ISO Analyst
Job Description
Must Have Technical/Functional Skills
Required Qualifications
- 5+ years in information security with at least 3 years focused on cloud security architecture and compliance reviews (AWS, GCP, or Azure).
- Hands-on familiarity with cloud infrastructure and services: VPC/VNet, compute (EC2, GCE), storage (S3, GCS), IAM, networking,
logging/monitoring, and KMS/CMEK concepts.
- Strong knowledge of security controls and implementation patterns in IaC/CI-CD pipelines (Terraform, policy-as-code concepts preferred).
- In-depth understanding of compliance and risk frameworks: NIST (800-53/CSF), ISO/IEC 27001, SOC2, and enterprise ISRP-style review
processes.
- Experience producing audit-ready evidence and formal compliance reports; comfortable interacting with auditors, risk owners, and business
stakeholders.
- Excellent written and verbal communication; ability to present residual risk and remediation trade-offs to technical and non-technical audiences.
- Relevant certifications preferred: CISSP, CISM, CRISC, CCSK, AWS/GCP security certs, or ISO 27001 Lead Auditor.
Desired Skills & Attributes
- Prior experience participating in cloud solution certification programs or gate-based security reviews.
- Familiarity with MITRE ATT&CK mapping and interpreting threat model outputs.
- Ability to work cross-functionally with threat modelers, control engineers, IAM, SOC, and business owners; pragmatic approach to
remediation and risk acceptance.
- Strong organizational skills; ability to maintain and present consolidated evidence bundles and tracking for multiple concurrent services.
Outcomes & Deliverables
- Timely ISRP/ISO review reports and certification gate sign-off recommendations.
- Policy compliance checklists, gap analyses, and prioritized remediation/corrective action plans with owners and timelines.
- Audit-ready evidence bundles for each certified service (diagrams, test results, control artifacts).
- Documented residual risk decisions, accepted exceptions, and monitoring or remediation commitments.
- Regular status reports on certification progress, non-compliance items, and escalations.
Roles & Responsibilities
Role Overview
As an ISO Analyst with deep cloud security and architecture expertise, you will validate solutions against enterprise security policy,
drive ISRP/ISO reviews for cloud services and enable certification readiness. You will work closely with threat modelers,
security controls engineers, cloud IAM engineers, architects, and business owners to assess residual risk, document compliance evidence,
and support certification gates across cloud-native deployments (GCP/AWS).
Key Responsibilities
- Perform ISRP/ISO reviews of cloud solutions from design through certification, validating adherence to enterprise security policies,
control specifications, and acceptance criteria.
- Assess cloud infrastructure and architecture (VPC/VNet, subnets, routing, NSGs, firewalls, EC2/GCE, S3/GCS, IAM, KMS/CMEK,
managed services) for policy compliance and residual risks.
- Verify implementation evidence for preventative, detective, and auto-remediation controls pr oduced by security controls engineers and
threat modelers.
- Map solution controls and risks to compliance and risk frameworks (NIST CSF/800-53, ISO/IEC 27001, relevant regulatory requirements)
and produce gap analyses.
- Drive residual risk decisions and coordinate risk exception or corrective action plans with business owners, CSP/vendor representatives,
and risk & control functions.
- Prepare and maintain audit-ready documentation: review reports, policy checklists, evidence bundles, sign-off forms, and remediation tracking.
- Liaise with onboarding and training leads to ensure external consultants meet required entitlements and threat-modeling certifications prior to
productive work.
- Participate in stakeholder reviews and certification gate meetings; provide formal sign-off recommendations.
- Track and report certification progress, outstanding non-compliance items, remediation timelines, and escalations.
Salary Range: $110,000 to $125,000 per year
**Location**
Irving, TX
**Job Function**
TECHNOLOGY
**Role**
Analyst
**Job Id**
408577
**Desired Skills**
Cyber Threat Hunting
**Salary Range**
$110,000-$125,000 a year
Desired Candidate Profile
**Qualifications** : BACHELOR OF COMPUTER SCIENCE
Verified Visa Sponsor
More from Tata Consultancy Services (TCS)
Visa Sponsorship Data
AI Resume Tailoring
Tailor your resume for ISO Analyst roles
Reach hiring managers at tata consultancy services
AI Cover Letters for ISO Analyst
Generate tailored cover letters, recruiter emails, and LinkedIn messages matched to your resume.
- Tailored to your resume & job
- Cover letters, emails, LinkedIn messages
- Professional tone, your experience
