requirements across regions (e.g., APAC, EU, US), including&nbsp;regulatory bodies such as APRA, IRDAI,&nbsp;OFSI, or MAS.</li><li>Experience identifying control gaps, assessing compliance against regulatory expectations, and supporting remediation tracking.</li><li>Ability to develop and maintain clear, accurate, and audit-ready control documentation and supporting evidence.</li><li>Good understanding of computer vulnerabilities, hacker methodologies and other threats</li><li>Expertise in Information Security risk and project control assessment methodologies or similar experience gained elsewhere</li><li>Expertise in Solution Development Processes SDP or similar experience gained elsewhere</li></ul><p><strong>Education and Certifications</strong></p><p>4 Year/ bachelor’s degree required.</p><p><strong>Preferred certifications</strong>: CISA, CISM</p><p><strong>Work location:&nbsp;</strong>Bengaluru</p>","employment_type":"Full-Time","industry":"","job_template":false,"country":{"name":"India","country_code":"IN","region":"Asia"},"is_job_displayable":true,"job_url":"https://talent500.com/jobs/fmindia/lead-info-security-analyst-ind-bengaluru-T500-26673","created_at":"2026-06-12T19:40:25.904761+05:30","updated_at":"2026-07-24T20:36:28.092071+05:30","title_alias_1":"Lead Info Security Analyst IND","slug":"lead-info-security-analyst-ind-bengaluru-T500-26673","summary":null,"typical_workday":null,"what_you_offer":null,"what_you_need_to_succeed":null,"responsibilities":null,"type":null,"min_experience_years":5,"max_experience_years":8,"ctc_unit":"LPA","is_featured_job":false,"is_active":true,"job_code":"T500-26673","external_id":38677,"external_job_code":"FMCD004","is_anonymized":false,"mercurial_skills":null,"open_date":"2026-06-11T11:25:57.067681+05:30","published_at":"2026-06-12T19:40:25.142473+05:30","anonymization_needed":null,"anonymized_description":null,"xml_feed_anonymization":null,"unregistered_user_anonymization":null,"registered_user_anonymization":null,"pre_application_email_anonymization":null,"mettl_account":null,"job_table_sub_head":null,"job_table_short_desc":null,"is_remote":null,"job_video":null,"job_video_title":null,"job_video_description":null,"job_image_url":"https://wattt.s3.ap-south-1.amazonaws.com/PRODUCTION/T500-26673.png","role_summary":"<p><strong>Position Summary:</strong></p><p>Responsible for the coordination, execution, and support of global cybersecurity regulatory compliance and client assurance activities. This role focuses on responding to regulatory exams, client security questionnaires, and other external inquiries by partnering with Information Security &amp; Risk Management, IT, and business stakeholders to collect, validate, and communicate evidence of compliance to external stakeholders, including regulators and clients.</p><p>The position is responsible for evaluating and mapping security controls to global regulatory requirements, identifying gaps, and supporting the development of clear, accurate, and defensible responses. They serve as a key liaison across teams to ensure consistent, timely, and high-quality deliverables aligned with FM’s cybersecurity program.</p><p>Responsible for the collection, evaluation, understanding, and communication of security requirements involved in the development of new or the modification and ongoing support of existing information security program objectives and initiatives. The position is responsible for the monitoring, maintenance and measurement of select processes in support of the overall Information Security Program. They are expected to stay up to date on the latest threat intelligence such as vulnerability information, hacker methodologies, advanced persistent threats, business process frameworks and identity &amp; access management in order to anticipate potential information security breaches. They provide guidance and direction to business representatives, information security service owner(s) and technical resources and may manage projects of significant scope and complexity in support of the information security program.</p>","syndication_control":true,"syndication_status":"in_progress","syndication_job_title_alias":"[]","sourcing_requirements_updated_at":null,"t500_sourcing_control":true,"status":"open","job_redirection_url":null,"is_external_job":false,"is_leadership_job":false,"leadership_confidentiality_level":null,"pricing_type":null,"is_auto_apply_eligible":false,"external_apply_url":null,"ats_provider":null,"apply_timeout_seconds":null,"recruiter":"1154daea-f24c-4f7f-aad6-494543ee6112","category":30,"job_sub_category":11,"role":null,"job_function":721,"job_sub_function":1258,"naukri_industry":null,"naukri_functional_area":null,"naukri_role":null,"role_category":581,"linkedin_industry":null,"syndication_partners":["155c6cf4-8e99-4b9d-a962-30efd35c2aeb","56f3dcdd-b898-4806-ae12-c2578268f37c","5dc79af2-bfa4-4186-b589-219f71a4d5cf","9997eeaf-0206-4bb3-a458-e3823ad26e2f","a8bf9ce8-9d0e-401f-bb42-a409477787a6","aa8de7a4-71c0-4241-8523-33f47d7da6c6","dd8c2a4a-08ef-4849-8fd0-c5017b662841","f2b2a145-60a0-4c8e-86a2-dd03b3ee374a"],"candidate_job_status":null,"candidate_job_id":null,"mettl_assessment_to_be_taken":false,"company_font_data":{"font-family":"Montserrat","url":"https://fonts.googleapis.com/css2?family=Montserrat:ital,wght@0,100;0,200;0,300;0,400;0,500;0,600;0,700;0,800;0,900;1,100;1,200;1,300;1,400;1,500;1,600;1,700;1,800;1,900&display=swap"}}