Staples India Logo

Staples India

Lead Security Analyst

Posted 16 Hours Ago
Be an Early Applicant
In-Office
Chennai, Tamil Nadu, IND
Entry level
In-Office
Chennai, Tamil Nadu, IND
Entry level
Supports governance, risk, and compliance programs through policy management, enterprise risk assessments, control testing, audits, regulatory and privacy compliance, third-party risk assessments, and remediation tracking. Prepares dashboards and reports, maintains risk registers and policy repositories, collaborates with global IT, security, legal, privacy, procurement, and audit teams, and helps improve GRC processes and tooling.
The summary above was generated by AI
The GRC Analyst/Lead supports the organization’s governance, risk management, and compliance (GRC) programs by assisting with control design and testing, risk assessments, policy management, third party risk management and vendor assessment, and regulatory compliance activities. This role works closely with global stakeholders across IT, Security, Legal, Privacy, and Internal Audit to ensure adherence to internal policies, industry frameworks, and regulatory requirements. This role should be able to work independently and should be used to Global collaboration; the Staples GRC function is lead out of Staples US Corporate and this role will serve as an extension of such team to provide coverage to the India office. 

Governance & Policy Management 

  • Support the lifecycle management of information security, privacy, and risk management policies (drafting, review, approvals, communication, and periodic refresh). 

  • Maintain policy repositories and ensure alignment with applicable frameworks and regulatory requirements. 

  • Assist with governance reporting, metrics, and committee materials. 

Risk Management 

  • Participate in enterprise and IT risk assessments, including risk identification, scoring, documentation, and tracking of mitigation plans. 

  • Support risk workshops and coordination with business and technology teams. 

  • Maintain risk registers and follow up on remediation activities. 

Compliance & Assurance 

  • Support compliance programs aligned to frameworks such as:  

  • SOC 1 / SOC 2 

  • ISO/IEC 27001 

  • PCI DSS 

  • NIST CSF / NIST 80053 (as applicable) 

  • Assist with internal and external audits, including evidence collection, walkthroughs, control testing, and issue tracking. 

  • Support customer, vendor, and regulatory inquiries related to security and compliance. 


Regulatory & Privacy Support 

  • Assist with compliance activities related to applicable laws and regulations (e.g., India Digital Personal Data Protection Act (DPDP), GDPR, or other regional privacy requirements as applicable). 

  • Support privacy risk assessments, data inventories, and control documentation. 

ThirdParty Risk Management 

  • Support third party/vendor risk assessments, including questionnaire review, evidence validation, and risk issue tracking. 

  • Coordinate with procurement, legal, and security teams on vendor compliance matters. 

Reporting & Continuous Improvement 

  • Prepare dashboards, metrics, and reports for management and audit committees. 

  • Identify opportunities to improve GRC processes, tooling, and documentation. 

  • Support implementation and maintenance of GRC tools (e.g., Archer, ServiceNow GRC, MetricStream, or similar). 



Requirements

Basic Qualifications
  • Working knowledge of at least one major framework (SOC, ISO 27001, PCI DSS, NIST). 

  • Understanding of risk and control concepts, including control design and effectiveness. 

  • Strong documentation, analytical, and organizational skills. 

  • Ability to work with global teams across multiple time zones. 

  • Strong written and verbal communication skills in English. 


Preferred Qualifications
  • Experience supporting global or US based compliance programs. 

  • Familiarity with privacy regulations (DPDP, GDPR, CCPA concepts). 

  • Experience with GRC platforms (e.g., LogicGate). 

  • Professional certifications (or progress toward):  

  • CISA, CRISC, CISM 

  • ISO 27001 Lead Implementer / Auditor 


Similar Jobs

16 Hours Ago
In-Office
Chennai, Tamil Nadu, IND
Entry level
Entry level
eCommerce • Retail • Software
Leads complex security incident investigations, forensic analysis, threat hunting, detection engineering, and incident response across endpoint, network, cloud, and identity environments. Coordinates containment and recovery for high-severity incidents, analyzes malicious artifacts, advises on security architecture, mentors junior analysts, partners with engineering and vulnerability teams, and contributes to SOC strategy, reporting, metrics, and continuous improvement.
Top Skills: Antivirus SoftwareCloud SecurityEdrFirewallsIamIntrusion Detection SystemsSIEM
21 Hours Ago
Hybrid
Chennai, Tamil Nadu, IND
Expert/Leader
Expert/Leader
Digital Media • Information Technology • News + Entertainment
Designs, implements, and maintains secure enterprise and data center network infrastructure. Manages Fortinet, Palo Alto, and F5 firewalls and load balancers; supports routing, switching, high availability, disaster recovery, monitoring, incident response, compliance, documentation, and automation. Collaborates with infrastructure teams and vendors, resolves complex production issues, performs root cause analysis, and mentors junior engineers.
Top Skills: AnsibleBgpF5 Big-IpF5 DnsF5 GtmF5 LtmFortinetGitHsrpIgmpLacpMlagMulticastOspfPalo Alto FirewallsPimPort-ChannelPythonRest ApisStpVpcVrfVrrp
21 Hours Ago
Hybrid
Chennai, Tamil Nadu, IND
Senior level
Senior level
Digital Media • Information Technology • News + Entertainment
Build, maintain, and improve a software automation platform, including workflows, CI/CD pipelines, and Go- or Python-based tools. Collaborate with stakeholders to identify automation opportunities, troubleshoot incidents, improve reliability, and participate in on-call support. The role also involves system design, technical documentation, mentoring junior staff, software releases, performance analysis, and cross-functional collaboration with quality assurance.
Top Skills: ArgocdAWSCi/CdDockerGoInfrastructure As CodeJenkinsKubernetesPythonTerraform

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account