Senior Analyst
Job Description
The Cybersecurity Risk & Compliance function is responsible for identifying, assessing, and managing cybersecurity and compliance risks across the organization. The team establishes security standards, validates adherence to security controls, and partners with business and technology teams to strengthen the organization's security posture.
As a Senior Analyst in the Cybersecurity Risk & Compliance team, you will independently execute cybersecurity risk assessments, compliance reviews, and governance activities while supporting the organization's evolving AI adoption. You will collaborate with Product, Engineering, Legal, Privacy, and business stakeholders to identify risks, recommend appropriate controls, and ensure security requirements are incorporated into business initiatives.
Role Expectations
Conduct cybersecurity risk assessments for products, applications, infrastructure, vendors, and business initiatives, including New Product Initiatives (NPIs).
Perform AI governance reviews for AI/ML use cases, GenAI integrations, third-party AI services, and agentic workflows by identifying potential security, privacy, and compliance risks.
Evaluate security risks and recommend appropriate controls aligned with organizational policies and industry best practices.
Support the implementation and operationalization of cybersecurity policies, standards, and control requirements across business and technology teams.
Partner with Product, Engineering, Cloud, Privacy, Legal, and other stakeholders to provide practical security guidance throughout project lifecycles.
Assist with readiness activities for security certifications and compliance frameworks by collecting evidence, validating controls, and supporting internal and external audits.
Review the effectiveness of implemented security controls and track remediation activities through to closure.
Support continuous monitoring activities by maintaining risk registers, dashboards, metrics, and compliance reporting.
Participate in security awareness initiatives by providing guidance on cybersecurity policies, secure development practices, and responsible AI usage.
Contribute to improving risk assessment methodologies, governance processes, templates, and documentation.
Identify opportunities to automate repetitive risk and compliance activities to improve operational efficiency.
Stay current with emerging cybersecurity threats, regulatory developments, cloud security trends, and AI governance practices.
Qualifications
3–6 years of experience in Cybersecurity Risk & Compliance, Information Security, Governance, Risk & Compliance (GRC), or related domains.
Experience conducting cybersecurity risk assessments, security reviews, compliance assessments, or control validation activities.
Working knowledge of cloud security concepts, preferably AWS, and common cloud security controls.
Familiarity with cybersecurity frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, HIPAA, NIST 800-171, or similar frameworks.
Exposure to AI governance concepts, AI risk assessments, or emerging AI security considerations is desirable.
Understanding of common AI/ML security risks, including:
Data leakage
Prompt injection
Hallucination and model reliability
Third-party AI integrations
Bias and fairness considerations
Familiarity with software development and cloud technologies is desirable, including:
AWS
Kubernetes
Docker
CI/CD pipelines
GitHub
Strong analytical and problem-solving skills with the ability to evaluate security risks and recommend practical solutions.
Excellent written and verbal communication skills with experience working across cross-functional teams.
Relevant certifications such as Security+, CISA, CISM, CRISC, AWS Security Specialty, or similar certifications are desirable.
Key Responsibilities
Independently execute cybersecurity and AI risk assessments.
Review business initiatives for compliance with security policies and standards.
Support audit readiness and evidence collection activities.
Perform security reviews for new technologies and third-party services.
Track remediation plans and validate control implementation.
Maintain governance documentation, risk registers, and assessment artifacts.
Provide day-to-day cybersecurity guidance to business and engineering teams.
Contribute to continuous improvement of governance processes and automation initiatives.
Additional Information
At Freshworks, we have fostered an environment that enables everyone to find their true potential, purpose, and passion, welcoming colleagues of all backgrounds, genders, sexual orientations, religions, and ethnicities. We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant, richer environment that boosts the goals of our employees, communities, and business. Fresh vision. Real impact. Come build it with us.
Company Description
Organizations everywhere struggle under the crushing costs and complexities of “solutions” that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business software has become a blocker instead of ways to get work done.
There’s another option. Freshworks. With a fresh vision for how the world works.
Freshworks Inc. builds uncomplicated service software that delivers exceptional employee and customer experiences. Our people-first approach to AI eliminates friction, helping businesses reduce complexity, lower cost-to-serve, and deliver faster, more human support through enterprise-grade yet easy-to-use CX and IT solutions. Nearly 75,000 companies, including Bridgestone, New Balance, Nucor, S&P Global, and Sony Music, trust Freshworks to power their Employee Experience (EX) and Customer Experience (CX) operations.
Fresh vision. Real impact. Come build it with us.