Free cookie consent management tool by TermsFeed IT Analyst, Security, Risk and Compliance | Antal Tech Jobs
Back to Jobs
8 Weeks ago

IT Analyst, Security, Risk and Compliance

decor
Pune, Maharashtra, India
Information Technology
Full-Time
World Bank Group

Overview

IT Analyst, Security, Risk and Compliance

Job #:
req32055
Organization:
World Bank
Sector:
Information Technology
Grade:
GE
Term Duration:
3 years 0 months
Recruitment Type:
Local Recruitment
Location:
Chennai,India
Required Language(s):
English
Preferred Language(s):

Closing Date:
3/17/2025 (MM/DD/YYYY) at 11:59pm UTC

Description

Do you want to build a career that is truly worthwhile? Working at the World Bank Group provides a unique opportunity for you to help our clients solve their greatest development challenges. The World Bank Group is one of the largest sources of funding and knowledge for developing countries; a unique global partnership of five institutions dedicated to ending extreme poverty, increasing shared prosperity and promoting sustainable development. With 189 member countries and more than 130 offices worldwide, we work with public and private sector partners, investing in groundbreaking projects and using data, research, and technology to develop solutions to the most urgent global challenges. For more information, visit www.worldbank.org

ITS Vice Presidency Context:

The Information and Technology Solutions (ITS) Vice Presidential Unit (VPU) enables the World Bank Group to achieve its mission of ending extreme poverty and boost shared prosperity on a livable planet by delivering transformative information and technologies to its staff working in over 150+ locations. For more information on ITS, see this video:https://www.youtube.com/watch?reload=9&v=VTFGffa1Y7w

Vice Presidency Context

Information and Technology Solutions (ITS) enables the WBG to achieve its mission of ending extreme poverty by 2030 and boosting shared prosperity in a sustainable manner by delivering transformative information and technologies to its staff working in over 130 client countries.

ITS services range from: establishing the infrastructure to reach and connect staff and development stakeholders; providing the devices and agile technology and information applications to facilitate the science of delivery through decentralized services; creating and maintaining tools to integrate information across the World Bank Group, the clients we serve and the countries where we operate; and delivering the computing power staff need to analyze development challenges and identify solutions.

The ITS business model combines dedicated business solutions centers that provide services tailored to specific World Bank Group business needs and shared services that provide infrastructure, applications and platforms for the entire Group. ITS is one of three VPUs that have been brought together as the World Bank Group Integrated Services (WBGIS), to provide enhanced corporate core services and enable the institution to operate as one strategic and coordinated entity.

Unit Context

The ITS Information Security and Risk Management (ITSSR) unit, headed by the Chief Information Security Officer (CISO), is responsible for providing leadership in managing the functions and activities of information security and risk across the World Bank Group, enabling the achievement of WBG's business objectives. ITSSR enables and facilitates a risk aware culture, ensures that WBG information assets are protected in an effective, efficient, and balanced manner; and IT security and risk management efforts throughout the World Bank Group are coordinated and aligned to the Bank's business and IT strategy. ITSSR establishes and maintains the World Bank Group's IT and InfoSec policies and standards; develops and engineers the WBG's information security plans and solutions; responds to security incidents; and ensures that the information risks are identified, assessed, and managed in consistent with the overall risk management approach and with the established appetite and tolerance. ITSSR consists of three main units: 1) ITS Risk Management, Compliance, and Policy, 2) ITS Information Security Engineering and Operations (ITSIS), and 3) Program Management Office (PMO).

Note: If the selected candidate is a current Bank Group staff member with a Regular or Open-Ended appointment, s/he will retain his/her Regular or Open-Ended appointment. All others will be offered a 3 year term appointment.

Duties and Accountabilities:

ITSIS is seeking to fill the position of IT Analyst, Security, Risk and Compliance within the ISOC. The successful candidate will be responsible for managing high-visibility security incident responses. The ideal candidate will possess the necessary technical and interpersonal skills to handle high-impact incidents. We are looking for an incident responder who thrives under intense pressure and is committed to round-the-clock availability to swiftly identify, contain, and remediate critical security incidents. This role demands immediate response to potential breaches, requiring exceptional problem-solving abilities and the capacity to work effectively during off-hours. In addition to applied experience, the individual will bring excellent problem solving, communication and teamwork skills, along with agile ways of working, strong business insight, an inclusive leadership attitude and a continuous learning focus.

Note: If the selected candidate is a current Bank Group staff member with a Regular or Open-Ended appointment, s/he will retain his/her Regular or Open-Ended appointment. All others will be offered a 3 year term appointment.

Scope of Work

  • Provide Information Security Operations Center (ISOC) support on a 24x7x365 basis by shift work with rotation

  • Review information security alerts from various sources and based on the classification and its impact would prioritize the alerts and assign to the respective teams within Information Security Office.
  • Conduct thorough investigative actions based on security events and remediate as dictated by standard operating procedures

  • Participate in all the phases of security incident response process, including detection, containment, eradication, and post-incident reporting.
  • Record detailed Security Incident Response activities in the Case Management System.

  • Use Security information and event management (SIEM) capabilities to develop alerts to detect anomalies.
  • Assist in developing and setting up frameworks for developing Security incident response.

  • Assist developing and maintaining ISMS procedures (related to ISOC) for complying with global ISMS policy defined by the organization.
  • Maintain technical proficiency in information security concepts and related technologies through on the job training, performing individual research and attending training courses as necessary.

  • Undertake knowledge sharing and training activities on various monitoring tools and remediation techniques on periodic basis.
  • Develop periodic status reports and monthly metrics for reporting purposes.

  • Support R&D lab using virtual machines and monitor open-source security research news, contribute to control testing and strengthening.
  • Experience in threat hunting in a diverse log and tool environment. The role requires the person to be able to manage threat hunting work program not limited to scoping, tooling and reporting metrics.

  • Perform detailed analysis of attacks against web infrastructure. This includes identification of malicious code within URLs, collection of malicious plugins and/or exploits' payload. Able to identify exploit and exploit tools involved in attacks. Able to identify packing techniques used to obfuscate URLs. Able to look at return traffic from exploitation activity looking for successful exploitation.
  • Respond to High impact incident like ransomware, major compromise, internal threats, third parties, and data leakage.

  • Perform log analysis, analyze large datasets, forensic analysis and create reports.
  • Create and deliver data driven reports and presentations for management and other stakeholders.

  • Liaison with threat hunting, infrastructure, IT, vulnerability management, threat intelligence and software engineer team members.
  • Conduct forensic examinations that include collection, preservation and analysis of data and systems.

  • Support creation and delivery of incident response tabletop exercises designed to identify gaps, improve skills, enhance communication and engage with key stakeholders.
  • Perform other duties as assigned.

Selection Criteria

  • Bachelor's degree in computer science, information technology, systems engineering, or a related field.

  • Minimum 5 years of Information Security experience required with majority of time in a SOC.
  • Experience in investigations including, but not limited to, end-user hosts, servers, network infrastructure, mobile devices, peripherals and application systems.

  • Experience in working on High impact incident like ransomware, major compromise, internal threats, third parties, and data leakage.
  • Experience in log analysis, ability to analyze large datasets, create reports, perform forensic analysis.

  • Experience in building and maintaining tools, processes, and capabilities for log analysis, ensuring the provision of data to incident stakeholders in an easy and scalable manner.
  • Understanding of network traffic and be able to analyze network traffic from an Incident Response perspective.

  • Past exposure to handle malware and financial crime malware related incidents.
  • Familiarity with industry-standard processes defined for systems design, database design, development, testing, and integration phases of a project, including Agile-based implementations.

  • Experience working in Agile environments, participating in Agile ceremonies, and utilizing Agile methodologies for security operations and threat investigations.
  • Knowledge of common hacking tools and techniques

Preferred Skillsets / Requirements

  • GIAC Certified Intrusion Analyst (GCIA) or GIAC Certified Incident Handler (GCIH)
Competencies

  • Client Understanding and Advising - Looks at issues from the client's perspective and takes action beyond normal expectations to ensure client satisfaction.
  • Learning Orientation - Stays abreast of new trends and developments in own specialty area, the broader industry, and exposes self to increasingly more challenging projects and opportunities to learn.

  • Broad Business Thinking - Maintains an in-depth understanding of the long term implications of decisions both for department and the client's business. Ensures that decisions are supported by relevant stakeholders as well as sound performance data.
  • Compliance with Standards - Monitors and maintains records on requests for information and assistance.

  • Knowledge of Emerging Technology - Tests new technology to evaluate capability compared to specifications.

World Bank Group Core Competencies

The World Bank Group offers comprehensive benefits, including a retirement plan; medical, life and disability insurance; and paid leave, including parental leave, as well as reasonable accommodations for individuals with disabilities.

We are proud to be an equal opportunity and inclusive employer with a dedicated and committed workforce, and do not discriminate based on gender, gender identity, religion, race, ethnicity, sexual orientation, or disability.

Learn more about working at the World Bank and IFC , including our values and inspiring stories.
Job ID req32055

Share job
Similar Jobs
View All
1 Day ago
TrueFan - Senior Machine Learning Engineer
Information Technology
  • Thiruvananthapuram, Kerala, India
About UsTrueFan is at the forefront of AI-driven content generation, leveraging cutting-edge generative models to build next-generation products. Our mission is to redefine content generation space through advanced AI technologies, including deep ge...
decor
1 Day ago
Salesforce commerce cloud consultant
Information Technology
  • Thiruvananthapuram, Kerala, India
Salesforce Commerce Cloud consultant  5+ Years of Experience 6 to 12 months Mode - Remote 1.1LPM - 1.2LPM Max Key Responsibilities Translate business requirements into scalable Salesforce Service Cloud solutions, in collaboration with CAE's technic...
decor
1 Day ago
Cloud Infrastructure Engineer
Information Technology
  • Thiruvananthapuram, Kerala, India
DescriptionInvent the future with us. Recognized by Fast Company’s 2023 100 Best Workplaces for Innovators List, Ampere is a semiconductor design company for a new era, leading the future of computing with an innovative approach to CPU design focuse...
decor
1 Day ago
Devops Engineer- Intermetiate
Information Technology
  • Thiruvananthapuram, Kerala, India
BackJD: Dev ops Engineer:As a DevOps Specialist- should be able to take ownership of the entire DevOps process, including Automated CI/CD pipelines and deployment to production.They should also be comfortable with risk analysis and prioritization.Le...
decor
1 Day ago
Sr Data Scientist (London)
Information Technology
  • Thiruvananthapuram, Kerala, India
AryaXAI stands at the forefront of AI innovation, revolutionizing AI for mission-critical, highly regulated industries by building explainable, safe, and aligned systems that scale responsibly. Our mission is to create AI tools that empower research...
decor
1 Day ago
Software Test Engineer
Information Technology
  • Thiruvananthapuram, Kerala, India
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further att...
decor
1 Day ago
Software Developer 5 (Java Fullstack)
Information Technology
  • Thiruvananthapuram, Kerala, India
Job DescriptionBuilding off our Cloud momentum, Oracle has formed a new organization - Oracle Health Applications & Infrastructure. This team focuses on product development and product strategy for Oracle Health, while building out a complete platfo...
decor
1 Day ago
Java Developer - Spring Frameworks
Information Technology
  • Thiruvananthapuram, Kerala, India
Java DescriptionWe are looking for a passionate and talented Java Developer with 2-3 years of hands-on experience to join our growing development team.The ideal candidate should have a strong foundation in Java technologies and the ability to develo...
decor

Talk to us

Feel free to call, email, or hit us up on our social media accounts.
Social media